Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PENTEST-LAB — Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent AI simulator, and GRC evidence reporting for learning penetration testing and defensive techniques. | Kitploit
Tools/GitHubGitHub/pannagkumaar/pentest-lab
Vulnerability AnalysisExploitationWeb SecurityCTFPenetration TestingCloud SecurityAuthenticationLearning & EducationAPI SecurityAI SecurityLabs & Practice
1192 months agoNot yet reviewed
GitHub
pannagkumaar/pentest-lab

PENTEST-LAB

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent AI simulator, and GRC evidence reporting for learning penetration testing and defensive techniques.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

PENTEST-LAB

A modern vulnerable application & cyber range for learning web, API, cloud, AI, and blue-team security through hands-on attack chains.

╔═══════════════════════════════════════════════════════════════╗
║     ██████╗ ███████╗███╗   ██╗████████╗███████╗███████╗████████╗ ║
║     ██╔══██╗██╔════╝████╗  ██║╚══██╔══╝██╔════╝██╔════╝╚══██╔══╝ ║
║     ██████╔╝█████╗  ██╔██╗ ██║   ██║   █████╗  ███████╗   ██║    ║
║     ██╔═══╝ ██╔══╝  ██║╚██╗██║   ██║   ██╔══╝  ╚════██║   ██║    ║
║     ██║     ███████╗██║ ╚████║   ██║   ███████╗███████║   ██║    ║
║     ╚═╝     ╚══════╝╚═╝  ╚═══╝   ╚═╝   ╚══════╝╚══════╝   ╚═╝    ║
║        MODERN CYBER RANGE · 53 CHALLENGES · 8 TRACKS            ║
╚═══════════════════════════════════════════════════════════════╝

★ Star this repo if it helps you - it's free and helps others discover free security education.


What makes this different

PENTEST-LAB is not another single-vuln box. It is a full cyber range that pairs the attacker and defender perspectives with GRC-style evidence output:

  • 53 challenges across 8 tracks - Web, API, Auth/Session, Cloud/DevOps, AI Security, Business Logic, Attack Chain, Blue Team Evidence.
  • Central challenge registry - one source of truth feeding the UI, flag validator, and evidence generator.
  • Learn before you solve - every challenge links to authoritative references (OWASP, PortSwigger, MITRE, NIST) so you can study the concept, then exploit it. Flags are earned by exploiting, not revealed in the UI.
  • Transparent AI simulator - the AI track runs on an inspectable in-process "model" (no external LLM): you see the full [SYSTEM][USER][RETRIEVED][HISTORY] context, the generated output, the injection technique detected, and toggles for each mitigation.
  • Central event store - every request and flag is logged; the defender view is built on the same events the attacker generates.
  • Guided attack chain - Recon → Information Disclosure → Token Abuse → Privilege Escalation → Data Access → Evidence Report, with live progress.
  • Blue Team mode - failed logins, suspicious API access, SSRF, privesc, file uploads, flag captures, and chain progress in one dashboard.
  • GRC evidence mode - Markdown / JSON / CSV reports mapping each finding to severity, endpoint, evidence, business impact, remediation, control domain, and a detection opportunity. (Broad control-domain mapping - not a compliance certification.)
  • Earned, not revealed - the flag field is locked until you capture it. The modal shows the status, not the literal flag, so you actually have to exploit the endpoint (via the in-UI API Tester or your own client).
  • Recommended next + weighted progress - each solved challenge suggests a sensible next one, and your progress score weights harder challenges more than easy ones (4 > 3 > 2 > 1) instead of a flat count.
  • Portable progress - export your captured flags and progress as a Markdown portfolio artifact you can keep after the lab is gone.
  • Safe by default - binds to 127.0.0.1, warns loudly on 0.0.0.0, all secrets fake and clearly marked, SSRF targets a local in-process mock (no real egress), no external targets.
  • Easy to run - one Python script, a Makefile, and docker-compose.
  • Self-checking - make verify-registry validates the challenge registry (unique ids/flags, required fields, resources, hint counts) so the catalog stays consistent.

