// Virtual labs

Pick your range.

142 browser-based labs across pentest, red team, blue team, cloud, malware analysis and SOC operations.

20 labs · filtered
Sorted by relevance
Kali
Beginner

Kali Linux: Recon Fundamentals

Master nmap, gobuster and enumeration workflow against a vulnerable target network.

#nmap#gobuster#enumeration
90m · 250pts4,218 ops
Wind
Advanced

Active Directory: Kerberoasting & Lateral Movement

Compromise a multi-domain Windows forest using Kerberoasting, AS-REP roasting and DCSync.

#kerberos#impacket#mimikatz
180m · 900pts1,462 ops
Kali
Intermediate

AWS Cloud: IAM Privilege Escalation

Exploit misconfigured IAM policies and over-permissive S3 buckets in a live AWS sandbox.

#aws#iam#s3
120m · 600pts2,840 ops
Ubun
Intermediate

SOC Analyst: SIEM Triage with Splunk

Investigate a live intrusion using SPL queries, MITRE mappings and timeline analysis.

#splunk#siem#mitre
150m · 550pts3,105 ops
Wind
Critical

Malware Analysis: Banking Trojan Reversing

Reverse a polymorphic banking trojan in an isolated sandbox. Extract C2 IOCs and unpacking routine.

#reversing#ghidra#yara
240m · 1200pts712 ops
Kali
Beginner

Web Security: OWASP Top 10 Live Range

Chain SQLi, XSS, IDOR and SSRF against a deliberately vulnerable banking app.

#owasp#burp#sqli
120m · 400pts6,204 ops
Kali
Advanced

Azure: Entra ID Tenant Compromise

Phish, replay tokens and abuse conditional access gaps to take over an Entra ID tenant.

#azure#entra#phishing
180m · 850pts928 ops
Mixe
Advanced

Purple Team: Threat Emulation vs. Detections

Run Atomic Red Team techniques and tune detections in a connected SIEM. Iterate until you can see every move.

#purple#atomic#sigma
200m · 950pts540 ops
Wind
Intermediate

Windows 11: Local Privilege Escalation

Enumerate misconfigurations and unquoted service paths to escalate from low-priv user to SYSTEM.

#windows#privesc#winpeas
120m · 500pts1,985 ops
Kali
Intermediate

ATT&CK Fundamentals

Master the ATT&CK matrix: tactics, techniques and the cyber kill chain.

#mitre#attack#fundamentals
90m · 300pts0 ops
Ubun
Intermediate

Build Detection Coverage

Audit SIEM telemetry against ATT&CK techniques and produce a coverage dashboard.

#siem#splunk#coverage
120m · 450pts0 ops
Ubun
Intermediate

Security Content Developer

Build a Splunk detection, correlation search and alert for a fresh PowerShell attack.

#detection-engineering#splunk#powershell
120m · 500pts0 ops
Wind
Intermediate

SOC Engineer Data Requirements

Justify and document logging requirements (PowerShell, Sysmon 1/3, 4688) for ATT&CK coverage.

#sysmon#logging#soc
90m · 400pts0 ops
Kali
Advanced

Threat Hunting: C2 Beaconing

Hunt T1071 application-layer beaconing across Splunk, Sysmon and DNS logs.

#threat-hunting#t1071#dns
150m · 650pts0 ops
Ubun
Advanced

Risk-Based Alerting (RBA)

Convert ATT&CK detections into weighted risk scores and trigger a high-risk alert on user jsmith.

#rba#risk#splunk
150m · 700pts0 ops
Kali
Advanced

Adversary Emulation

Safely emulate the APT chain: initial access → PowerShell → credential dumping → lateral movement → persistence → exfil.

#red-team#emulation#atomic
180m · 800pts0 ops
Wind
Advanced

Blue Team Incident Response

Detect, investigate, contain, eradicate and recover from the simulated APT ShadowFox intrusion.

#ir#dfir#timeline
180m · 750pts0 ops
Mixe
Advanced

Red Team Assessment

Speak ATT&CK across teams: map technique → detection status → response status → gap.

#purple-team#assessment#gap-analysis
150m · 700pts0 ops
Ubun
Advanced

CISO Dashboard

Translate ATT&CK posture into a board-ready dashboard: coverage %, asset visibility, maturity, heatmap, roadmap.

#ciso#governance#dashboard
120m · 600pts0 ops
Mixe
Critical

Capstone: APT ShadowFox

Live-fire APT ShadowFox capstone. Chain T1190 → T1059 → T1003 → T1021 → T1041 end-to-end.

#capstone#apt#shadowfox
240m · 1500pts0 ops