Skip to main content
ToolLicensePlatformsPricingAction
Blue Team Labs OnlineProprietaryWebFreemiumProfile
CTFdApache-2.0Linux, macOS, WindowsFree / CommercialProfile
CyberDefendersProprietaryWebFreemiumProfile
DVWAGPL-3.0-or-laterLinux, macOS, WindowsOpen SourceProfile
Hack The BoxProprietaryWebFreemiumProfile
HackviserProprietaryWebFreemiumProfile
LetsDefendProprietaryWebFreemiumProfile
Metasploitable 3BSD-3-ClauseLinux, WindowsOpen SourceProfile
OverTheWireProprietary (free service)WebFreeProfile
OWASP Juice ShopMITLinux, macOS, WindowsOpen SourceProfile
picoCTFProprietary (free service)WebFreeProfile
PortSwigger Web Security AcademyProprietary (free service)WebFreeProfile
TryHackMeProprietaryWebFreemiumProfile
VulhubMITLinux, macOS, WindowsOpen SourceProfile
VulnHubProprietary (free service)WebFreeProfile
VulNyxGPL-3.0WebFreeProfile

Software in CTF & Practice Labs

Gamified defender practice covering incident response, forensics, SIEM, and phishing analysis.

LicenseProprietary
PlatformWeb

CTFd

Free / Commercial

Open source platform for hosting capture-the-flag competitions with plugins and dynamic scoring.

LicenseApache-2.0
PlatformLinux, macOS, Windows

Blue team and DFIR labs built from real forensic artifacts such as memory dumps and PCAPs.

LicenseProprietary
PlatformWeb

DVWA

Open Source

Damn Vulnerable Web Application, a PHP web app with deliberately insecure code for practice.

LicenseGPL-3.0-or-later
PlatformLinux, macOS, Windows

Hack The Box

Freemium

Hands-on hacking labs, machines, and CTF competitions with academy courses and enterprise ranges.

LicenseProprietary
PlatformWeb

Hackviser

Freemium

Hands-on training platform with labs, scenario machines, and browser-based tooling plus certifications.

LicenseProprietary
PlatformWeb

LetsDefend

Freemium

Simulated SOC training platform where learners investigate realistic alerts in a blue team workflow.

LicenseProprietary
PlatformWeb

Metasploitable 3

Open Source

Deliberately vulnerable Windows and Ubuntu VMs built with Packer and Vagrant for exploit practice.

LicenseBSD-3-Clause
PlatformLinux, Windows

Free SSH-based wargames teaching Linux, networking, and security fundamentals level by level.

LicenseProprietary (free service)
PlatformWeb

OWASP Juice Shop

Open Source

Intentionally insecure Node.js web application covering the OWASP Top 10 and beyond, with built-in score board.

LicenseMIT
PlatformLinux, macOS, Windows

Free Carnegie Mellon CTF platform and year-round learning game built for students.

LicenseProprietary (free service)
PlatformWeb

Free web security training with hundreds of interactive labs from the makers of Burp Suite.

LicenseProprietary (free service)
PlatformWeb

TryHackMe

Freemium

Guided, beginner-friendly security training rooms with browser-based attack machines.

LicenseProprietary
PlatformWeb

Vulhub

Open Source

Pre-built vulnerable Docker Compose environments reproducing CVEs across common products.

LicenseMIT
PlatformLinux, macOS, Windows

Repository of downloadable vulnerable-by-design virtual machines for offline practice.

LicenseProprietary (free service)
PlatformWeb

VulNyx

Free

Free downloadable vulnerable Linux and Windows machines with difficulty tiers and a leaderboard.

LicenseGPL-3.0
PlatformWeb

Frequently Asked Questions

What is CTF & Practice Labs?

Practice environments for offensive and defensive security skills: capture-the-flag platforms, deliberately vulnerable applications, and wargames where techniques can be exercised without touching systems the learner does not own.

What topics does the CTF & Practice Labs category cover?

Capture The Flag (CTF) Platforms, Vulnerable-by-Design Applications, Wargames, Blue Team Practice, Skill Assessment

About CTF & Practice Labs

CTF and practice lab platforms provide targets that exist to be attacked, which lets learners and professionals practice techniques without legal exposure. The category includes commercial and community lab platforms with guided rooms, machines, and certifications, free wargames served over SSH, and intentionally vulnerable applications that can be run locally in Docker or a VM to practice web exploitation against the OWASP Top 10 and beyond. It also covers CTF competition platforms, which teams use to host their own events. Practice targets differ from the tools in the penetration testing category: the lab is the environment, not the weapon. Blue team practice has its own platforms with alert triage, forensics, and log analysis challenges built from real artifacts. Skill progression in this category maps well onto the rest of the directory, since labs usually require the same recon, exploitation, and forensics tools used in professional work.

Covered Topics & Disciplines

Capture The Flag (CTF) PlatformsVulnerable-by-Design ApplicationsWargamesBlue Team PracticeSkill Assessment