A realistic security game. The terminal is simulated but
the commands are literally real: nmap, hydra,
ssh, curl, grep. No invented syntax,
and every flag it accepts does something.
Here is the difference. When you finish a job the game sits you down in that night's SOC. The queue in front of you holds the rows you left, mixed in with the office's ordinary traffic. Which one is you?
berkay@kit:~$ nmap 10.13.37.0/24 Starting Nmap 7.94 ( https://nmap.org ) Nmap scan report for 10.13.37.20 Host is up (0.00060s latency). PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 3306/tcp open mysql Nmap scan report for 10.13.37.44 Host is up (0.00084s latency). PORT STATE SERVICE 22/tcp open ssh 8080/tcp open http [port scan · trace +5] You have the live machines. Which one is interesting? Look at their ports. ✓ objective complete · +60 xp
The same evening, on the night shift of the SOC the client outsources to. Something in this queue is yours. TIME RULE LV SOURCE 13:04:11 5501 3 10.0.0.4 PAM: session opened (cron) 13:11:39 31101 5 10.0.0.211 Web server 400 error code 13:20:00 100010 5 10.13.37.5 Many connections to closed ports 13:20:05 100012 6 10.13.37.5 Service banner probing pattern 13:52:02 5402 3 10.0.0.4 Successful sudo to ROOT One source in this queue mapped the block. What is its address?
Both blocks are the game's real output, taken from the first contract. The thing that produced those two blue rows is the scan on the left.
Runs in the browser, no account needed. The first contract takes fifteen minutes.