⬡ Security365 │ Web Pentest Range · M4 Cổng Các Lab ATT&CK Navigator
Browser-only · simulated · OWASP-BWA kill chain

The Web Pentest Range

Mỗi lab là một giai đoạn của cùng một engagement nhắm vào một mục tiêu (OWASP Broken Web Apps @ 10.10.10.31): content discovery map các app, làm lộ một template endpoint trở thành server-side code execution. Đi từ trên xuống, hoặc nhảy tới bất kỳ giai đoạn nào. Capstone Blue Team tái dựng cả chain từ web access, WAF và app log.

Play the chain
Enter the Labs →
Ten stages in kill-chain order: content discovery, SSTI → RCE, web shell, SSRF credential theft, IDOR, XSS session hijacking, web-shell C2, exfiltration, defacement, and the Blue Team capstone.
Open the launcher →
See the coverage
ATT&CK Navigator →
A focused slice of MITRE ATT&CK Enterprise lit by what the series teaches — every mission and quiz tag across all labs, spanning nine tactics from Reconnaissance to Impact.
Open the matrix →

The engagement One attacker, one target, one subnet — every lab is a stage of the same operation.

🐉
Attacker
Kali Linux
10.10.10.10
→
🕸️
Target
OWASP-BWA
10.10.10.31

The web kill chain Nine ATT&CK tactics, walked top to bottom. Lit phases are taught by the series.

Jump to a lab Every stage as a direct deep link, with your progress on this browser.