Accept the boundary
Only test systems you own or have explicit permission to test. The exercises here are demonstrations and intentionally vulnerable scenarios—not permission to poke somebody else's server.
The current product is browser-based training with downloadable evidence files. You do not need Kali Linux, a VM, payment, or an account for your first challenge.
Only test systems you own or have explicit permission to test. The exercises here are demonstrations and intentionally vulnerable scenarios—not permission to poke somebody else's server.
Choose an easy challenge, read the objective, inspect the supplied target or evidence, and use hints when you need them. Hints are instruction, not a moral failure.
A flag looks like THTB{your_answer}. Static exercises ask the Worker to validate it. Browser-generated engine exercises are local and unranked until signed solve receipts exist.
Your grind is stored in this browser by default. An optional account can copy it to the cloud, but current ranks and badges are not proof of independently verified skill.
After your first clean solve, open the dashboard and hover or focus a locked badge. Its clue points toward the next move; earned badges explain what you actually did.
$ clues
Keyboard users can focus every card and badge. Reduced-motion settings keep the signal still.
Live: free browser exercises, daily challenges, downloadable artifacts, local badges and ranks, optional account sync, and the community forum. Not live: hosted vulnerable VMs, paid subscriptions, team billing, verified competitive rankings, or certifications.
Start with the firewall exercise, then use the dashboard to choose the next weakest track.
begin challenge one read the faq