Skip to content

Practise cybersecurity inside controlled, authorised environments

Every target in the lab exists to be compromised. Nothing you touch here belongs to anyone else — that is the entire point.

A range you are allowed to break

The hardest part of learning offensive security legally is finding somewhere to practise. The Cyber Lab is that somewhere: isolated networks, deliberately vulnerable applications and scripted incidents, running on infrastructure built for the purpose.

  • Segmented from the public internet and from other students
  • Reset to a clean state whenever you want to start over
  • Scope is written into every exercise brief
  • Graded on your remediation write-up, not just the flag
Free forever · no plan, no card

Try the Cyber Lab for free

3 starter ranges are open to everyone. Create a free account and you can solve real challenges, capture real flags and earn XP — no plan required. It is the same lab environment paying students use, so you can judge CyberKnight properly before you spend anything.

What you can work on

17 ranges and 14 challenges. Each range is an isolated environment we own and you are authorised to attack.

Foundation Needs Beginner 4 ranges

Included with any plan. Foundations: authentication flaws, reconnaissance and the basics done properly.

Unlock
Easy

Broken Access Control Range

A reporting application where the session logic trusts a value it should not. Reach another tenant's data without valid…

  • Identify the flawed authorisation check
  • Access a second tenant's records
  • Write the remediation as a code change
45 min 100 XP
Sign in and unlock
Easy

Injection Playground

Six endpoints, six injection contexts — SQL, NoSQL, command, LDAP, template and header. Each one wants a different tech…

  • Identify the injection context in each endpoint
  • Extract the flag from each
  • Write parameterised fixes for all six
45 min 100 XP
Sign in and unlock
Easy

Broken Authentication Range

A deliberately weak login flow. Find the ways in that do not involve guessing a password.

  • Identify the session handling weakness
  • Find the account enumeration vector
  • Demonstrate the password reset flaw
45 min · 2 flags 220 XP
Sign in and unlock
Easy

Network Reconnaissance Range

Map an unfamiliar internal network from a single foothold, quietly.

  • Enumerate reachable hosts and services
  • Identify the domain controller
  • Map the trust relationships
60 min · 1 flags 180 XP
Sign in and unlock
Advanced Needs Advanced 5 ranges

Advanced and Pro plans. Full application assessments, API authorisation and incident reconstruction.

Unlock
Medium

Compromised Host Triage

A Linux host that has been compromised. Work out how they got in, what they did, what persists, and what you would tell…

  • Establish the initial access vector from logs
  • Identify every persistence mechanism
  • Build a defensible timeline
45 min 250 XP
Sign in and unlock
Medium

Segmented Network Range

Six hosts across three segments. Start with a foothold on the DMZ and reach the internal database — documenting every h…

  • Enumerate each segment from your current position
  • Identify the pivot paths available
  • Reach the internal database host
45 min 250 XP
Sign in and unlock
Medium

Web Application Assessment Range

A full application assessment against a purpose-built target with several classes of vulnerability.

  • Complete a full methodology pass
  • Find at least one injection flaw
  • Find the broken access control
90 min · 2 flags 490 XP
Sign in and unlock
Medium

API Security Range

A REST API with authorisation problems that do not show up in the documentation.

  • Enumerate the undocumented endpoints
  • Demonstrate the object-level authorisation flaw
  • Find the mass assignment issue
75 min · 1 flags 370 XP
Sign in and unlock
Medium

Incident Response Range

A compromised host with artefacts to find. Reconstruct what happened and when.

  • Establish the initial access vector
  • Build a timeline of attacker activity
  • Identify the persistence mechanism
90 min · 2 flags 550 XP
Sign in and unlock
Pro Needs Pro 5 ranges

Pro plan only. Active Directory attack paths, cloud misconfiguration chains and manual code review.

Unlock
Hard

Domain Escalation Lab

A small Windows domain with a realistic set of misconfigurations. Go from a low-privileged user to Domain Admin, then w…

  • Map the domain attack paths
  • Escalate to Domain Admin
  • Identify the detection signature of each step
45 min 500 XP
Sign in and unlock
Hard

Capture the Flag: Chained

Nothing here is critical on its own. Three low-severity issues chain into full compromise — the exercise is seeing the …

  • Find all three individual issues
  • Work out how they combine
  • Achieve full compromise via the chain
45 min 500 XP
Sign in and unlock
Hard

Active Directory Attack Path Range

A realistic AD environment. Find a path from a standard user to domain admin.

  • Enumerate the domain from a standard user
  • Identify the privilege escalation chain
  • Reach domain administrator
120 min · 1 flags 800 XP
Sign in and unlock
Hard

Cloud Misconfiguration Range

A cloud environment with IAM and storage misconfigurations that compound.

  • Identify the publicly reachable storage
  • Enumerate the over-permissive IAM role
  • Demonstrate the privilege escalation
100 min · 1 flags 800 XP
Sign in and unlock
Hard

Secure Code Review Range

A real codebase with real bugs. Find them by reading, not by fuzzing.

  • Complete a structured review of the auth module
  • Identify the injection sink
  • Find the race condition
110 min · 1 flags 800 XP
Sign in and unlock

Lab scope is not a suggestion

Every exercise brief states exactly which hosts are in scope. Testing anything outside that range — including other students' instances — ends lab access. This isn't bureaucracy; scope discipline is the skill that separates a professional tester from a liability, and it's assessed like everything else.

  • Written scope in every brief, before any tooling is mentioned
  • Techniques taught with their legal context attached
  • Responsible disclosure practised as part of the exercise
  • No lab content is transferable to systems you don't own

Want lab access for your team?

We build private ranges for internal security training. Tell us the skill level and the stack you run.

Prefer a form? Request security assistance