CTF & Practice Labs
Practice environments for offensive and defensive security skills: capture-the-flag platforms, deliberately vulnerable applications, and wargames where techniques can be exercised without touching systems the learner does not own.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| Blue Team Labs Online | Proprietary | Web | Freemium | Profile→ |
| CTFd | Apache-2.0 | Linux, macOS, Windows | Free / Commercial | Profile→ |
| CyberDefenders | Proprietary | Web | Freemium | Profile→ |
| DVWA | GPL-3.0-or-later | Linux, macOS, Windows | Open Source | Profile→ |
| Hack The Box | Proprietary | Web | Freemium | Profile→ |
| Hackviser | Proprietary | Web | Freemium | Profile→ |
| LetsDefend | Proprietary | Web | Freemium | Profile→ |
| Metasploitable 3 | BSD-3-Clause | Linux, Windows | Open Source | Profile→ |
| OverTheWire | Proprietary (free service) | Web | Free | Profile→ |
| OWASP Juice Shop | MIT | Linux, macOS, Windows | Open Source | Profile→ |
| picoCTF | Proprietary (free service) | Web | Free | Profile→ |
| PortSwigger Web Security Academy | Proprietary (free service) | Web | Free | Profile→ |
| TryHackMe | Proprietary | Web | Freemium | Profile→ |
| Vulhub | MIT | Linux, macOS, Windows | Open Source | Profile→ |
| VulnHub | Proprietary (free service) | Web | Free | Profile→ |
| VulNyx | GPL-3.0 | Web | Free | Profile→ |
Software in CTF & Practice Labs
Blue Team Labs Online
FreemiumGamified defender practice covering incident response, forensics, SIEM, and phishing analysis.
CTFd
Free / CommercialOpen source platform for hosting capture-the-flag competitions with plugins and dynamic scoring.
CyberDefenders
FreemiumBlue team and DFIR labs built from real forensic artifacts such as memory dumps and PCAPs.
DVWA
Open SourceDamn Vulnerable Web Application, a PHP web app with deliberately insecure code for practice.
Hack The Box
FreemiumHands-on hacking labs, machines, and CTF competitions with academy courses and enterprise ranges.
Hackviser
FreemiumHands-on training platform with labs, scenario machines, and browser-based tooling plus certifications.
LetsDefend
FreemiumSimulated SOC training platform where learners investigate realistic alerts in a blue team workflow.
Metasploitable 3
Open SourceDeliberately vulnerable Windows and Ubuntu VMs built with Packer and Vagrant for exploit practice.
OverTheWire
FreeFree SSH-based wargames teaching Linux, networking, and security fundamentals level by level.
OWASP Juice Shop
Open SourceIntentionally insecure Node.js web application covering the OWASP Top 10 and beyond, with built-in score board.
picoCTF
FreeFree Carnegie Mellon CTF platform and year-round learning game built for students.
Free web security training with hundreds of interactive labs from the makers of Burp Suite.
TryHackMe
FreemiumGuided, beginner-friendly security training rooms with browser-based attack machines.
Vulhub
Open SourcePre-built vulnerable Docker Compose environments reproducing CVEs across common products.
VulnHub
FreeRepository of downloadable vulnerable-by-design virtual machines for offline practice.
VulNyx
FreeFree downloadable vulnerable Linux and Windows machines with difficulty tiers and a leaderboard.
Frequently Asked Questions
What is CTF & Practice Labs?→
Practice environments for offensive and defensive security skills: capture-the-flag platforms, deliberately vulnerable applications, and wargames where techniques can be exercised without touching systems the learner does not own.
What topics does the CTF & Practice Labs category cover?→
Capture The Flag (CTF) Platforms, Vulnerable-by-Design Applications, Wargames, Blue Team Practice, Skill Assessment
About CTF & Practice Labs
CTF and practice lab platforms provide targets that exist to be attacked, which lets learners and professionals practice techniques without legal exposure. The category includes commercial and community lab platforms with guided rooms, machines, and certifications, free wargames served over SSH, and intentionally vulnerable applications that can be run locally in Docker or a VM to practice web exploitation against the OWASP Top 10 and beyond. It also covers CTF competition platforms, which teams use to host their own events. Practice targets differ from the tools in the penetration testing category: the lab is the environment, not the weapon. Blue team practice has its own platforms with alert triage, forensics, and log analysis challenges built from real artifacts. Skill progression in this category maps well onto the rest of the directory, since labs usually require the same recon, exploitation, and forensics tools used in professional work.
Covered Topics & Disciplines
Related Security Categories
Binary analysis and ROP tools for exploit research and compiler-mitigation verification.
Intercepting HTTP proxies, security assessment toolkits, and network exploitation frameworks.
Disassemblers, binary decompilers, and dynamic execution analyzers.