Welcome to the Security365 Pentest Range — a self-contained training network you attack entirely in the browser. You operate from a Kali attacker box at 10.10.10.10 (M1), sweep the subnet, and find three deliberately vulnerable targets on 10.10.10.0/24: a Linux box (M2), a Windows/AD box (M3) and a web stack (M4). Each one is walked end to end — recon, exploitation, post-exploitation, lateral movement, privilege escalation, persistence — then you switch chairs for the Blue Team capstone (M5), correlating every IOC into one campaign and writing the report. Every command is simulated; nothing real is ever touched.
▾ Start with reconnaissance — discover the hosts, then pick your module.
Five modules on a single subnet. Start from the Kali box, work the three classic training targets across Linux, Windows and the web, then close the loop from the defender's chair. The attack lifecycle is the same everywhere — the techniques are native to each environment.
Your operator box — Kali fundamentals plus a sandbox and CTF. This is where netdiscover runs and where every engagement begins. Start here.
Ubuntu-era server riddled with classic services: vsftpd, Samba, NFS, r-services, web apps. The original teaching ground for network exploitation.
Windows Server 2008 R2 with SMBv1, web RCE paths, and reusable credentials — a full Windows kill chain from EternalBlue to service persistence.
A stack of broken web applications. Discovery, injection, IDOR, XSS session theft, web shells and exfiltration — the application layer of the same campaign.
No new target — the defender's chair. Pull the IOCs left behind on M2, M3 and M4, correlate them into one intrusion, and write the incident report.
Each lab maps to a single MITRE ATT&CK technique and runs as a terminal mission with objectives and a knowledge check. Across Linux, Windows and the web the lifecycle stays the same — and the Blue Team capstone closes the loop.
Every lab is one stage of the same engagement — output from one feeds the next, so you learn how a real intrusion compounds across hosts.
Recon, exploitation, credential theft, lateral movement, privilege escalation and persistence — each isolated and mapped to ATT&CK on Linux, Windows and web.
Reconstruct the whole campaign from event logs and network data across all three targets, hunt each technique, and write the incident report.
The labs are sequenced as a real engagement. From the Kali box (M1) you discover the subnet, then walk any target — M2 Linux, M3 Windows/AD, M4 web — top to bottom. The last stage flips you to the defender's side in the M5 SOC capstone.
Before you attack anything, you find what's alive. From the Kali box, run an ARP sweep of the lab subnet — the hosts it discovers are your way in.
Your operator workstation. Learn the tooling, run the sandbox and CTF, then launch the engagement against the discovered targets.
Kali Linux · M1 →When the three targets are done, switch chairs. Correlate every IOC from M2, M3 and M4 into one campaign and write the incident report.
SOC War Room · M5 →This Pentest Range — the portal, the five lab platforms, the missions, the simulated terminals and the campaign data — is original work, © VINH NTT — Security365, all rights reserved. It was designed, built and is owned by the author.
You are welcome to use it freely to learn: run the labs, study the techniques, practise the kill chain end to end. It is not licensed to be repackaged, rebranded or resold. Keep the credit intact and it stays free for the next person to learn on.
This range is free and self-contained — it's enough to build real skill on your own. If you'd like a guided path beyond it, here are two honest options. No pressure: finish the range first.
Instructor-led practice on real CompTIA & EC-Council lab environments — the same lifecycle you just walked, on live infrastructure with feedback.
security365.io →Structured study and exam prep for PenTest+, CEH, CySA+ and CSA — to turn range practice into a credential. Preparation only; no outcome is guaranteed.
academy.security365.io →