8 Weeks. 40 Machines.
One Roadmap.
Eight themed series dropping weekly — each one a self-contained lab estate built around a real attack pattern. Full schedule below.
Operation Switchboard
Live NowA telecom startup exposed its internal protocol stack. Navigate legacy daemons, misconfigured services, and credential leaks through five interconnected hosts.
Blacksite Webapp
Live NowBlacksite built five internal web tools in a hurry. Every tool has a classic OWASP Top 10 flaw. Move through the estate extracting credentials from each.
Pipeline Breach
Live NowA CI/CD pipeline exposed from dev to prod. Leaked commits, environment variables, registry credentials, and build server access form a chain from source to root.
Exposed API
Live NowFive microservices shipped without a security review. BOLA, mass assignment, JWT forgery, broken function-level auth, and SSRF — the OWASP API Security Top 10 distilled into a single estate.
Cryptovault
Live NowCryptovault rolled its own crypto. Five services expose predictable tokens, crackable JWT secrets, hash length extension, padding oracles, and a factorizable RSA key.
Containment Failure
Live NowFive containers with dangerous misconfigurations — capability abuse, proc filesystem leaks, writable host mounts, Docker socket escapes, and the cgroups notify_on_release technique.
Memory Lane
Live NowFive SUID binaries, five memory corruption vulnerabilities. ret2win, shellcode injection, ROP chains, format string exploitation, and heap corruption — built for binary exploitation beginners.
Social Engineering Sim
Live NowTechnical OSINT on RatCorp infrastructure. Five services leak credentials through HTTP headers, robots.txt, document metadata, debug logs, and hidden API export endpoints.
Unlock Every Series
Premium gives you instant access to all 8 themed series, walkthroughs, and every machine the moment it goes live.