Practise cybersecurity inside controlled, authorised environments
Every target in the lab exists to be compromised. Nothing you touch here belongs to anyone else — that is the entire point.
A range you are allowed to break
The hardest part of learning offensive security legally is finding somewhere to practise. The Cyber Lab is that somewhere: isolated networks, deliberately vulnerable applications and scripted incidents, running on infrastructure built for the purpose.
- Segmented from the public internet and from other students
- Reset to a clean state whenever you want to start over
- Scope is written into every exercise brief
- Graded on your remediation write-up, not just the flag
Try the Cyber Lab for free
3 starter ranges are open to everyone. Create a free account and you can solve real challenges, capture real flags and earn XP — no plan required. It is the same lab environment paying students use, so you can judge CyberKnight properly before you spend anything.
What you can work on
17 ranges and 14 challenges. Each range is an isolated environment we own and you are authorised to attack.
Free for everyone. Create an account — no plan, no payment — and start solving straight away.
Free Range: Your First Flag
A guided starter range. Learn how the lab works and capture your first flag in about twenty minutes.
- Understand how a range brief defines scope
- Inspect what the application sends to your browser
- Find the value the page was not meant to reveal
Free Range: Broken Access Control
The classic web flaw, in its simplest form. Reach a page you were never meant to see.
- Map what the application shows a normal user
- Identify a resource referenced but not linked
- Reach it without valid authorisation
Free Range: Recon Basics
Before you attack anything, you look. Practise gathering the picture properly.
- Enumerate the exposed services on the target
- Identify the software and version in use
- Spot the one exposed file that leaks information
Included with any plan. Foundations: authentication flaws, reconnaissance and the basics done properly.
Broken Access Control Range
A reporting application where the session logic trusts a value it should not. Reach another tenant's data without valid…
- Identify the flawed authorisation check
- Access a second tenant's records
- Write the remediation as a code change
Injection Playground
Six endpoints, six injection contexts — SQL, NoSQL, command, LDAP, template and header. Each one wants a different tech…
- Identify the injection context in each endpoint
- Extract the flag from each
- Write parameterised fixes for all six
Broken Authentication Range
A deliberately weak login flow. Find the ways in that do not involve guessing a password.
- Identify the session handling weakness
- Find the account enumeration vector
- Demonstrate the password reset flaw
Network Reconnaissance Range
Map an unfamiliar internal network from a single foothold, quietly.
- Enumerate reachable hosts and services
- Identify the domain controller
- Map the trust relationships
Advanced and Pro plans. Full application assessments, API authorisation and incident reconstruction.
Compromised Host Triage
A Linux host that has been compromised. Work out how they got in, what they did, what persists, and what you would tell…
- Establish the initial access vector from logs
- Identify every persistence mechanism
- Build a defensible timeline
Segmented Network Range
Six hosts across three segments. Start with a foothold on the DMZ and reach the internal database — documenting every h…
- Enumerate each segment from your current position
- Identify the pivot paths available
- Reach the internal database host
Web Application Assessment Range
A full application assessment against a purpose-built target with several classes of vulnerability.
- Complete a full methodology pass
- Find at least one injection flaw
- Find the broken access control
API Security Range
A REST API with authorisation problems that do not show up in the documentation.
- Enumerate the undocumented endpoints
- Demonstrate the object-level authorisation flaw
- Find the mass assignment issue
Incident Response Range
A compromised host with artefacts to find. Reconstruct what happened and when.
- Establish the initial access vector
- Build a timeline of attacker activity
- Identify the persistence mechanism
Pro plan only. Active Directory attack paths, cloud misconfiguration chains and manual code review.
Domain Escalation Lab
A small Windows domain with a realistic set of misconfigurations. Go from a low-privileged user to Domain Admin, then w…
- Map the domain attack paths
- Escalate to Domain Admin
- Identify the detection signature of each step
Capture the Flag: Chained
Nothing here is critical on its own. Three low-severity issues chain into full compromise — the exercise is seeing the …
- Find all three individual issues
- Work out how they combine
- Achieve full compromise via the chain
Active Directory Attack Path Range
A realistic AD environment. Find a path from a standard user to domain admin.
- Enumerate the domain from a standard user
- Identify the privilege escalation chain
- Reach domain administrator
Cloud Misconfiguration Range
A cloud environment with IAM and storage misconfigurations that compound.
- Identify the publicly reachable storage
- Enumerate the over-permissive IAM role
- Demonstrate the privilege escalation
Secure Code Review Range
A real codebase with real bugs. Find them by reading, not by fuzzing.
- Complete a structured review of the auth module
- Identify the injection sink
- Find the race condition
Lab scope is not a suggestion
Every exercise brief states exactly which hosts are in scope. Testing anything outside that range — including other students' instances — ends lab access. This isn't bureaucracy; scope discipline is the skill that separates a professional tester from a liability, and it's assessed like everything else.
- Written scope in every brief, before any tooling is mentioned
- Techniques taught with their legal context attached
- Responsible disclosure practised as part of the exercise
- No lab content is transferable to systems you don't own
Courses with the most lab time
Web Application Security
Find, verify and fix the vulnerability classes that actually appear in web applications.
OWASP Top 10 in Depth
Each OWASP category worked through properly — how it presents, how to test for it, and how to close it.
Vulnerability Assessment & Management
Run assessments across an estate, separate signal from noise, and build a remediation programme that works.
Want lab access for your team?
We build private ranges for internal security training. Tell us the skill level and the stack you run.
Prefer a form? Request security assistance