practice range
picoCTF Gym
Carnegie Mellon's beginner CTF archive. Every past challenge stays playable, and the hints nudge you without handing over the answer.
// PES University — Electronic City Campus
Everything the club actually uses — practice ranges, tooling and reading. No paid course funnels, no listicles. Start at the top of the path if you have never opened a terminal on purpose.
Work through these in order. Each step is a prerequisite for the next one, and each ends with something you can actually submit.
OverTheWire Bandit, levels 0–20. Teaches ssh, file handling, pipes and grep by making you need them. Budget two evenings.
overthewire.org/wargames/banditPortSwigger's Web Security Academy — the SQL injection and access control tracks. Free labs, graded, written by the people who build Burp.
portswigger.net/web-securitypicoCTF's practice gym. Beginner categories are solvable with step 01 and 02 alone — the rest is where you find out what you like.
play.picoctf.org/practiceBring one unsolved challenge to the weekly session. Explaining where you got stuck is the fastest way through it, and it is how the team gets picked.
weekly sessions & scheduleFilter by category, or search by name, tool or topic. Everything listed is free unless the card says otherwise.
60 resources
practice range
Carnegie Mellon's beginner CTF archive. Every past challenge stays playable, and the hints nudge you without handing over the answer.
practice range
Guided rooms with an attack box in the browser. Best when you want to fill a gap in one topic rather than hack around freely.
practice range
Full machines to root, with no hand holding. Start on retired boxes, and only read someone's writeup after you finish.
course
ASU's binary exploitation course, lectures and graded challenges included. It is the most complete free route into memory corruption.
practice range
Cryptography taught as puzzles you solve in Python. It runs from modular arithmetic up to real RSA and AES failures.
exercises
Eight sets of attacks that you implement yourself. Slow, unglamorous, and the reason people stop trusting their own crypto code.
course
Labs and theory for every major web bug class, from injection to SSRF to request smuggling. This is what we teach from.
practice range
A few hundred short challenges sorted by category. Handy when you want one problem in one topic instead of a whole machine.
practice range
Bandit is only the first game. Natas covers web, Narnia and Behemoth cover exploitation, and Krypton covers ciphers, all over ssh.
practice range
Vulnerable VMs you download and run in VirtualBox. No subscription and no network limits, which helps when the campus wifi is having a day.
practice range
HackerOne's web challenges, built around bugs that turn up in real bounty reports. Flags here also unlock private programme invites.
practice range
A deliberately broken shop app you host yourself, with a scoreboard built in. It is our usual target for web workshops.
practice range
Eight challenges about return oriented programming and nothing else. Do them the week after you first get past a stack canary.
practice range
Phoenix and Nebula, which took over from Protostar. Graded overflows, format strings and privilege escalation on ready made VMs.
practice range
Small, sharp exploitation puzzles served over ssh. Each one hides a single trick, so they work well solved in pairs.
practice range
Embedded exploitation against a fictional lock, all in the browser with a debugger attached. The gentlest way into assembly.
practice range
A steady stream of reversing binaries uploaded by other people and rated by difficulty. Pick a one star, open Ghidra, find the check.
practice range
Cloud misconfiguration taught as a hunt through one badly built AWS account. Six levels, and you do not need an account of your own.
calendar
Every live competition, how much it is worth, and the writeups afterwards. Check it on Monday and pick the weekend event we play together.
reference
The wiki everyone has open mid challenge. Enumeration checklists and escalation tricks for each service and platform.
reference
A payload and bypass collection sorted by bug class. Read the methodology notes too, not just the strings you can paste.
reference
Unix binaries you can abuse to escape a restricted shell or escalate privileges. Use LOLBAS for the Windows side.
reference
The Windows half of the same idea. Signed Microsoft binaries that download, run or bypass things, and a good reading list for detection work.
book
Trail of Bits' short guide to how competitions work and how to prepare for one. Read it before your first live event.
book
Binary exploitation explained one real CTF challenge at a time, starting at simple overflows and ending in heap grooming.
