The XSS Rat Training Grounds

Own every lab. Master the methodology.

Training machines built by The XSS Rat — from basic enumeration to extreme multi-vector chains. Register once, unlock targets, submit flags, and track your progress on the leaderboard.

Active Challenges 40
Coming Soon 3
IP Visibility Locked Until Login
☠ The Burrow 2 reached it Can you?

⚡ New Series — Launching 31 May 2026

Project Meridian

5 new OSCP-prep machines inside SolarGate Energy's network. SUID abuse, cron hijacking, sudo escapes, and Linux capabilities — a full Linux privesc series.

View Project Meridian → 💡 Community suggestion by tumtum

Dropping in

--days
:
--hrs
:
--min
:
--sec

🛡 Purple Team Series — Launching 20 Jun 2026

Help me, I got compromised

Five connected hosts. One breach. Log forensics, SOC triage, code review, and a host under constant attack that you must defend — with a 30-minute auto-reset.

Dropping in

--days
:
--hrs
:
--min
:
--sec

Coming Soon

🕐 Upcoming Machines

See full schedule (7 total) →
🐀🐀🐀 🕐 Launching soon

Breakout

Breakout is an internal container management console that was meant to be ops-only. Someone left a debug endpoint live. The container has more access to the runtime than it should — and so do you.

In calculating...

🐀🐀🐀🐀🐀 Premium 🕐 Launching soon

Darkpulse

Darkpulse is a full Active Directory environment built by an ops team that grew too fast to keep up with its own complexity. Every layer trusts the one beneath it. The monitoring system has a view of everything — and so will you, once you understand what it's reporting.

In calculating...

🐀🐀 🕐 Launching soon

Blindspot

Blindspot is an internal URL validation tool. It checks whether endpoints are reachable — and it makes those requests from the server. There's an internal configuration service that wasn't supposed to be externally accessible.

In calculating...

Top Players

View full leaderboard

Want to go further?

All courses. All certs. All lives. One price — forever.

These labs are built around the same methodology taught in The XSS Rat's courses. If you want the full picture — recon, exploit chains, API hacking, business logic, CNWPP certification and everything in between — the Endless Bundle has 45+ courses, 3 cert paths, weekly live sessions, and every future release included. No subscriptions. No upsells.

10+Courses
3xCertifications
ALLLive lessons
80%Off right now