user-hoodieHacking (practical)

TryHackMearrow-up-right: an interactive cybersecurity learning platform offering virtual labs and challenges for beginners to advanced learners. ($ if you wanna complete the entire path or do the free chapters and compensate with YouTube walkthroughs)

VulnLabarrow-up-right: provides a pentesting and red teaming lab with around 120 vulnerable machines, including standalone systems and complex Active Directory environments. It covers a range of difficulties from easy to advanced and offers guidance through notes, hints, and walkthroughs. ($)

VulnHubarrow-up-right: offers downloadable virtual machines (VMs) designed to practice exploitation and penetration testing. (FREE)

PentesterLabarrow-up-right: provides hands-on web application security training with real-world challenges and virtual labs focused on vulnerabilities. ($ + FREE)

Hack The Boxarrow-up-right: a platform for penetration testing challenges and CTFs, offering labs, virtual machines, and an academy for learning ethical hacking. ($ + FREE)

Offensive Security Labsarrow-up-right: a platform offering practical labs for learning penetration testing and cybersecurity, connected to Offensive Security certifications. (Practice $, Play =3 free hours/day)

Slayer Labsarrow-up-right: a cybersecurity training platform with a focus on hands-on labs and challenges, designed to improve penetration testing skills. ($)

Immersive Labsarrow-up-right: a cybersecurity training platform for organizations and individuals to upskill their teams with hands-on labs and exercises in various security domains. ($ + FREE)

HackMyVMarrow-up-right: a platform offering vulnerable virtual machines for learning and practicing penetration testing skills. (FREE)

Hack This Sitearrow-up-right: a safe and legal training ground for hackers to test and expand their ethical hacking skills with challenges, CTFs, and more. (FREE)

Try2Hackarrow-up-right: a game of computer hacking that includes infrastructure, reverse engineering, cracking and cryptoanalysis tasks.

Kubernetes Goatarrow-up-right: a GitHub project providing a vulnerable Kubernetes environment for security testing and learning. (FREE)

Damn Vulnerable GraphQL Applicationarrow-up-right: a GitHub project for learning and exploiting vulnerabilities in GraphQL applications. (FREE)

OWASP Juice Shoparrow-up-right: a vulnerable web application designed to learn and practice web application security testing, widely used for security training. (FREE)

PortSwiggerarrow-up-right: provider of web application security tools and training, empowering professionals to identify and address vulnerabilities effectively. In their labs, you can alternate between the BurpSuite community tool and ZAP (Zed Attack Proxy) . (FREE)

DVWAarrow-up-right: arrow-up-rightan intentionally vulnerable web application designed to practice hacking in a controlled environment. (FREE)

GOADarrow-up-right: a pentest Active Directory LAB project. The purpose of this lab is to give pentesters a vulnerable Active directory environment ready to use to practice attack techniques. (FREE)​

CryptoHackarrow-up-right: platform to learn about cryptography through solving challenges and cracking insecure code. (FREE)

Pwned Labsarrow-up-right: upskills cybersecurity professionals affordably and effectively. Explore their interactive labs that replicate real-world scenarios. (FREE + $)

Last updated