Red-team & pentest quizzes
Practice the offensive-security body of knowledge. Choose how many questions you want; every attempt is drawn fresh and in random order from a large pool, so you rarely see a repeat. Each answer is a fact cited to its primary source. Runs entirely in your browser — no account, no tracking.
MITRE ATT&CK (Enterprise)
Tactics, techniques and sub-technique IDs, plus mitigations — derived from the official ATT&CK Enterprise v19.2 dataset and cited to each ATT&CK page.
LiveOWASP Web Security Testing Guide
The WSTG web-application testing catalogue — all 12 categories and 114 tests, their IDs and objectives, derived from the official checklist and cited to each OWASP page.
LivePentest methodology
Engagement methodology end to end: NIST SP 800-115 phases and techniques, CVSS v3.1 severity scoring, the PTES phases and technical guidelines, OWASP risk rating and the Cyber Kill Chain — each answer cited to its primary source.
LiveActive Directory & privilege escalation
The AD attack chain — Kerberos and NTLM abuse, LSASS/DCSync credential theft, Pass-the-Hash/Ticket and privilege escalation — mapped to MITRE ATT&CK techniques.
LiveCloud attacks
Attacks against cloud platforms — IaaS, SaaS, Identity Provider and Office Suite — across every tactic, from the official MITRE ATT&CK Enterprise v19.2 cloud matrix and cited to each ATT&CK page.
LiveContainers & Kubernetes
Attacking and hardening containers and Kubernetes — the MITRE ATT&CK Containers matrix plus Kubernetes architecture, RBAC, Pod Security Standards, the OWASP Kubernetes Top Ten and NSA/CISA hardening — each answer cited to its primary source.
LiveLinux privilege escalation
Escalating from a shell to root on Linux — GTFOBins SUID, sudo and capability abuse, the MITRE ATT&CK Linux privilege-escalation techniques, and the Linux capabilities(7) model — each answer cited to its primary source.