Real scenarios
Believable red-team and blue-team missions—not passive theory or click-through quizzes.
Get the complete collection of 90 practical cyber security labs—and every future lab we release. Run them on your own VM, capture real flags, and train at your pace without another subscription.
# Mission 29 — SQL Injection Deep Dive
labuser@kali:~/lab29$ ./exploit.py --dump users
[+] Query broken
[+] Admin record extracted
[+] Flag recovered
labuser@kali:~/lab29$ ./submit_flag 'FLAG{sql_mastered}'
[+] Correct! Lab complete.
labuser@kali:~/lab29$ ▋
Everything you need to move from setup to a verified flag in one focused session.
Believable red-team and blue-team missions—not passive theory or click-through quizzes.
Build each vulnerable environment on your own isolated VM in minutes.
Enough direction to keep moving and enough space to learn by doing.
Use the terminal, scanners, scripts, and workflows practitioners use.
A built-in submit_flag checker proves you solved each objective.
Every new lab joins your collection automatically, with no extra payment.
One purchase unlocks the complete current and future collection.
Start at Lab 01 or jump to the topic that closes your skill gap.
Follow the beginner VM guide, run the setup, use real tools, and work your way to the flag.
Clean up the environment and keep moving through the roadmap.
Start with Lab 01: Linux Fundamentals for Hackers. Navigate a compromised server, abuse a permission mistake, and capture your first flag.
Click below to start the full lab immediately.
Start Lab 01 →No card required. Runs on your own VM.
A progression where every new lab builds on skills you already earned.
Shells, permissions, logs, SSH, networking, scripting, passwords, containers, and OSINT.
OWASP flaws, privilege escalation, SUID, cron abuse, persistence, and Windows internals.
BloodHound, Kerberoasting, SQL injection, XSS, CSRF, SSRF, XXE, and RCE.
Stealth scanning, pivoting, forensics, incident response, cloud, and kernel exploits.
Trust abuse, AD CS, reversing, malware sandboxing, YARA, and Sigma.
Attack, detect, investigate, and report on one complete environment.
Phishing, TLS, file forensics, firewalls, PowerShell defense, API auth, image forensics, DNS analysis, OAuth, and K8s RBAC.
SSTI, GraphQL, JWT, request smuggling, prototype pollution, WebSockets, logic flaws, NoSQL, cache attacks, and deserialization.
Buffer overflows, Metasploit, content discovery, spraying, NTLM relay, PrintNightmare, GPO abuse, CI/CD abuse, escapes, and prompt injection.
Sysmon, registry forensics, SIEM queries, ATT&CK mapping, ransomware response, cloud DFIR, Android, triage, Snort, and crypto failures.
Follow a structured path from Linux fundamentals to advanced red-team and blue-team operations—without a monthly bill.
Get the whole cyber security roadmap today and every lab added tomorrow.
One-time purchase · Lifetime access · No subscription
Short, practical notes — every one pointing back to hands-on practice.
Learn the container security foundations that matter first: image provenance, secrets, privileges, network boundaries, and Kubernetes RBAC.
Compare YARA and Sigma by data source, rule structure, tuning, and workflow, with safe examples for detection beginners.
Build a small SOC analyst home lab around logs, alerts, timelines, detection rules, and written incident conclusions.
Yes. One purchase gives you lifetime access to all 90+ current labs and every future lab. There is no subscription or renewal.
A dedicated Ubuntu or Kali VM for most labs, plus Windows Server for the Active Directory track. Our beginner VM setup guide covers installation, isolation, and snapshots.
Each fictional vulnerable environment runs in an isolated VM you control. Only test systems you own or have permission to test.
Yes. The road starts with fundamentals and steadily increases in difficulty.
Every lesson passes automated structure and static checks. Platform-specific end-to-end verification is tracked separately because tools and operating systems change over time. If something breaks, open a GitHub issue or email us at admin@threatroad.com — we'll investigate it and send you an update.
Yes. Use the Request a Lab form and tell us what you want to train next.
Get the complete roadmap now and every future Threat Road lab at no extra cost.