Exercises
48 exercises. Free ones need no card — just sign up.
| Exercise | Topic | Est. time | Difficulty | Solved by | Tier |
|---|---|---|---|---|---|
|
Intro to Web Security
Learn how attackers see the web, then find your first flags.
|
Web | ~1.8 hrs | Easy | 0 | Free |
|
Linux Fundamentals
Get comfortable on the command line, the hacker home turf.
|
Linux | ~1.9 hrs | Easy | 0 | Free |
|
Network Fundamentals
How data actually travels between machines.
|
Network | ~1.9 hrs | Easy | 0 | Free |
|
OSINT Fundamentals
Find what is hiding in plain sight.
|
OSINT | ~1.9 hrs | Easy | 0 | Free |
|
Windows Fundamentals
The other operating system you will meet on every engagement.
|
Windows | ~1.9 hrs | Easy | 0 | Free |
|
Networking Essentials
Speak the language of networks: the OSI model, the TCP handshake and the ports you meet every day.
|
Network | ~1.7 hrs | Easy | 0 | Free |
|
How the Web Works
Requests, responses, methods and status codes — the foundation every web hacker needs.
|
Web | ~1.6 hrs | Easy | 0 | Free |
|
Cryptography Foundations
The CIA triad, and the crucial difference between encoding, hashing and encryption.
|
Cryptography | ~1.6 hrs | Easy | 0 | Free |
|
The Cyber Kill Chain
See an attack as a chain of stages — and learn where defenders can break it.
|
Blue Team | ~1.7 hrs | Easy | 0 | Free |
|
Introduction to AI Security
Why AI is its own attack surface, and the OWASP LLM Top 10 that maps it.
|
AI Security | ~4.4 hrs | Easy | 0 | Free |
|
Game Hacking Fundamentals
The ethics and the core idea: game state is just numbers in memory.
|
Reverse Engineering | ~20.1 hrs | Easy | 0 | Free |
|
Cloud Security Fundamentals
The shared responsibility model and why identity, not the network, is the new perimeter.
|
Cloud | ~25 min | Easy | 0 | Free |
|
Welcome: How This Platform Works
What a room, task, flag and point are — and how to answer your very first question.
|
Start Here | ~1.5 hrs | Easy | 0 | Free |
|
Staying Legal & Safe
The single most important lesson: only ever test systems you own or are allowed to test.
|
Start Here | ~1.6 hrs | Easy | 0 | Free |
|
Setting Up Your Free Practice Lab
Two ways to start — browser-only, or a free isolated Kali Linux VM. Step by step.
|
Start Here | ~1.6 hrs | Easy | 0 | Free |
|
The Linux Terminal, From Zero
What a terminal is, how to read the prompt, and ten commands you will use forever — try each one.
|
Start Here | ~7.9 hrs | Easy | 0 | Free |
|
Your Essential Toolkit
The handful of tools every beginner should know, what each one does, and how to install them.
|
Start Here | ~3.9 hrs | Easy | 0 | Free |
|
Your First Hack: A Guided Walkthrough
Capture a real hidden flag on this very website, step by step. No tools required.
|
Start Here | ~7.9 hrs | Easy | 0 | Free |
|
CTF: First Blood
A short challenge box to test what you have learned.
|
CTF | ~1.8 hrs | Medium | 0 | Free |
|
Web Exploitation Basics
The three bugs you will find on almost every web app.
|
Web | ~1.9 hrs | Medium | 0 | 🔒 Pro |
|
Nmap Deep Dive
Master the scanner every pentester reaches for first.
|
Network | ~1.9 hrs | Medium | 0 | 🔒 Pro |
|
Cryptography 101
Tell encoding, hashing, and encryption apart, then break some.
|
Crypto | ~1.8 hrs | Medium | 0 | 🔒 Pro |
|
Password Cracking
From captured hashes to plaintext passwords.
|
Passwords | ~1.9 hrs | Medium | 0 | 🔒 Pro |
|
Digital Forensics Intro
Follow the artifacts a system leaves behind.
|
Forensics | ~1.9 hrs | Medium | 0 | 🔒 Pro |
|
Steganography
Messages hidden inside ordinary files.
|
Stego | ~1.8 hrs | Medium | 0 | 🔒 Pro |
|
SQL Injection In Depth
Understand why SQL injection happens, bypass a login, and extract data with UNION.
|
Web | ~1.6 hrs | Medium | 0 | 🔒 Pro |
|
Cross-Site Scripting (XSS)
Run JavaScript in someone else's browser — and learn the one rule that stops it.
|
Web | ~1.7 hrs | Medium | 0 | 🔒 Pro |
|
Prompt Injection & Jailbreaks
The number-one LLM risk: untrusted text becoming instructions the model obeys.
|
AI Security | ~1.7 hrs | Medium | 0 | 🔒 Pro |
|
Attacking the ML Pipeline
Poisoning, evasion, model extraction and inversion — name the attack, then stop it.
|
AI Security | ~1.7 hrs | Medium | 0 | 🔒 Pro |
|
Memory Scanning & Editing
Find an unknown address by scanning and filtering, then follow pointers so it survives a restart.
|
Reverse Engineering | ~4.1 hrs | Medium | 0 | 🔒 Pro |