Labs
14 challenges available. Find the flag, submit it, earn points.
Find the Hidden File
A sensitive file is hidden somewhere in the filesystem. Can you find it?
Reverse Shell
Establish a reverse shell connection to the target machine.
Sudo Privilege Escalation
A user has sudo privileges for an unusual binary. Escalate to root.
Registry Secrets
Sensitive information is stored in the Windows Registry. Find it.
PowerShell Empire
Use PowerShell to extract data from a remote system.
Domain Enumeration
Enumerate the Active Directory domain and find sensitive accounts.
Kerberoasting
Perform a Kerberoasting attack to extract service account credentials.
S3 Bucket Misconfiguration
An S3 bucket has been misconfigured. Find and access sensitive data.
IAM Privilege Escalation
Escalate privileges using overly permissive IAM policies.
Azure AD Enumeration
Enumerate Azure AD tenant and discover security misconfigurations.
Broken Authentication
The API has a broken authentication mechanism. Bypass it.
Mass Assignment
Exploit mass assignment vulnerability to escalate privileges.
SQL Injection
A login form is vulnerable to SQL injection. Login without credentials.
XSS Stored
A comment section is vulnerable to stored XSS. Steal the admin cookie.