Home › Lab
Lab
Hands-on cybersecurity labs — guided walkthroughs you can follow start to finish, plus curated external ranges worth your weekend. Everything here runs against legal targets: deliberately vulnerable machines and platforms built to be attacked.
New to this? Follow the guided ladder. Lab 00 sets up your practice environment in about twenty minutes, Lab 01 runs your first scan, then the OverTheWire series takes you from your first shell through your first web hacking one small step at a time — each a copy-paste walkthrough with progress you can track.
Working on AI? The LLM security lab spins up a deliberately vulnerable model on your own machine and walks the OWASP LLM Top 10 — prompt injection, system-prompt leakage, excessive agency.
Want a bigger playground? The curated entries below point to ranges like Hack The Box, LetsDefend and GOAD — honestly labelled, no fluff.
OWASP FinBot — vulnerable agentic-AI CTF
Capture-the-flag lab built around a vulnerable AI agent handling financial tasks. Walk through prompt injection, insecure tool use, and data leakage in agentic systems—the attack surface…
GOAD — Game of Active Directory
Intentionally vulnerable Active Directory lab built for hands-on attack and defense practice. Deploys a broken domain with realistic misconfigurations—weak delegation, bad GPO hygiene, lateral movement paths—so…