// Virtual labs
Pick your range.
142 browser-based labs across pentest, red team, blue team, cloud, malware analysis and SOC operations.
Kali Linux: Recon Fundamentals
Master nmap, gobuster and enumeration workflow against a vulnerable target network.
Active Directory: Kerberoasting & Lateral Movement
Compromise a multi-domain Windows forest using Kerberoasting, AS-REP roasting and DCSync.
AWS Cloud: IAM Privilege Escalation
Exploit misconfigured IAM policies and over-permissive S3 buckets in a live AWS sandbox.
SOC Analyst: SIEM Triage with Splunk
Investigate a live intrusion using SPL queries, MITRE mappings and timeline analysis.
Malware Analysis: Banking Trojan Reversing
Reverse a polymorphic banking trojan in an isolated sandbox. Extract C2 IOCs and unpacking routine.
Web Security: OWASP Top 10 Live Range
Chain SQLi, XSS, IDOR and SSRF against a deliberately vulnerable banking app.
Azure: Entra ID Tenant Compromise
Phish, replay tokens and abuse conditional access gaps to take over an Entra ID tenant.
Purple Team: Threat Emulation vs. Detections
Run Atomic Red Team techniques and tune detections in a connected SIEM. Iterate until you can see every move.
Windows 11: Local Privilege Escalation
Enumerate misconfigurations and unquoted service paths to escalate from low-priv user to SYSTEM.
ATT&CK Fundamentals
Master the ATT&CK matrix: tactics, techniques and the cyber kill chain.
Build Detection Coverage
Audit SIEM telemetry against ATT&CK techniques and produce a coverage dashboard.
Security Content Developer
Build a Splunk detection, correlation search and alert for a fresh PowerShell attack.
SOC Engineer Data Requirements
Justify and document logging requirements (PowerShell, Sysmon 1/3, 4688) for ATT&CK coverage.
Threat Hunting: C2 Beaconing
Hunt T1071 application-layer beaconing across Splunk, Sysmon and DNS logs.
Risk-Based Alerting (RBA)
Convert ATT&CK detections into weighted risk scores and trigger a high-risk alert on user jsmith.
Adversary Emulation
Safely emulate the APT chain: initial access → PowerShell → credential dumping → lateral movement → persistence → exfil.
Blue Team Incident Response
Detect, investigate, contain, eradicate and recover from the simulated APT ShadowFox intrusion.
Red Team Assessment
Speak ATT&CK across teams: map technique → detection status → response status → gap.
CISO Dashboard
Translate ATT&CK posture into a board-ready dashboard: coverage %, asset visibility, maturity, heatmap, roadmap.
Capstone: APT ShadowFox
Live-fire APT ShadowFox capstone. Chain T1190 → T1059 → T1003 → T1021 → T1041 end-to-end.
