PENTEST LAB

Advanced offensive security testing environment with isolated, monitored targets for professional red team training and research

[ 01 ] — ATTACK SURFACE

WEB EXPLOITATION

dvwa.lab.testlab.hk · juiceshop.lab.testlab.hk

Seven vulnerable web applications ranging from beginner to advanced challenges. Practice XSS, SQLi, CSRF, file inclusion, and modern web app exploitation techniques.

EASY → HARD
BURP SQLMAP FFUF
3 INSTANCES UP
LAUNCH ▸

NETWORK PENTEST

10.66.0.0/24 — metasploitable2 · metasploitable3

Full subnet of legacy-vulnerable boxes featuring Samba, vsftpd 2.3.4, Tomcat, NFS, SNMP, and more. Perfect for port scanning, service exploitation, pivoting and lateral movement drills.

MEDIUM
NMAP METASPLOIT CHISEL
2 INSTANCES UP
LAUNCH ▸

ACTIVE DIRECTORY

corp.lab.local — DC01 · WS01 · WS02 · FILE01

Windows domain lab with realistic enterprise setup. Practice Kerberoasting, AS-REP roasting, Pass-the-Hash, DCSync, GPO abuse, golden ticket attacks, and BloodHound attack-path mapping.

HARD
IMPACKET CRACKMAPEXEC BLOODHOUND
4 HOSTS UP
LAUNCH ▸

REVERSE ENGINEERING

re.lab.testlab.hk — crackmes · packed bins

Curated collection of reverse engineering challenges from simple crackmes to complex packed binaries. Includes malware analysis samples in isolated sandbox environments.

MEDIUM → HARD
GHIDRA X64DBG R2
SANDBOX READY
LAUNCH ▸

C2 & POST-EXPLOIT

c2.lab.testlab.hk — teamserver isolated

Red-team infrastructure zone dedicated to C2 operations, beacon lifecycle management, AV/EDR evasion research, DLL sideloading, and persistence testing on hardened endpoints.

HARD
SLIVER HAVOC MYTHIC
ON STANDBY
REQUEST ▸

CRYPTO & OSINT

ctf.lab.testlab.hk · osint.lab.testlab.hk

CryptoCraft challenges featuring padding oracles, hash length extension, weak-RSA, and more. OSINT range includes footprinting, dorking, and breach-data correlation on synthetic personas.

CRYPTO OSINT CTF
LAUNCH ▸

[ 02 ] — RULES OF ENGAGEMENT

STAY LEGAL, STAY SHARP

01

ONLY TARGETS INSIDE THE RANGE

Confine all testing activities strictly to designated lab environments. External targeting is prohibited.

02

NO EXFIL BEYOND THE WALL

All data must remain within the lab boundaries. No external data exfiltration permitted.

03

NO DoS / DESTRUCTIVE PAYLOADS

Avoid denial-of-service attacks or destructive payloads that could impact lab availability.

04

LOG EVERYTHING

Every session produces a comprehensive report: timeline, payloads, impact, and remediation. If it isn't documented, it didn't happen.

05

RESET AFTER COMPROMISE

Always reset target environments after successful compromise to maintain lab integrity.

06

AUTHORIZED HANDS ONLY

Access restricted to authorized personnel with proper credentials and training.