TechBizAcademy
Practice range

Hands-on labs

Fourteen labs, from your first Linux command to incident response. Type real commands, answer graded questions, capture hidden flags. All labs open — no account, no unlocking.

Simulated & safe

Every host, hash and log here is simulated in your browser — no real system is ever contacted. Testing systems you do not own or have written authorisation to test is a criminal offence in most countries. Lab 06 links to legal platforms where you can practise exploitation against machines provided for that purpose.

Suggested order — but every lab is open. 0 / 18 complete.
01 Beginner Foundations 20 min 13 items

Kali Linux: The Commands You Actually Need

Navigation, reading files, permissions, searching, processes and ports — the foundation every other lab assumes.

ls grep find
02 Beginner Offensive 25 min 10 items

Network Recon & SMB Enumeration

Sweep a network, scan ports, fingerprint services and enumerate SMB shares over a null session.

nmap smbclient
03 Beginner Offensive 20 min 10 items

Web Enumeration & Hidden Content

Fingerprint a web server, mine robots.txt, brute-force directories and find a backup leaking credentials.

curl gobuster
04 Intermediate Offensive 30 min 10 items

SQL Injection: From Error to Data

Confirm an injectable parameter, count columns, pivot to UNION SELECT and dump the credential table.

sqli
05 Intermediate Offensive 25 min 9 items

Cross-Site Scripting: Filters & Bypasses

Three inputs, three filters. Work out reflected vs stored, and break out of an attribute context.

xss
06 Intermediate Offensive 20 min 10 items

Password Cracking: Hashes & Wordlists

Identify a hash algorithm, crack what a wordlist reaches, and see exactly where a wordlist stops working.

hashcat john
07 Advanced Offensive 35 min 11 items

EternalBlue (MS17-010): Identify, Exploit, Report

The full engagement arc — confirm, exploit in the simulator, collect proof and write the remediation.

nmap metasploit
08 Beginner Defensive 25 min 10 items

SOC: Log Triage & Brute-Force Detection

Work an authentication alert: count the failures, find the source, spot the login that finally succeeded.

grep count
09 Beginner Defensive 20 min 10 items

SOC: Phishing Email Analysis

Analyse headers and body of a reported email — SPF/DKIM/DMARC, lookalike domain and the real link target.

grep cat
10 Advanced Defensive 30 min 10 items

SOC: Incident Response & Containment

Build the timeline, find persistence and exfiltration, then decide the containment order that preserves evidence.

grep timeline
11 Advanced Offensive 35 min 11 items

Active Directory: Finding the Path to Domain Admin

Enumerate the domain, kerberoast a weak service account, and map the group membership that leads to DA.

enum kerberoast
12 Intermediate Cloud 30 min 10 items

Cloud Misconfiguration: Buckets, Roles & Metadata

Follow a public bucket through instance metadata to a role takeover — the chain behind most cloud breaches.

aws curl
13 Intermediate Defensive 25 min 11 items

Malware Triage: Static Analysis Without Detonating

Triage a suspicious attachment safely: file type, hashes, strings, PE imports and threat intel.

strings pe
14 Advanced Defensive 30 min 10 items

Digital Forensics: Reconstructing What Happened

Verify an image hash, recover a deleted archive and build the artefact timeline.

fls recover
15 Intermediate Offensive 30 min 11 items

Linux Privilege Escalation: From User to Root

Enumerate sudo rules, SUID binaries, cron jobs and writable paths, then escalate — and record the hardening.

sudo suid
16 Intermediate Defensive 25 min 11 items

Packet Analysis: Reading Traffic Like an Analyst

Work a capture: protocol breakdown, follow a stream, recover cleartext credentials and spot C2 beaconing.

pcap filter
17 Beginner Offensive 25 min 11 items

OSINT: Mapping a Target Before You Touch It

Passive reconnaissance only — whois, DNS, subdomains, email format, breach data and an exposed repository.

whois subdomains
18 Beginner Foundations 20 min 11 items

Cryptography & Encoding: Telling Them Apart

Base64, hex, Caesar and hashes — what each one actually is, and why calling encoding "encryption" is dangerous.

decode hashid

How the labs work

  • Real syntax. You type the same commands you would use on a real engagement.
  • Graded questions. Each lab asks questions you answer from what you found. Answers show as _ for letters and # for digits, so you know the shape without being given it.
  • Hidden flags. Flags are never printed — you have to reach the file, share or log that holds them.
  • Progress is per-browser. No account, no email. Clearing site data resets it.