Labs

14 challenges available. Find the flag, submit it, earn points.

Easy 100 pts

Find the Hidden File

A sensitive file is hidden somewhere in the filesystem. Can you find it?

Medium 200 pts

Reverse Shell

Establish a reverse shell connection to the target machine.

Medium 250 pts

Sudo Privilege Escalation

A user has sudo privileges for an unusual binary. Escalate to root.

Easy 150 pts

Registry Secrets

Sensitive information is stored in the Windows Registry. Find it.

Hard 300 pts

PowerShell Empire

Use PowerShell to extract data from a remote system.

Medium 200 pts

Domain Enumeration

Enumerate the Active Directory domain and find sensitive accounts.

Expert 400 pts

Kerberoasting

Perform a Kerberoasting attack to extract service account credentials.

Easy 150 pts

S3 Bucket Misconfiguration

An S3 bucket has been misconfigured. Find and access sensitive data.

Hard 350 pts

IAM Privilege Escalation

Escalate privileges using overly permissive IAM policies.

Medium 200 pts

Azure AD Enumeration

Enumerate Azure AD tenant and discover security misconfigurations.

Medium 250 pts

Broken Authentication

The API has a broken authentication mechanism. Bypass it.

Hard 300 pts

Mass Assignment

Exploit mass assignment vulnerability to escalate privileges.

Easy 100 pts

SQL Injection

A login form is vulnerable to SQL injection. Login without credentials.

Medium 200 pts

XSS Stored

A comment section is vulnerable to stored XSS. Steal the admin cookie.