CTFs & Vulnerable Targets
Curated catalog of free + freemium platforms and downloadable targets.
CTFs & Vulnerable Targets — Catalog Mapped to AYSEC
A curated catalog of free / freemium platforms and downloadable vulnerable targets. Use this to direct AYSEC students to free hands-on practice.
Always-On CTF Platforms
| Platform |
Free? |
Best For |
URL |
| picoCTF |
Free |
Absolute beginners through advanced |
picoctf.org |
| OverTheWire |
Free |
Linux command line + early hacking |
overthewire.org |
| Root-Me |
Free + Premium |
Full breadth of categories |
root-me.org |
| PentesterLab |
Freemium |
Web exploitation deep dive |
pentesterlab.com |
| PortSwigger Web Security Academy |
Free |
Web AppSec |
portswigger.net/web-security |
| HackTheBox |
Freemium |
Pentest, AD, web |
hackthebox.com |
| TryHackMe |
Freemium |
Beginners + structured paths |
tryhackme.com |
| CryptoHack |
Free |
Cryptography (gamified) |
cryptohack.org |
| CryptoPals |
Free |
Hands-on cryptography attacks |
cryptopals.com |
| OWASP Juice Shop |
Free |
OWASP Top 10 lab (downloadable) |
github.com/juice-shop/juice-shop |
| Hack The Box Academy |
Freemium |
Structured curriculum |
academy.hackthebox.com |
| CyberDefenders |
Freemium |
DFIR, blue team |
cyberdefenders.org |
| Blue Team Labs Online |
Freemium |
DFIR, blue team |
blueteamlabs.online |
| LetsDefend |
Freemium |
SOC analyst training |
letsdefend.io |
| APISec University |
Free |
API hacking |
apisecuniversity.com |
| pwn.college |
Free |
Binary exploitation, RE |
pwn.college |
| HackingHub |
Free |
Web hacking |
hackinghub.io |
| Pwned Labs |
Freemium |
Cloud + AppSec |
pwnedlabs.io |
Mapping by AYSEC Track
AYSEC-000 Foundations
- OverTheWire Bandit — Linux terminal puzzles. Free.
- picoCTF general challenges — Crypto, Forensics intro. Free.
- OverTheWire Krypton — early crypto.
- OverTheWire Natas — early web.
AYSEC-101 Pentesting
- HackTheBox Starting Point — guided intro machines. Free Tier-0 boxes.
- HackTheBox retired easy machines — TJnull's OSCP-like list. VIP.
- VulnHub — downloadable OSCP-prep VMs.
- VulnHub.com hosts hundreds of vulnerable VMs.
- Recommended: Kioptrix series, DC series, FristiLeaks, SickOs, Mr-Robot.
- TryHackMe Jr Penetration Tester path. Premium.
- OffSec Proving Grounds (PG) — paid; OSCP-style boxes.
- VulnNet series on TryHackMe.
Active Directory specific (101 Module 11–12)
- GOAD (Game of Active Directory) — Orange Cyberdefense; deploy locally.
- HackTheBox Academy AD path + retired AD boxes (Forest, Active, Cascade, Sizzle).
- Pro Lab Offshore (HTB) — premium.
- CyberRange — multi-host AD scenarios on HTB.
- TryHackMe Throwback + Wreath networks.
Buffer overflows (101 Module 08)
- TryHackMe Buffer Overflow Prep.
- VulnHub Brainpan series.
- Vulnserver (download from GitHub).
- pwn.college "Memory Errors" dojo.
- ROP Emporium — staged ROP exercises.
AYSEC-102 SOC / Blue Team
- Splunk Boss of the SOC (BOTS) — v1, v2, v3. Free download.
- CyberDefenders Blue Team challenges — PCAP / EVTX / memory.
- Blue Team Labs Online — investigation challenges.
- LetsDefend — simulated SOC tickets to triage.
- TryHackMe SOC Level 1 / 2 paths.
- DetectionLab — pre-built blue-team home lab.
AYSEC-103 DFIR
- CyberDefenders — packaged disk + memory + EVTX cases.
- Magnet Forensics CTF (Magnet Weekly) — released CTF samples.
- DFIR.training — community resources.
- NIST CFReDS — federal reference disk images.
- Digital Corpora — academic-quality datasets.
- The DFIR Report — real intrusions to study (no challenges, but excellent reading).
AYSEC-104 GRC
- GRC mock audits — community-shared scenarios.
- NIST CSF Reference Tool — interactive.
- Vanta / Drata trial accounts — sample SOC 2 control matrices.
AYSEC-105 Cloud Security
- flaws.cloud / flaws2.cloud — AWS attack labs. Free.
- CloudGoat (Rhino Security Labs) — deployable AWS scenarios.
- AWSGoat — AWS vulnerable web app.
- GCPGoat — GCP equivalent.
- AzureGoat — Azure equivalent.
