Labs are coming. Until they're here, courses do the job.
Isolated VM-based labs (your own VPN, your own target, reset on demand) are the next big chunk of work. They're not live yet. Today the platform delivers the same skills via courses with hands-on examples you can run on your own machine.
Per-student isolated targets.
Real vulnerable services in a sandbox you can pop without breaking anything. The plan below is what we're shipping, in order.
Web
Browser-only, no VPN. SQLi, broken auth, SSRF, IDOR, XSS.
Network
VPN-based. Recon, service exploitation, pivoting.
Active Directory
Small AD environments. Kerberoasting, AS-REP, DCSync.
Blue team
Pre-recorded SIEMs, threat hunts on enriched logs.
What you can do today.
The course platform is fully live and covers the conceptual ground that labs will eventually let you practise in a sandbox.
Use third-party platforms
For now we recommend pairing our courses with public lab platforms (HTB, THM, Root-Me) for the practical bits.