Real pentests.
Not flags.
Break realistic company systems on your own machine and bring back the analyst's credentials.
← All labs
Invoice portal
Globex Finance's supplier portal. The finance analyst behind it approves every payout.
Category
web
Difficulty
Medium
Runtime
Docker
Skills
3
Submit evidence
username:password
0
hypervisors supported
0
flags to guess
0%
free, open source
How it works
From target to evidence.
Every lab is pinned, open source and yours to run. The evidence is unique to you.
Launcher
cyberctf start
Your lab
Docker · Vagrant
Evidence
unique to you
Completed
verified by the API
Platform
Everything a real engagement needs.
Built around a map of cybersecurity skills, so every lab you complete says something precise about what you can do.
Mapped to a skills graph
Each lab trains specific skills, from detecting an injection to exploiting it. Your progress builds a picture of what you actually master.
you
analyst2686:q7#Rk2!mWz9pLx4eanother player
analyst2686:Zt8%bN4@cHw2sKv6Evidence, unique to you
Same lab, same account, different secret. Writeups can't complete the lab for you.
Docker or full VMs
Containers for web targets, multi-VM networks through Vagrant on the hypervisor you already use.
CyberCTF/invoice-portal-sqli
docker-compose.yml
lab.json
evidence/claim-evidence.sh
build/web/src/…
tests/test_exploit.py
Open source, pinned
Every lab is a public repository, downloaded at an exact commit. Read it, run it offline, improve it.
Labs
Pick a target.
No labs published yet. They're on their way.
The launcher
Run it. Break it. Prove it.
One click downloads the lab at a pinned commit, starts it in Docker or a VM, and hands it your personal evidence.
Download the launcherYour first target is waiting.
Free, forever. Create an account, install the launcher, and bring back your first evidence tonight.