Quick start

# 1. One-liner (installs deps, seeds the DB, starts the server)
python start_lab.py
# or:  make start

Open http://localhost:3000 in your browser.

Other ways to run
# Backend only
cd backend && npm install && npm start

# Docker (published to 127.0.0.1 only)
docker compose up --build

# Reset captured flags / events / chain progress
make reset

# Refresh demo seed data
make seed

# Smoke test core routes (start the lab first)
make test

# Validate the challenge registry (unique ids/flags, fields, resources)
make verify-registry

# Safe local-only exploit demo (5 challenges)
python demo_exploit.py

Challenge tracks

TrackWhat you learn#
◆ Web App PentestSQLi, IDOR, file upload, path traversal, WAF bypass14
◆ API SecurityBOLA, mass assignment, rate-limit bypass, webhooks, GraphQL, CORS reflection, NoSQL injection7
◆ Auth & SessionJWT kid/alg confusion, refresh-token reuse, reset tokens, fixation, MFA, host-header reset poisoning9
◆ Cloud / DevOps.env leak, SSRF metadata, docker debug, public storage, CI/CD tokens5
◆ AI Securityprompt injection, indirect injection, RAG leak/poison, tool calls, multi-turn jailbreak, output-filter bypass, and three-level audit drills10
◆ Business Logiccoupon stacking, negative qty, race conditions, payment bypass5
◆ Attack ChainGuided end-to-end path + legacy full-chain RCE, with evidence2
◆ Blue Team EvidenceDetect attacks and generate a GRC report1
53

Each challenge has: id, title, track, category, difficulty, objective, vulnerable endpoint, exploitation concept, 3 progressive hints (vague → specific → answer), flag, remediation, detection/evidence notes, a mapped control domain, and a learn-before-solving resource list.

The challenge modal

Click any challenge card to open the modal. It gives you:

  • Objective, endpoint, and the exploitation concept so you know what to aim at.
  • Learn before solving - authoritative links (OWASP, PortSwigger, MITRE, NIST) to study first.
  • 3 progressive hints - reveal them one at a time if you get stuck; how many you used is tracked per challenge.
  • Open in API Tester - jump straight into a pre-loaded request against the vulnerable endpoint, or send it from your own client.
  • Recommended next - once solved, a sensible next challenge is suggested to keep your learning path going.
  • Prev / Next nav - move through challenges without closing the modal.
  • Locked flag - the literal flag is hidden until you capture it by exploiting the endpoint. The modal shows captured / not-captured status.

Attack chain mode

A realistic, fully local chain in six detected steps:

Recon → Information Disclosure → Credential/Token Abuse →
Privilege Escalation → Sensitive Data Access → Evidence Report
B=http://127.0.0.1:3000
curl -s $B/api/attack-chain/recon    # 1. debug endpoint discloses routes
curl -s $B/api/attack-chain/leak     # 2. leaked fake JWT secret (weak123)
# 3. forge admin token -> 4. escalate -> 5. read fake customer records -> 6. report
curl -s $B/api/attack-chain/progress

Track progress live in the Attack Chain tab.


Blue team mode

The Defender tab shows the same activity the attacker just performed: recent events, failed logins, suspicious API access, file uploads, SSRF attempts, privilege-escalation attempts, flags captured, and attack-chain progress - each event severity-coloured, flag captures flagged with 🚩.

curl -s http://localhost:3000/api/blue-team/dashboard

Evidence report mode

Generate a report from your captured flags mapping each to a finding with severity, affected endpoint, evidence, business impact, remediation, control domain, and a detection opportunity.

# Markdown (default)
curl -s -X POST http://localhost:3000/api/evidence/report \
  -H 'Content-Type: application/json' -d '{"format":"markdown"}'

# JSON or CSV
curl -s -X POST http://localhost:3000/api/evidence/report \
  -H 'Content-Type: application/json' -d '{"format":"csv"}'

# Control domains mapped: Access Control, Logging & Monitoring,
# Secure Development, Secrets Management, Change Management,
# Configuration Management, Data Protection, Incident Response.
Download Tool