Cybersecurity Knowledge Base — 51 Hands-On Labs
A comprehensive, structured collection of 51 cybersecurity labs covering the entire security landscape. Each file is a self-contained, practical lab with verified commands, working code, and real tools. Every command is testable — no pseudocode, no placeholders.
WARNING: All labs are for educational purposes only. Only test against your own systems, devices, and authorized targets. Unauthorized access is illegal.
Structure — Progressive Learning Path
Files are numbered sequentially by topic area. Start from 01 and work through. Each phase builds on previous concepts.
Phase 1: Foundation & Privacy (01-09)
#
Lab
What You'll Do
01
WireGuard VPN
Deploy self-hosted VPN with kill-switch firewall
02
Tor Setup
System-wide Tor, torsocks, stream isolation, bridges
03
Tails OS
Bootable USB, persistence, GPG verification
04
Traffic Chaining
VPN-through-Tor, Tor-through-VPN, iptables kill-switch
05
Containerization
Firejail, bubblewrap, Docker, systemd-nspawn, QEMU/KVM
06
Live Forensics
Real-time OS leak detection (DNS, NTP, telemetry)
07
OSINT
Digital footprint discovery, theHarvester, holehe, sherlock
08
Steganography
Hide/extract data in images, audio, video, text, network
09
Cryptography
Hash cracking, length extension, padding oracle, ECB, timing
Phase 2: Network Attacks (10-18)
#
Lab
What You'll Do
10
Network Sniffing
tcpdump, wireshark, mitmproxy, protocol analysis
11
ARP Poisoning
MITM pipeline + real-time credential harvesting
12
Password Spraying
Hydra, Medusa, Ncrack, wordlist generation
13
Reverse Shells
Bash, Python, PHP, Perl, PowerShell, socat, OpenSSL
14
DNS Tunneling
Iodine, dnscat2, manual data exfiltration via DNS
15
MAC Spoofing
Randomization, NetworkManager, probe request sniffing
16
Wireless Attacks
WPA2 handshake capture/crack, evil twin, WPS pixie dust
17
Bluetooth Recon
hcitool, sdptool, BLE scanning, RSSI tracking
18
VoIP Hacking
SIP scanning, extension brute force, RTP interception
Phase 3: Web, API & Mobile (19-26)
#
Lab
What You'll Do
19
Full Pentest
Complete methodology: recon → exploit → pivot → report
20
Web Shells
PHP shells, log poisoning, cron/systemd persistence
21
API Hacking
IDOR, GraphQL introspection, JWT attacks, mass assignment
22
Phone Shell
ADB USB/Wi-Fi, Termux SSH, reverse shell from phone
23
Phone MITM
mitmproxy, CA cert install, transparent traffic interception
24
SMS Spoofing
Email-to-SMS gateways, GSM AT commands, online APIs
25
Mobile Pentesting
apktool, jadx, Frida SSL bypass, MobSF, deep links
26
Social Engineering
SET, Gophish, credential harvesting, phishing infrastructure
Phase 4: Post-Exploitation (27-33)
#
Lab
What You'll Do
27
Linux Priv Esc
SUID, sudo, cron, capabilities, kernel exploits, Docker/LXD
28
Windows AD
Kerberoasting, Pass-the-Hash, Golden Ticket, DCSync
29
Container Escape
Privileged containers, docker socket, cgroup, K8s service accounts
30
Hypervisor Escape
Detection, enumeration, CVE reference, hardening checks
31
C2 Frameworks
Sliver, Havoc — full setup, implants, pivoting
32
Botnet Simulation
Flask C2 server, agent beacons, admin panel, modules
33
AV/EDR Evasion
Shellcode encryption, AMSI/ETW bypass, sandbox detection
Phase 5: Cloud Security (34-36)
#
Lab
What You'll Do
34
AWS Hacking
S3 enumeration, IAM escalation, EC2 metadata, Lambda
35
Azure Hacking
Entra ID, Managed Identity, Key Vault, RBAC abuse
36
GCP Hacking
Storage buckets, IAM escalation, metadata, Cloud Functions
