Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent AI simulator, and GRC evidence reporting for learning penetration testing and defensive techniques.
A modern vulnerable application & cyber range for learning web, API, cloud, AI, and blue-team security through hands-on attack chains.
╔═══════════════════════════════════════════════════════════════╗
║ ██████╗ ███████╗███╗ ██╗████████╗███████╗███████╗████████╗ ║
║ ██╔══██╗██╔════╝████╗ ██║╚══██╔══╝██╔════╝██╔════╝╚══██╔══╝ ║
║ ██████╔╝█████╗ ██╔██╗ ██║ ██║ █████╗ ███████╗ ██║ ║
║ ██╔═══╝ ██╔══╝ ██║╚██╗██║ ██║ ██╔══╝ ╚════██║ ██║ ║
║ ██║ ███████╗██║ ╚████║ ██║ ███████╗███████║ ██║ ║
║ ╚═╝ ╚══════╝╚═╝ ╚═══╝ ╚═╝ ╚══════╝╚══════╝ ╚═╝ ║
║ MODERN CYBER RANGE · 53 CHALLENGES · 8 TRACKS ║
╚═══════════════════════════════════════════════════════════════╝
★ Star this repo if it helps you - it's free and helps others discover free security education.
PENTEST-LAB is not another single-vuln box. It is a full cyber range that pairs the attacker and defender perspectives with GRC-style evidence output:
[SYSTEM][USER][RETRIEVED][HISTORY] context, the generated output, the
injection technique detected, and toggles for each mitigation.127.0.0.1, warns loudly on 0.0.0.0, all
secrets fake and clearly marked, SSRF targets a local in-process mock (no
real egress), no external targets.make verify-registry validates the challenge registry
(unique ids/flags, required fields, resources, hint counts) so the catalog
stays consistent.# 1. One-liner (installs deps, seeds the DB, starts the server)
python start_lab.py
# or: make start
Open http://localhost:3000 in your browser.
# Backend only
cd backend && npm install && npm start
# Docker (published to 127.0.0.1 only)
docker compose up --build
# Reset captured flags / events / chain progress
make reset
# Refresh demo seed data
make seed
# Smoke test core routes (start the lab first)
make test
# Validate the challenge registry (unique ids/flags, fields, resources)
make verify-registry
# Safe local-only exploit demo (5 challenges)
python demo_exploit.py
| Track | What you learn | # |
|---|---|---|
| ◆ Web App Pentest | SQLi, IDOR, file upload, path traversal, WAF bypass | 14 |
| ◆ API Security | BOLA, mass assignment, rate-limit bypass, webhooks, GraphQL, CORS reflection, NoSQL injection | 7 |
| ◆ Auth & Session | JWT kid/alg confusion, refresh-token reuse, reset tokens, fixation, MFA, host-header reset poisoning | 9 |
| ◆ Cloud / DevOps | .env leak, SSRF metadata, docker debug, public storage, CI/CD tokens | 5 |
| ◆ AI Security | prompt injection, indirect injection, RAG leak/poison, tool calls, multi-turn jailbreak, output-filter bypass, and three-level audit drills | 10 |
| ◆ Business Logic | coupon stacking, negative qty, race conditions, payment bypass | 5 |
| ◆ Attack Chain | Guided end-to-end path + legacy full-chain RCE, with evidence | 2 |
| ◆ Blue Team Evidence | Detect attacks and generate a GRC report | 1 |
| 53 |
Each challenge has: id, title, track, category, difficulty, objective, vulnerable endpoint, exploitation concept, 3 progressive hints (vague → specific → answer), flag, remediation, detection/evidence notes, a mapped control domain, and a learn-before-solving resource list.
Click any challenge card to open the modal. It gives you:
A realistic, fully local chain in six detected steps:
Recon → Information Disclosure → Credential/Token Abuse →
Privilege Escalation → Sensitive Data Access → Evidence Report
B=http://127.0.0.1:3000
curl -s $B/api/attack-chain/recon # 1. debug endpoint discloses routes
curl -s $B/api/attack-chain/leak # 2. leaked fake JWT secret (weak123)
# 3. forge admin token -> 4. escalate -> 5. read fake customer records -> 6. report
curl -s $B/api/attack-chain/progress
Track progress live in the Attack Chain tab.
The Defender tab shows the same activity the attacker just performed: recent events, failed logins, suspicious API access, file uploads, SSRF attempts, privilege-escalation attempts, flags captured, and attack-chain progress - each event severity-coloured, flag captures flagged with 🚩.
curl -s http://localhost:3000/api/blue-team/dashboard
Generate a report from your captured flags mapping each to a finding with severity, affected endpoint, evidence, business impact, remediation, control domain, and a detection opportunity.
# Markdown (default)
curl -s -X POST http://localhost:3000/api/evidence/report \
-H 'Content-Type: application/json' -d '{"format":"markdown"}'
# JSON or CSV
curl -s -X POST http://localhost:3000/api/evidence/report \
-H 'Content-Type: application/json' -d '{"format":"csv"}'
# Control domains mapped: Access Control, Logging & Monitoring,
# Secure Development, Secrets Management, Change Management,
# Configuration Management, Data Protection, Incident Response.