warming up your workspace

Python practice in Cybersecurity

Browse the rooms before signing in. Opening a room requires an account and follows your existing access. Practice does not issue certificates.

  • Caesar Intercept

    Decoding a C2 beacon string before it rotates.

    classical-crypto. Free room.

  • Checksum Gate

    Fingerprinting firmware before the update daemon times out.

    hashing. Free room.

  • Hex Dump Rescue

    Recovering a clobbered config value before the next deploy.

    encoding. Free room.

  • Signal Noise

    Security engineer triaging a live phishing report.

    encoding. Free room.

  • Log Timestamp Triage

    Pulling a suspicious login window before the ticket escalates.

    log-forensics. Account access required.

  • Salted Crack

    Recovering a salted password before the red team must pivot.

    password-cracking. Account access required.

  • Vigenere Tap

    Decrypting a wiretapped side-channel before the log is purged.

    classical-crypto. Account access required.

  • XOR Key Recovery

    Recovering a ransomware XOR key before the VM snapshot expires.

    modern-crypto. Account access required.

  • Frequency Crack

    Breaking a single-byte XOR cipher before the red-team debrief.

    classical-crypto. Account access required.

  • Packet Source Filter

    Finding hosts talking to a malicious CIDR before forensics closes.

    network-analysis. Account access required.

  • Rainbow Resistance

    Proving a service stores raw SHA-1 instead of bcrypt.

    hashing. Account access required.

  • Repeating-Key Decrypt

    Cracking repeating-XOR beacon traffic before the window closes.

    modern-crypto. Account access required.

  • ECB Oracle Probe

    Detecting ECB mode in a staging encryption oracle.

    modern-crypto. Account access required.

  • Cookie Forge

    Forging an admin cookie from a weak HMAC key before the bounty closes.

    web-security. Account access required.

  • Log Pivot Hunt

    Reconstructing lateral movement from a multi-service log corpus.

    log-forensics. Account access required.

  • VM Disassemble

    Tracing a crackme stack VM to find the serial before the portal closes.

    reverse-engineering. Account access required.

  • Beacon Fingerprint

    Scoring periodic C2 beaconing from connection timestamps.

    network-analysis, log-forensics. Account access required.

  • Hashcat Helper

    Routing a mixed batch of captured hashes to the right algorithm.

    password-cracking, hashing. Account access required.

  • Operation Nightfall

    A full red-team operation racing the blue team's automated rollback.

    encoding, classical-crypto, modern-crypto, password-cracking, web-security, reverse-engineering. Account access required.

  • Polyglot Payload

    Delivering an obfuscated payload through a strict WAF.

    encoding, modern-crypto. Account access required.