CyberCTF labs are free, open-source pentest environments you run on your own machine. Each one is a realistic company with one real vulnerability, and ends with evidence to bring back, not a flag.
1. Create your account
Sign up with CyberCTF. Your account is used by the website and the launcher to track the labs you complete.
2. Install the launcher
Download the launcher for macOS, Windows or Linux. You also need:
- Docker (Docker Desktop or Docker Engine) for Docker labs;
- Vagrant and a hypervisor for VM labs.
The launcher's first screen checks what your machine can run.
3. Start a lab
Pick a lab from the catalogue and click Open in the launcher, or start it from the launcher itself. It downloads the lab at a pinned commit and starts it locally.
4. Bring back the evidence
Exploit the vulnerability, find the evidence described in the lab's objective (for example an analyst's credentials), and submit it on the lab page. A correct submission marks the lab as completed.