What you will learn
- Investigate systems with core commands
- Understand files and permissions
- Find evidence in logs and running processes
Practice Linux commands, permissions, processes, logs, and privilege boundaries through focused security challenges.
39 challenges available.
LinuxLevel 2A custom-built deb package is installed on this system. Use dpkg or apt to inspect the package's details and find…
LinuxLevel 2Among several background processes, one has the flag embedded in its command-line arguments. List them with ps and…
LinuxLevel 2Several users are registered on this system. Parse /etc/passwd with awk to find the one matching a specific condition,…
LinuxLevel 2Some older log files have been gzip-compressed by log rotation. Use a command that searches inside compressed files…
LinuxLevel 2Multiple application and system log files are provided. The flag is embedded in a single DEBUG-level line — narrow it…
LinuxLevel 2Several environment variables, including some dummy credentials, are set on this system. List them with env and find…
LinuxLevel 3A specific binary on this system has Linux capabilities assigned to it. Investigate a privilege escalation technique…
LinuxLevel 3A copy of the find command with the SUID bit set exists on this system. Use a well-known GTFOBins technique to obtain…
LinuxLevel 3A daemon process runs continuously in the background, with the flag set as one of its environment variables.…
LinuxLevel 3A binary that prints nothing to standard output is provided. Trace its system calls with strace to determine which…
LinuxLevel 3A cleanup script that root runs periodically has a gap (TOCTOU) between checking and acting on a file. Try exploiting…
LinuxLevel 4This challenge analyzes a vulnerable kernel module with a /proc interface as a safe user-space simulation. Find the…
LinuxLevel 4A vulnerable SUID C binary with protections disabled is provided. Exploit its buffer overflow to redirect control flow…
LinuxLevel 5This challenge safely recreates eBPF-rootkit investigation as offline evidence analysis. Without loading eBPF or…
LinuxLevel 5This challenge models mmap, MAP_PRIVATE, and madvise—the ingredients used by Dirty COW (CVE-2016-5195)—as a safe,…