Security365 Lab Launcher · Web (M4) Portal Labs ATT&CK Navigator
Web attack lifecycle · pick a stage

The Web kill chain, one lab at a time

Each lab is a stage of the same engagement against one target (OWASP Broken Web Apps @ 10.10.10.31): content discovery maps the apps, which exposes a template endpoint that becomes server-side code execution. Walk them top to bottom, or jump to any stage. The Blue Team capstone reconstructs the whole chain from web access, WAF and app logs.