Specifications
| Format | Labs |
|---|---|
| Level | Beginner, Intermediate, Advanced |
| Price | Paid tier exists |
| Access | Registration required |
| Activity | Active |
| Language | EN |
| Category | Web, Pwn, Cryptography, Systems |
Standalone Windows and Linux machines for solo pentesting, each with its own network segment and an attack surface you have to find yourself. A free account exposes a small set of machines; the rest sit behind a subscription.
Pros & cons
Pros
- Full machines with a network, not isolated vulnerable apps
- Machines graded from easy through Active Directory chains
- A busy community: fresh writeups and new boxes every week
Cons
- The catalogue is the product: without a subscription you see a corner of it
- Each machine needs the VPN client and enough RAM to run a nested network
- Writeups are everywhere, so an unsorted machine is often solved before you start
Who it fits
Suits someone who wants whole hosts rather than dissected web apps. Starting from a walkthrough is fine: machines are graded, and one solved easy box teaches the workflow faster than reading.
Getting started
- Register, then clear the Starting Point machines before touching the main list
- Install Kali in VirtualBox or VMware, the VPN client alone is not enough for AD chains
- Write one note per machine: recon, foothold, the step you got wrong
History
Running for well over a decade and still releasing machines most weeks. The landing page now leads with the corporate Cyber Workforce Development programme, while individual users keep the same machines and academy on a subscription. Machine quality drifts: some are textbook, some are thin.