Hack The Box 
Standalone Windows and Linux machines for solo pentesting, each with its own network segment and an attack surface you have to find yourself. A free account exposes a small set of machines; the rest sit behind a subscription.
Data verified
30 platforms in the catalog
Online platforms catalog
CTFs, labs, VMs and academies. Filter by level, price and domain.
Click a map cell or a bar — the catalog filters by it.
fewermore
| Level | Category | Platforms |
|---|---|---|
| Beginner | Web | 11 |
| Beginner | Pwn | 9 |
| Beginner | Reverse | 7 |
| Beginner | Cryptography | 9 |
| Beginner | Forensics | 5 |
| Beginner | Systems | 8 |
| Beginner | Networks | 3 |
| Beginner | OSINT | 4 |
| Beginner | Steganography | 1 |
| Beginner | Misc | 3 |
| Beginner | Secure code | 3 |
| Beginner | DFIR | 0 |
| Beginner | SecOps | 0 |
| Intermediate | Web | 14 |
| Intermediate | Pwn | 12 |
| Intermediate | Reverse | 11 |
| Intermediate | Cryptography | 11 |
| Intermediate | Forensics | 7 |
| Intermediate | Systems | 11 |
| Intermediate | Networks | 5 |
| Intermediate | OSINT | 4 |
| Intermediate | Steganography | 1 |
| Intermediate | Misc | 4 |
| Intermediate | Secure code | 3 |
| Intermediate | DFIR | 1 |
| Intermediate | SecOps | 1 |
| Advanced | Web | 11 |
| Advanced | Pwn | 10 |
| Advanced | Reverse | 10 |
| Advanced | Cryptography | 10 |
| Advanced | Forensics | 7 |
| Advanced | Systems | 7 |
| Advanced | Networks | 3 |
| Advanced | OSINT | 4 |
| Advanced | Steganography | 1 |
| Advanced | Misc | 2 |
| Advanced | Secure code | 3 |
| Advanced | DFIR | 1 |
| Advanced | SecOps | 1 |
| Format | Platforms |
|---|---|
| Challenges | 15 |
| Labs | 5 |
| Virtual machines | 4 |
| Learning | 11 |
| Aggregator | 1 |
Standalone Windows and Linux machines for solo pentesting, each with its own network segment and an attack surface you have to find yourself. A free account exposes a small set of machines; the rest sit behind a subscription.
Short rooms on networks, Linux, web and crypto, each with hints and a walkthrough behind them. The site advertises over 1,000 labs and learning paths, and a free account is enough to work through the early material. No ranked season, no team rating.
The web pentesting academy run by the makers of Burp Suite, working through the OWASP list topic by topic, from recon to business logic flaws. Practice happens in labs on deliberately vulnerable applications. Learning is free; the exam at the end is not.
Not a trainer but a noticeboard: a calendar of competitions, a team list and team ratings. You use it to see what is running, what is announced, and who plays where. There is nothing to solve here, only events to enter.
A Russian-language platform with over 400 challenges across eight categories, including the steganography most platforms skip. Flagged tasks sit next to virtual machines and theory material. The running season is free; the archive is behind premium.
Cryptography tasks from classical ciphers to protocol-level bugs, grouped into topic pyramids, each with an interactive hint mode. Counting the per-topic counters gives about 316 challenges, some of them from the community CTF archive rather than the platform.
The cyber range from Positive Technologies: a virtual infrastructure with copies of real IT systems, each carrying its own business context. Work is organised in seasons with a timer and a rating, and annual tournaments decide who qualifies with a team.
A teaching platform that starts at zero: systems, memory, the shell, crypto, web. Practice runs through dojos where belts mark progress from white to black. Around 5,743 tasks are listed, but the graded core is the first eight dojos.
A Russian-language site from the TaipanByte team holding roughly a hundred tasks across the main categories. The format is a plain CTF archive: statement, flag, submission through an account. No leaderboard pressure and no season running.
A game of 35 levels where every answer is a command typed into the terminal of a remote machine. You connect over SSH and work through Linux itself, from plain file commands to privileges and SSH tunnels. Nothing to install, no account.
