Basic Port Scanning
EasyFind a service nmap's default scan doesn't show you
Hands-on labs built the way real engagements actually run — live targets, real tools, and evidence you have to go find, not a quiz with four multiple-choice answers.
Read a target the way a real engagement starts: full port sweeps, service fingerprinting, subnet discovery.
SQL injection, CSRF, SSRF, JWT forgery, and a full six-vulnerability marketplace app to take apart.
Dictionary attacks, offline hash cracking, lockout-aware spraying, and credential reuse across systems.
Real aws-cli against purpose-built AWS-shaped targets: public buckets, IAM escalation, a full kill chain.
The OWASP API Top 10 as things you actually break — broken auth, mass assignment, excessive data exposure.
No live target — real evidence. Logs, packet captures, and a suspicious file, investigated start to finish.
Map a target before you touch it. Port scanning, service fingerprinting, and subnet sweeps with real nmap output, not a quiz about it.
Find a service nmap's default scan doesn't show you
Fingerprint an outdated service by its version banner
Sweep a /28 to find the one host that matters
Scan the transport protocol most tools skip
Chain TCP and UDP recon into one full sweep
The bugs that show up in every real pentest report. Injection, broken auth, and a six-vulnerability marketplace app built to be taken apart.
Bypass authentication with a single crafted login
Extract hidden data past a keyword filter
Pull data out one true/false answer at a time
Read the database through response delays alone
Force an admin's browser to act without their consent
Turn a URL fetcher into a pivot to internal services
Forge an admin token by abusing a signing mix-up
Recover deleted secrets straight from commit history
Hijack an admin session through a product review
Read another shopper's order history by changing an ID
Checkout with a price the server never agreed to
Grant yourself admin through an unprotected field
Escape the uploads folder to read arbitrary files
Weaponize a trusted domain's own login flow
Cracking and spraying, the way they actually happen: wordlists, offline hashes, lockout-aware attacks, and credential reuse across systems.
Automate a wordlist attack against a live FTP login
Identify and crack a leaked password hash offline
Beat a lockout policy by inverting the usual attack
Break a homemade salting scheme with the right tool
Turn one cracked password into a second system breach
Real aws-cli, pointed at purpose-built AWS-shaped targets. Public buckets, metadata theft, IAM privilege escalation, and a four-stage kill chain.
Pull data from a bucket that needed no credentials
Steal instance credentials through a server-side fetch
Attach an admin policy to your own low-priv user
Turn command injection into a stolen execution role
Bucket to SSRF to IAM to serverless, in one sitting
The OWASP API Top 10, built as things you actually break: raw responses, swapped IDs, extra JSON fields, and endpoints nobody gated.
Find what the raw API response leaks past the UI
Read someone else's private messages by swapping an ID
Grant yourself a role the form was never meant to expose
Call an admin endpoint your account was never checked against
Chain exposure, IDOR, and escalation into full compromise
No live target to exploit — real evidence to read. Logs, packet captures, and a suspicious file, the way an actual investigation runs.
Isolate a brute-force attacker from 200 lines of noise
Find the one real alert among five explainable false positives
Follow a TCP stream to catch data leaving the network
Unmask a file that isn't what its extension claims
Run a complete investigation, start to finish
Prove an intrusion by correlating two separate logs
No subscriptions, no per-track add-ons. Buy once and you're in — including every challenge we ship after today.