- Pwned Labs — modern cloud attack labs (free + premium).
- HackTheBox AWS Cloud Pentesting module.
- ChatGPT-driven CTFs for AI-cloud (emerging).
AYSEC-106 AppSec / Bug Bounty
- PortSwigger Web Security Academy — ★★★ best free AppSec resource.
- OWASP Juice Shop — vulnerable Express app, dozens of challenges.
- DVWA (Damn Vulnerable Web Application).
- WebGoat (OWASP).
- bWAPP (buggy web app).
- Hackazon (older).
- HackTheBox Bug Bounty Hunter path.
- APISec University — free API course.
- crAPI (OWASP's vulnerable API).
- VulnAPI projects.
- HackerOne CTF (free, scrolls past disclosed bugs).
AYSEC-150 IoT / OT
- Industrial Intrusion — TryHackMe.
- MQTT — TryHackMe and elsewhere.
- GRFICSv3 (Graphical Realism Framework for ICS) — visual ICS simulation.
- ICSim — simulated CAN bus for car-hacking practice.
AYSEC-151 AI Security
- AIVillage / Gandalf by Lakera — prompt-injection challenges.
- Lakera AI Red Team challenges.
- DEF CON AI Village challenges (annual).
- HackTheBox AI modules.
AYSEC-152 Cryptography
- ★ CryptoPals — 8 sets of attack exercises. The gold standard.
- CryptoHack — gamified crypto challenges.
- Boxentriq — cipher tools and challenges.
- NSA Cryptochallenge archives.
AYSEC-201 Red Team
- HackTheBox Pro Labs: Offshore, RastaLabs, Cybernetics, Zephyr, APTLabs.
- TryHackMe Red Team Path.
- Goad — Active Directory lab.
- DetectionLab — red+blue (you red-team your own blue lab).
AYSEC-202 RE & Malware
- ★ pwn.college — multi-dojo curriculum (RE, kernel, browsers, etc.).
- crackmes.one — community RE challenges.
- Reverse Engineering for Beginners — Dennis Yurichev (free book + exercises).
- Microcorruption — embedded RE CTF (free).
- abuse.ch Malware Bazaar — real samples (handle responsibly).
- theZoo (GitHub) — historical malware samples.
- FLARE-On — Mandiant's annual RE challenge (free, retired challenges available).
- 0x00sec — community RE problems.
AYSEC-203 Threat Hunting
- Splunk Boss of the SOC.
- Detection Engineering Maturity Model exercises.
- Atomic Red Team — run on your own lab.
- Caldera — adversary emulation against your hunts.
AYSEC-204 Mobile AppSec
- OWASP MASTG Test Apps — Android + iOS.
- DIVA Android.
- InsecureBank.
- OWASP iGoat-Swift (iOS).
- Sieve (Android).
- Frida CodeShare — community scripts.
Annual / Major CTF Events
| Event |
When |
Notes |
| DEF CON CTF |
Aug |
Top-tier; team registration |
| Google CTF |
Jun |
Free, online, beginner + advanced |
| HackTheBox University CTF |
Sep |
Free for university teams |
| HackTheBox Cyber Apocalypse |
annual |
Free, online, large prizes |
| picoCTF |
Mar–Apr |
Free, beginner-friendly |
| National Cyber League |
Fall |
Student-only |
| CSAW CTF |
Sep |
NYU-led |
| Plaid CTF |
Apr |
CMU-led; advanced |
| FLARE-On |
Aug–Oct |
Mandiant; RE-only |
| NetWars |
Various |
SANS-affiliated |
| TryHackMe Christmas |
Dec |
Holiday challenges |
Vulnerable VMs — Most-Recommended for OSCP-Like Practice
(Curated list — search VulnHub / HackTheBox)
VulnHub:
Kioptrix series (1, 2, 3, 4, 5)
Mr Robot
DC series (1-9)
Mercy
Lampião
SickOs 1.1, 1.2
FristiLeaks 1.3
Pwnlab
Stapler
HackLAB Vulnix
Gibson
Kevin
ColddBox
HackTheBox retired (TJnull list highlights):
Lame, Legacy, Devel, Optimum, Bashed, Nibbles
Bastard, Granny, Grandpa, Tally
Active, Forest, Cascade, Sizzle, Mantis
ServMon, Doctor, Magic, Knife, Nest
Sauna, Sniper, Resolute, Monteverde
Object, Outdated, Soccer, Bolt
How to Use This Catalog in AYSEC
For every AYSEC module's "Lab" task, link to:
- The most-relevant free / freemium platform.
- A specific challenge or VM.
- Estimated time.
Embed direct URLs. Make practice the path of least resistance — students don't have to hunt for "what to do next."
Maintenance
CTF / VM lists go stale fast. Re-check quarterly. Add new HackTheBox / TryHackMe rooms as they release. Note when prices / availability change (HackTheBox VIP, OffSec PG, etc.).