Rooms
Each room explains one class of vulnerability, then gives you a handful of real challenges to practise it on. Read the write-up first, then work through the challenges in order — they get harder as you go.
Foundations: Attacking Entra ID & Azure
Before any exploit makes sense you need the map: what Entra is versus Azure, the two separate role systems, how app registrations and service principals fit together, which API is which, and how Conditional Access decides. Written for someone who has never opened the portal.
Easy
·
Reading
·
~60 min
SQL Injection
Make a database run your input as code. Log in without a password, read tables you were never shown, and learn why every fix except one is a patch over the real problem.
Easy
·
5 challenges
·
~120 min
0 of 5 solved