Skip to content
2 of 6 Live

Security Labs

2 of 6 planned lab environments are live — Network Forensics and Web App Penetration. Active Directory, Wireless, Cloud Attack and Malware Analysis remain on the roadmap.

The Web App Pentest Lab is a real, deliberately vulnerable application on its own subdomain — it has no security hardening by design and is meant to be attacked. Don’t reuse passwords or test data you use elsewhere against it.

Web App Penetration Lab

Live

Difficulty: Beginner

OWASP Juice Shop — a deliberately vulnerable web app covering the OWASP Top 10. SQLi, XSS, IDOR, SSRF, XXE, insecure deserialisation and broken authentication, with a built-in scoreboard for guided progress.

Network Forensics Lab

Live

Difficulty: Intermediate

4 downloadable PCAP exercises covering C2 beacon detection, DNS tunneling, internal lateral movement and a clean-traffic baseline — with guided questions and revealable analysis for each.

Active Directory Attack Lab

Planned

Difficulty: Advanced

Full Windows domain environment with Server 2022 DC. Practice Kerberoasting, AS-REP roasting, DCSync, Golden/Silver Ticket attacks, BloodHound enumeration and LAPS abuse.

Wireless Attack Lab

Planned

Difficulty: Intermediate

Simulated enterprise WLAN environment. Practice evil twin attacks, WPA2 handshake capture, PMKID attacks, 802.1X bypass and rogue AP detection in an isolated 802.11 simulation.

Cloud Attack Lab

Planned

Difficulty: Advanced

Isolated AWS and Azure environments with intentional misconfigurations. Practice IAM privilege escalation, metadata service SSRF, S3 bucket enumeration, Lambda abuse and cloud pivot techniques.

Malware Analysis Lab

Planned

Difficulty: Advanced

REMnux and FlareVM-based environments for static and dynamic malware analysis. Pre-configured with Ghidra, Cutter, x64dbg, Wireshark and Process Monitor. Includes sample malware corpus.

Want to be notified when the next lab ships? Reach out via the contact page.