All Linux labs
72 hands-on labs that run a real Linux shell in your browser. Each one gives you a scenario, tasks, and feedback the moment you get something wrong.
- Creating EvidenceSet up an evidence workspace and record your first discovery for the incident report.
- The FilesystemYou have landed on a compromised server.
- File HuntThe attacker planted files across the system.
- Opening the CaseYou have been paged for case 2291 on a web server.
- Triage the DropA scanner flagged this web root.
- Log AnalysisSOC flagged suspicious SSH activity.
- Look InsideMove into a folder and read a file to find what the attacker left behind.
- Outbound ConnectionsYou captured a connection snapshot from the host before you touched it.
- Write the EvidenceFindings you cannot quote are findings you cannot act on.
- Permission AuditThe attacker may have loosened file permissions.
- Weak PermissionsPermissions are the quiet way an attacker keeps their access.
- Processes in Odd PlacesYou saved a process snapshot from the host.
- Reading FilesYou found a suspicious configuration file.
- Scattered EvidenceThe attacker scattered scripts and config files.
- Baseline the HostA finding means nothing without context.
- Correlate the Login LogAuth log exported from the host.
- Suspicious AccountsAudit the account list for anything that should not be there.
- What's Here?You're in.
- Crack the Auth LogThe auth.log is massive from a sustained attack.
- Crack the Brute Force3:12 AM, repeated SSH failures.
- Contain the Breach192.168.1.50 has root and is still inside.
- Cross-Reference SourcesThree log files, same time window.
- Eradicate PersistenceThe attacker is locked out but backdoors remain.
- Escalate and NotifyYou have 10 minutes to brief the CISO.
- Find File AnomaliesRoot-level attackers hide things in the filesystem.
- Uncover Hidden FilesThe attacker had root for hours.
- The First Five MinutesSOC alert at 04:00 AM.
- Forensic Disk CaptureThe attacker is out.
- Crack the Full InvestigationFour log files, multiple attackers.
- Verify Against Threat IntelYou found malware in /tmp.
- Threat Hunter: Incident ReportThe investigation is over.
- Build the IOC ListThe investigation is done.
- Protect the LogsRoot breach caught.
- Connect the DotsThree log sources, two attackers.
- Correlate the LogsOne log tells part of the story.
- Triage the LogsSOC alert at 3 AM.
- Hunt the MalwareThe attacker had root for 5 hours.
- Isolate the HostReverse shell detected.
- Map the Network FootprintA reverse shell on port 4444 calls back to 192.168.1.50.
- Separate Signal from NoiseThe auth.log is massive with legitimate traffic mixed with attacks.
- Expose the BackdoorsRoot was obtained 5 hours ago.
- Deep Port ScanPort scan results are in /evidence.
- Preserve EvidenceThe attacker is still logged in.
- Catch the Rogue ProcessesThe attacker is still inside.
- Hunt Rogue ProcessesRoot for 5 hours.
- Discover Open ServicesShell access to a compromised server.
- Read the System LogSyslog shows what the kernel saw.
- Fingerprint the TargetSOC alert fired.
- Rebuild the TimelineSomething happened between midnight and 4 AM.
- Threat Hunter: Timeline ReconstructionUse file timestamps to reconstruct the attacker's actions in chronological order.
- Map the User SessionsYou just SSH'd into a possibly compromised server.
- Enumerate the UsersThe attacker had root.
- Trace the Web AttackThe attacker attacked the web app too.
- Write the ReportThe breach is contained.
- Creating FilesMake the folders you actually want, then write down what you did so you remember it tomorrow.
- The FilesystemExplore the filesystem and learn what each top level folder is for.
- Finding FilesYou have lost a download somewhere under /home/student.
- First ContactOpen a shell on the practice machine and run your first commands.
- Listing FilesA practice folder full of files, including one you have to look closely to see.
- Reading LogsEvery machine keeps a diary.
- Moving AroundMove between folders and read a file to find the configuration.
- Ports and ConnectionsRun a web server for a day and you meet four ports before lunch.
- Who Can Open WhatLinux decides who can open a file using nine characters.
- PermissionsUnderstand how rwx works before you change anything.
- Running ProcessesEverything on Linux is a process, including the ones you never see.
- Reading FilesA configuration file is sitting in your home folder.
- Writing to FilesSend command output into files.
- Searching a Whole TreeA whole tree of files, and you need three things from it.
- System InformationGet to know the machine you are sitting at: kernel, architecture, disk usage and uptime.
- Searching Textgrep is the tool you will reach for most often.
- Users and GroupsRead /etc/passwd and sort real user accounts from system ones.
- Where Am I?You are logged in.