Browser-only · simulated · OWASP-BWA kill chain
The Web Pentest Range
A self-contained, browser-only training range that walks a single engagement against one target (OWASP Broken Web Apps @ 10.10.10.31) from first contact to visible impact, then reconstructs the whole chain from the defender's side. Every terminal is a hard-coded simulation — nothing is scanned, nothing is exploited. Start at the Labs to play the chain in order, or open the ATT&CK Navigator to see what the series lights up.
Play the chain
Enter the Labs →
Ten stages in kill-chain order: content discovery, SSTI → RCE, web shell, SSRF credential theft,
IDOR, XSS session hijacking, web-shell C2, exfiltration, defacement, and the Blue Team capstone.
Open the launcher →
See the coverage
ATT&CK Navigator →
A focused slice of MITRE ATT&CK Enterprise lit by what the series teaches — every mission and
quiz tag across all labs, spanning nine tactics from Reconnaissance to Impact.
Open the matrix →
The engagement One attacker, one target, one subnet — every lab is a stage of the same operation.
Attacker
Kali Linux
10.10.10.10
→
Target
OWASP-BWA
10.10.10.31