Don't watch someone hack.
Hack it yourself.
Spin up a real vulnerable machine, attack it with the same tools the pros use, and capture the flag to prove you did it. No videos. No multiple-choice quizzes. Just you vs. the target.
What it looks like the moment you start a lab.
EXPOSED SERVICES
4 open ports detected during initial nmap sweep. Two services running outdated software with known CVEs.
22
SSH
80
HTTP
3306
MYSQL
8080
HTTP-ALT
● LIVE - automated demo replays every 60s.
Six disciplines. Endless attack paths.
From web app pentesting to Active Directory compromise - every category ships with beginner-friendly entry points and insane-mode nightmares.
Web Security
SQLi, XSS, SSRF, auth bypass, deserialization - OWASP-style attacks against live web apps.
Network Security
Sniffing, spoofing, pivoting, lateral movement across segmented enterprise LANs.
System Admin
Linux privesc, Windows misconfigurations, cron abuse, SUID exploitation.
Active Directory
Kerberoasting, AS-REP roasting, GPP abuse, DCSync - full domain compromise.
Cloud Security
IAM privilege escalation, S3 bucket exposure, container escape, K8s attacks.
Digital Forensics
Memory dumps, disk imaging, log carving, steganography, timeline reconstruction.
Live in the range right now.
From zero to flag in four steps.
Spin Up
Choose a lab. A dedicated VM spins up in under 30 seconds with your own private network.
Connect
Open the in-browser terminal or SSH from your machine. Targets are isolated to you.
Exploit
Recon, enumerate, attack. Use any tool - nmap, Burp, sqlmap, Metasploit, BloodHound.
Submit Flag
Capture the flag hidden inside the target. Auto-graded. XP awarded. Rank rises.
Range statistics
0
Labs in range
0
Categories
12.4K
Flags captured
3,217
Students practicing
Ready to hack?
Pick your first target. The range is online 24/7 and your first flag is one nmap scan away.