Phase 6: Specialized Domains (37-41)
#
Lab
What You'll Do
37
IoT Firmware
binwalk extraction, UART serial, SPI/JTAG, repacking
38
Car Hacking
CAN bus, ICSim simulator, OBD-II, UDS diagnostics
39
SCADA/ICS
Modbus, S7Comm, Docker simulators, OpenPLC
40
Drone Hacking
MAVLink, DJI Tello SDK, ArduPilot SITL, Remote ID
41
WASM & Electron
ASAR extraction, WASM decompilation, secret extraction
Phase 7: Application Security (42-46)
#
Lab
What You'll Do
42
Buffer Overflow
ret2win, ret2libc, ROP chains, format string, integer overflow
43
Reverse Engineering
PE/ELF analysis, unpacking, strace/ltrace, radare2
44
Ransomware
AES encryptor/decryptor, C2 key server, full kill chain
45
Supply Chain
Dependency confusion, typosquatting, CI/CD audit
46
Side-Channel
Timing attacks, Rowhammer, Spectre/Meltdown checks, FLUSH+RELOAD
Phase 8: Hardware, Physical & Advanced (47-51)
#
Lab
What You'll Do
47
Physical Security
RFID cloning, lock picking, bumping, bypass techniques
48
USB HID Attacks
DuckyScript, Arduino HID, RPi Pico, Bash Bunny
49
Blockchain Hacking
Reentrancy, flash loans, oracle manipulation, Slither
50
ML/AI Security
Adversarial examples, model extraction, LLM jailbreaking
51
Log Analysis
Sigma rules, ELK stack, log detection, attack chain analysis
Set up a lab environment : Virtual machines (VirtualBox/QEMU), Docker containers, or disposable VPS
Start with 01-03 : Build your foundation (VPN/Tor/Tails)
Progress through phases sequentially : Each builds on previous concepts
Only target your own systems : Use local VMs, test accounts, and disposable environments
Every command is testable : All tools are available via apt, pip, or source builds
Target
Purpose
Difficulty
Metasploitable 2
Full-stack vulnerable VM
Easy
DVWA / Juice Shop
Web application practice
Easy-Medium
HackTheBox / TryHackMe
Guided pentesting
Varies
CloudGoat / Flaws.cloud
AWS security practice
Medium
VulnHub VMs
Real-world scenarios
Varies
ICSim (CAN bus)
Automotive security
Medium
Conpot / OpenPLC
ICS/SCADA practice
Medium
Your own VMs and containers
Everything else
Custom
Most labs use built-in Linux tools or apt-installable packages. Key tools by domain:
Network : nmap, tcpdump, wireshark, bettercap, mitmproxy
Web : curl, gobuster, ffuf, sqlmap, burpsuite
Exploitation : metasploit, hydra, john, hashcat, pwntools
Mobile : adb, apktool, jadx, frida, objection
Cloud : aws-cli, az-cli, gcloud, gsutil, ScoutSuite
Specialized : binwalk, can-utils, pymavlink, slither, impacket
Crypto/RE : hashcat, john, radare2, Ghidra, GDB
This repository is for educational purposes only . The techniques and tools described should only be used:
On your own systems and devices
On systems you have explicit written permission to test
In controlled lab environments
Unauthorized access to computer systems is illegal under the Computer Fraud and Abuse Act (CFAA) in the US and similar laws worldwide. The authors are not responsible for misuse of this information.
Key Improvements in This Version
Every command is verified — no pseudocode, no placeholder functions, no made-up tools
All tools are real — installable via apt, pip, git clone, or documented source builds
Working exploit code — buffer overflows compile, Python scripts execute, shell commands run
Practical focus — each lab produces verifiable results, not theoretical discussion
Progressive structure — fundamentals first, advanced topics build on earlier skills
24,000+ lines of dense, practical, hands-on cybersecurity content