methodology
How a real web assessment gets scoped and run, test by test. It turns scattered lab tricks into something you can repeat on a job.
reference
Archived public exploits with the papers behind them. Read the code before you run it, since plenty of what is posted needs fixing first.
tool
An intercepting proxy for anything over HTTP. Learn Repeater and Decoder first, because Intruder is rate limited on the free build.
tool
The NSA's reverse engineering suite, with a decompiler that holds up. It covers nearly every reversing challenge you will see as a student.
tool
A Python library for writing exploits. Process and socket handling, packing, ROP and shellcode helpers in a few lines.
tool
A gdb plugin that makes the heap, the stack and the registers readable. Install it the same evening you install pwntools.
tool
Encoding, decoding and analysis chained together in the browser. First thing to try on a blob of text you cannot identify.
tool
Packet capture and analysis. Most network forensics challenges are one display filter and a follow stream away from solved.
tool
A memory forensics framework. It pulls processes, network connections and injected code out of a RAM image.
tool
Host discovery, port scanning and service fingerprinting. Learn what the flags do before pasting a scan line from someone's writeup.
tool
A fast fuzzer for directories, subdomains, parameters and virtual hosts. Filter by response size early or you will drown in 200s.
wordlists
The wordlist collection every fuzzer expects to find on disk. Paths, parameters, passwords, payloads. Clone it once and keep it.
tool
Automated SQL injection detection and exploitation. Use it after you have found the injection by hand, not instead of looking.
tool
GPU password cracking with rule based mutation. Work out the hash mode first, since most failed cracks are just the wrong -m flag.
tool
Throws the standard RSA attacks at a weak key, from small exponent to Wiener and Fermat. Then go and read why the one that worked worked.
tool
Finds and extracts files hidden inside other files, firmware images included. The usual first move on an unexplained binary blob.
tool
Runs a whole steganography toolchain over an uploaded image at once. Saves twenty minutes on every flag hidden in a picture.
tool
Disk image forensics with timelines, deleted file recovery and keyword search. A GUI over The Sleuth Kit, and enough for most DFIR rooms.
tool
Builds a reverse shell one liner for whatever binary the target actually has, with the matching listener command next to it.
reference
A map of open source intelligence sources arranged by what you are starting from, whether that is a username, a domain, an image or a phone number.
tool
Checks a username across hundreds of sites. Run it on your own handles once and see how much of a trail you have left.
tool
A search engine for exposed services and their banners. Useful for scoping recon, and sobering when you point it at your own network.
reference
The toolkit Bellingcat's researchers actually use. Geolocation, imagery, transport and archive sources, kept up to date.
practice range
Investigations from the defender's chair. Log triage, phishing analysis and incident timelines. Rarer skill, and easier hiring.
practice range
Blue team CTFs built on real captures and memory images. The closest free thing to sitting a shift in a SOC.
practice range
A simulated SOC queue with alerts to close and evidence to attach. It teaches the workflow, not only the analysis.
datasets
Years of real infection pcaps with exercises and answers. Bring one to a Friday session and build the timeline as a group.
reference
The shared vocabulary for attacker behaviour. Once you can name a technique, detection engineering starts to make sense.
reference
Detection rules written once and converted to whatever SIEM you are stuck with. Read a few before you write your first one.
tool
Small scripted tests mapped to ATT&CK techniques. Run one in a lab VM, then check whether your logging noticed.
reference
Prompt injection, insecure output handling, data leakage and the rest. The current baseline for reviewing anything with a model in it.
practice range
Seven levels of prompt injection against system prompts that get harder each time. Twenty minutes, and the lesson sticks.
practice range
A chatbot CTF where the goal is a free flight. It shows how a model with tool access turns into an application vulnerability.
tool
A vulnerability scanner for LLMs. Jailbreak, leakage and toxicity probes run as one suite against a model you host yourself.
reference
ATT&CK's counterpart for machine learning systems. Real tactics used against models, from evasion through to model theft.
The list is maintained by members. Send a link and one line on why it earned a slot.