A crackme archive holding 4,778 binaries. The task is always the same shape: download the file, work out the check, recover the key or write a keygen. Filters cover difficulty, language and operating system, and registration is optional.
Four binaries under Phoenix take you through the classic memory bug classes one protection at a time; Nebula and Fusion are shorter linear paths. Open, with no account. The site data carries 57 challenges, a hand tally rather than a published count.
A task list that assumes you have never solved one, with no lab to set up. Web, crypto, reversing, forensics, pwn and osint sit side by side, each rated by difficulty, and every flag goes into the same submission box. No counter is published.
A blue-team site in an otherwise offensive catalogue: evidence triage, memory and disk imaging, network capture analysis, threat hunting and perimeter defence. Entry is a Join For Free button rather than a request form, with self-contained labs sitting alongside seasonal competitions.
Cryptography exercises that climb from raw bytes and XOR to AES, Diffie-Hellman, RSA and DSA, then hashing and the group theory underneath. You implement the primitive yourself; nothing is simulated and nothing is submitted. The site sits in the open and publishes no task counter.
A challenge board in fifteen categories, with the familiar furniture: a statement, tiered hints, a flag to submit and points for solves. The site advertises more than 300 challenges, a marketing figure rather than a count anyone maintains.
A challenge set built on a stated refusal: no guessing and no simulation. Challenges run against real systems and real data, so the answer is recoverable from what you are handed. Six categories: Crypto, Forensics, Misc, Pwning, Reversing, Web. Registration required.
Secure coding lessons in the register of a developer reference: what a vulnerability is, the code shape it arrives in, and the fix that closes it. No challenges, no flag submission. The site advertises 45-plus lessons, recent ones covering LLM Slopsquatting, CSS Injection and CORS.
Web labs grouped by OWASP topic, with a video walkthrough beside each one. The labs are built on real CVEs rather than invented bugs, so the fix you learn is the fix that shipped. The site advertises more than 700 hands-on labs; the free share covers most of the Top 10.
A beginner Linux course: command line, file systems, permissions, processes and packages. Lessons run in sequence and each ends with a task you type and have checked in the browser. Later sections reach the kernel. Free, with no registration and no lesson counter.
Tasks solved through the command line, where the statement describes a result and leaves the tools to you. Every task is checked automatically, with solutions and a leaderboard alongside. The basic levels need no registration, and no task counter is published.
A large CTF archive with several hundred challenges across the usual categories, from basic web to reversing and crypto. The format is classic: statement, flag, submit through a form. Worth knowing before you plan a session: the site sits behind an anti-bot.
Haxits: 38 riddles where you type an answer into a box instead of submitting a flag. They lean on regular expressions, word lists and numeric sequences, all solvable in the browser with nothing installed and no account. There is no ranking.
A Russian platform on a deliberately slow schedule: the organisers publish one CTF challenge a month and leave it open for the whole month. Categories are web, pwn, crypto and reverse, and the top three solvers each month enter a Hall of Fame.
A twenty-level quiz on security basics that runs in the browser, with no account and no tooling. Some levels are multiple choice, some are short forms you submit. An evening is enough to finish it, and the honest outcome is a list of fundamentals that have gone soft.
A web quest running since 2003, climbing from malformed HTML through XSS and SQL injection to access-control bypasses. Every level ships with a writeup, and the sequence was laid out when such bugs were still live on most stacks. The code has barely moved since.
Training on writing secure code, organised around the OWASP Top 10 for web and API plus LLM topics. The OWASP exercises stay open without an account; audit and reporting moved behind an enterprise plan after the Security Compass acquisition. No exercise counter is published.
46 binary exploitation challenges, each built around one protection: ASLR, canary, RELRO, NX. You analyse how a program was compiled and get past it, with a few reverse challenges alongside. Docker runs on their own servers, and the list stopped growing years ago.
A catalogue of deliberately vulnerable virtual machines you run on your own hypervisor. Each entry declares a difficulty, and the machines are built around a specific stack rather than a generic victim host: Samba, Kerberos, an internal CMS, not a bare Linux box.
Crackme-style reversing tasks across Windows, Linux, .Net, Flash, Java, Python and mobile. The format is close to a crackme: a binary, a check, and an algorithm to recover. It assumes you can already read a disassembler. No challenge counter is published.