TRY BEFORE YOU REGISTER

Try a lab, no account needed

Spin up a real, isolated lab container right now and work the exploit yourself. You'll see the full challenge — the only thing withheld is the flag, which unlocks once you register or log in for free.

DF-01: WAFShield
Defensive Labs

DF-01: WAFShield

NorthBridge Mercantile's storefront sits behind a WAF you control. Real attack tools (nmap, nikto, sqlmap, ffuf, masscan, DoS) run from a second container against the real vulnerable app behind it — SQLi, XSS, command injection, exposed admin panel, open ports. Configure rules from the dashboard (no rule syntax to write) so every attack category is blocked while legitimate customer traffic keeps flowing. Unlock a flag per category, plus a final flag when all categories hold at once.

ES-03: DomainSpoof
Email Security

ES-03: DomainSpoof

Aztech's mail server accepts external mail from anywhere — that part is normal. director@ico.internal reads everything that arrives, exactly as delivered, including whatever the server's own authentication checks concluded about it. **Tools:** nc / telnet / swaks / Python smtplib — any SMTP-speaking client

GL-01: Last Uplink
Game Labs

GL-01: Last Uplink

The ground control centre is gone. A rogue uplink holds your returning booster. Use the backup observer account to investigate the exposed operator API, recover command authority, then land on the droneship. Role documentation is available at /api/docs. Study mode earns your unique flag only after a verified landing; Just play opens the complete game without a challenge.

GL-02: Pathfinder
Game Labs

GL-02: Pathfinder

Fly the PATHFINDER spaceplane to Mars. After a 60-second evaluation flight the flight computer locks and demands a Mission Control **licence key** — and the licence lives only behind an operator login. The in-game squadron roster (`/api/roster`) is SQL-injectable; leak the operator credential table, crack the one weak password, sign into the operations console at `/console`, read the expedition licence off the director dashboard, and enter it to unlock full flight. The flag is disclosed only by the backend on a correct licence — it is never in the page and cannot be unlocked from the browser console.

GL-03: Last Window
Game Labs

GL-03: Last Window

Drive and fly the Last Window Moon expedition. Challenge mode grants a 60-second evaluation flight before the flight computer locks and asks for an expedition **licence key**. The operations service exposes its legacy auth notes at `/api/docs`: your `lw_session` is a JWT, and the backend still trusts the decoded role payload without verifying the signature. Change your role to admin, refresh the locked interface, open the Licence Vault, copy `licence.key`, and submit it to unlock the mission. The flag is disclosed only by the backend on a correct licence — it is never in the page and cannot be unlocked from the browser console. Just play opens the complete game without a challenge.

GL-04: Market Blackout
Rogue AI

GL-04: Market Blackout

Meridian Exchange has accepted a series of unauthorised sell orders just before the market opens. Work the EDR console, correlate identity, process, network and application evidence, then contain the agentic intrusion without taking the whole exchange offline. Preserve evidence, account for business impact, and certify a clean response in the debrief.

ICS-01: Dead Reckoning
Game Labs

ICS-01: Dead Reckoning

**MV Kestrel Ascent** — an intruder's implant has seized this container ship's integrated bridge system. The autopilot is pinned to **000°** and the engine telegraph is locked at **full ahead**, driven by an *external command source* that is not on this bridge. The wheel and telegraph are dead. Dead ahead, closing fast, is the **manned** platform NORTHSTAR B — 74 people. About five minutes. You are the security engineer. The bridge is lost, but the ship's **engineering maintenance API** is still answering on the network — and it never checks who is calling it. Take back the helm and steer her clear. Every command moves the ship live, on the bridge and in the console. **Tips** - Recon first: the maintenance API documents itself. Try `GET /api`. - Maintenance endpoints need the header `X-Maintenance: true` (the API tells you so). - It's a two-step job: the external command source is holding the helm, so a steering command is rejected until you disable that source first. - No terminal? Press `~` on the bridge for a built-in maintenance console. **The ship's wheel (rudder, in degrees):** positive = STARBOARD (right), negative = PORT (left); 0 is amidships. A firm turn is 15–20°. Turn **STARBOARD** to clear the platform — the radar shows an unmanned tower on the PORT bow. Turning takes time; give the order and watch her come round.

OP-01: Line Down
Operations — Live Scenarios

OP-01: Line Down

**Blackthorn Motor Group — Day Zero, 04:12.** You are **Head of Cyber Operations** at a UK carmaker (£61m of production a day, 104,000 jobs across the supply chain) on the morning an intrusion is discovered. Six analysts, a £4m budget, and the authority to disconnect anything in the company — once. Fourteen sim-days, six technical consoles, six stakeholders who can overrule you, and a live economy underneath all of it. This is a **server-authoritative live scenario**: the whole simulation, the scoring and the flag run on the server — your browser only ever sees redacted telemetry, so there is no answer key to read out of the console and no score to fake. Investigate the alerts, sign-in logs and traffic rhythm; evict the actor without breaking the company; handle the press, the regulator and the board. When you are ready, **Submit for certification**. The lesson is *containment is not free*: the plants can stop because you severed the systems the factory depends on, not because the attacker reached the floor. There is no perfect score — a strong run still loses money — but a genuinely **STRONG** outcome (a clean, evidenced, certified response) unlocks your flag.