Skip to content

Launch a vulnerable lab in minutes. Destroy it when you're done.

Pick a lab, choose where it runs, and get an isolated virtual machine with its address and logins. Built for red teams, students and detection engineers who need something real to attack and observe.

Free during the initial launch. Use these labs only on systems and networks you are authorized to test.

Internetoutbound blocked
You, over the host or VPN, through a gate into the private network

Private lab network

10.66.4.0/24

Ubuntu VM

10.66.4.10

  • OWASP Juice Shop

    :3000

  • DVWA

    :80

Every deployment gets a private network like this one, with its own address and no route in from outside.

From catalog to running lab

  1. 1

    Pick a lab

    Browse the catalog and choose the target you want to attack.

  2. 2

    Choose where it runs

    Select a connected runner. Cloud targets are coming next.

  3. 3

    Check readiness

    The platform checks memory, disk and quota before anything starts.

  4. 4

    Deploy

    An isolated virtual machine is built with the lab inside it.

  5. 5

    Connect and test

    You get the address, ports and credentials for the lab.

  6. 6

    Destroy

    Tear it down yourself, or let the timer clean it up for you.

A catalog that keeps growing

Labs catalogued
–
One-click deploys
–
Verified on a real VM
–
Full environments
–
Labs by area
AreaLabsReady to deployVerifiedFull environments
Loading areas…

Several cloud labs (AWSGoat, Sadcloud, CloudFoxable, TerraGoat) are plan-only: they create billable, public resources and need your own cloud credentials. Kubernetes labs need a cluster and Active Directory labs are multi-VM builds; Splunk Attack Range is the one-click option for a Windows domain with Sysmon feeding Splunk.

Built so a vulnerable lab stays contained

A private network per deployment
Each lab sits on its own subnet with its own address range.
Never exposed to the internet
There is no route in from outside; you reach it from the host or over VPN.
Cleaned up automatically
A timer destroys the environment so nothing vulnerable is left running.
Credentials are encrypted
Lab logins are stored encrypted and every view is recorded.
Every action is on the record
Deployments, invites and account changes are written to an audit log.
Separate organizations
Teams are isolated from each other, and viewers get read-only access.

Local today, cloud next

Deployments run on the machine that hosts the platform. VPS and cloud (AWS, Azure, Google Cloud) targets are planned for the next phase, using the same wizard.

Ready to attack something real?

Create an account and browse the full catalog.

Create a free account