← Back

🔬 Free Cybersecurity Labs

Practice your skills in safe, legal environments with these world-class platforms

🌐

PortSwigger Web Security Academy

Web Penetration Testing

The most comprehensive free training platform for web application security. Created by the makers of Burp Suite, featuring interactive labs covering SQL injection, XSS, CSRF, and dozens of other vulnerabilities.

  • Hundreds of interactive labs from beginner to expert
  • Free Burp Suite Community Edition included
  • Mystery lab challenges for exam preparation
  • Certification path available
Start Learning
📦

Hack The Box

Penetration Testing

Gamified cybersecurity training platform with 1.7M+ users. Features virtual machines, challenges, and realistic corporate scenarios. Perfect for offensive and defensive security training.

  • 450+ hacking labs across 300+ machines
  • Weekly new machine and challenge releases
  • HTB Academy with guided learning paths
  • Active community and competitions
Join HTB
🎮

TryHackMe

Beginner-Friendly Training

Learn cybersecurity through short, gamified real-world labs. Features cloud-hosted VMs deployable with one click. Over 4M users trust TryHackMe for offensive, defensive, and cloud security training.

  • 800+ real-world cyber scenarios
  • Guided learning paths for all skill levels
  • Browser-based, no downloads required
  • Free tier with extensive content
Explore THM
🚩

PicoCTF

CTF Competition

World's largest free hacking competition from Carnegie Mellon University. Designed for middle school through professional level. Features picoGym for year-round practice with cryptography, forensics, web exploitation, and binary challenges.

  • 550,000+ active users worldwide
  • Annual competition with prizes
  • picoGym available 24/7
  • Progressive difficulty levels
Play PicoCTF
⚔️

OverTheWire

Linux & Command Line

Collection of wargames teaching security concepts through hands-on challenges. Start with Bandit for Linux basics, progress to Leviathan for binary analysis, and Narnia for buffer overflows. Perfect for building fundamental skills.

  • Multiple progressive wargame series
  • Focus on Linux fundamentals and scripting
  • Binary exploitation and reverse engineering
  • Active community support
Start Wargames
🌟

Hack This Site

Ethical Hacking

One of the oldest and most respected free hacking training grounds. Features basic to advanced challenges teaching web application security, programming, cryptography, and steganography in a safe, legal environment.

  • Basic, Realistic, and Advanced missions
  • Application security challenges
  • Programming and logic puzzles
  • Large community forums
Hack This Site
💿

VulnHub

Offline Virtual Machines

Download vulnerable virtual machines for offline penetration testing practice. Features hundreds of community-created VMs covering network pentesting, web exploitation, privilege escalation, and real-world scenarios. Perfect for building a personal lab.

  • 500+ vulnerable VMs to download
  • Run locally with VirtualBox/VMware
  • Beginner to advanced difficulty levels
  • Community walkthroughs available
Download VMs
🧙

Gandalf AI (Lakera)

AI Prompt Injection

Interactive prompt injection challenge by Lakera. Try to make Gandalf reveal secret passwords through 8 progressively difficult levels with increasingly sophisticated defenses. Learn how LLMs can be exploited and defended against prompt injection attacks in a gamified environment.

  • 8 levels of prompt injection challenges
  • Learn to bypass AI security filters
  • Based on OWASP LLM Top 10
  • Real-world LLM security scenarios
Play Gandalf
🎯

Immersive Labs AI Prompting

AI Security Training

Beat the Bot challenge from Immersive Labs. Interactive prompt injection training with multiple difficulty levels. Learn to identify and exploit LLM vulnerabilities including DLP bypass, word filtering, and translation tricks in realistic scenarios.

  • 10 progressive challenge levels
  • Gamified AI security training
  • DLP and filter bypass techniques
  • Free educational platform
Start Challenge
🔓

PromptMe

LLM Security CTF

Educational project showcasing LLM security vulnerabilities. 10 hands-on CTF-style challenges inspired by OWASP LLM Top 10. Run locally using Ollama framework with open-source models. Learn prompt injection, jailbreaking, and AI red teaming in a safe environment.

  • 10 OWASP LLM Top 10 challenges
  • Runs locally with Ollama
  • CTF-style flag capture format
  • Hints and guided solutions included
Clone Repository
🎯

XSS Game by Google

XSS Specialization

Google's interactive training platform dedicated to Cross-Site Scripting (XSS) vulnerabilities. Six progressive levels teaching you to find and exploit XSS bugs. Learn the coding patterns that lead to XSS and how to prevent them.

  • 6 levels of XSS challenges
  • Real-world vulnerable scenarios
  • Hints and source code provided
  • Browser-based, instant access
Play XSS Game
🧀

Google Gruyere

Web Security

Intentionally vulnerable web application from Google. Practice finding and exploiting common web security flaws including XSS, CSRF, information disclosure, denial of service, and path traversal vulnerabilities.

  • Realistic vulnerable web application
  • Multiple vulnerability types
  • Detailed exploitation guides
  • Learn defensive techniques
Access Gruyere