Public catalog

Cybersecurity challenges

Explore distinct Locinode challenge families before entering the range. Procedural variants remain playable but are not separately indexed as duplicate search pages.

Subscribe to new challenge releases

binary_pwn

Starter: Adjacent Overflow

★☆☆☆☆175 XP20 minlinux

A heavily guided first memory-corruption exercise using an adjacent authorization value.

reverse_engineering

Starter: Strings First

★☆☆☆☆150 XP15 minlinux

Start reversing with the simplest useful habit: identify the file and inspect printable strings.

containers_cloud

Starter: Debug Environment

★☆☆☆☆125 XP10 minlinux

See why production debug endpoints and environment secrets are dangerous.

crypto

Starter: Decode This

★☆☆☆☆125 XP10 min

Distinguish encoding from encryption by decoding one clearly identified Base64 value.

recon_osint

Starter: Robots Trail

★☆☆☆☆100 XP8 min

Learn a basic reconnaissance habit by checking the crawler directives published by the target.

forensics

Starter: Read the Logs

★☆☆☆☆125 XP12 min

Learn to inspect a small incident log without downloading evidence onto your own computer.

network_services

Starter: Default Credentials

★☆☆☆☆125 XP10 min

Connect to a legacy training service and recognize the risk of unchanged commissioning credentials.

linux_privesc

Starter: Sudo Basics

★☆☆☆☆125 XP12 minlinux

Practice the first Linux privilege-escalation check in a deliberately simple maintenance shell.

web_api

Starter: View Source

★☆☆☆☆100 XP8 min

Learn the Locinode workflow by finding a clue intentionally left in an application page source.

binary_pwn

Service Recovery — Case 75E3

★★★☆☆450 XP25 minwindows

Atlas Field Services is investigating its maintenance console after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

web_api

Ledger Query — Case 71A0

★★★☆☆450 XP25 min

Granite Peak Systems is investigating its telemetry service after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

reverse_engineering

Encoded Loader — Case B75B

★★★☆☆450 XP25 minwindows

Highpoint Hospitality is investigating its vendor portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

recon_osint

Internal Zone — Case 93CD

★★☆☆☆300 XP17 min

Northstar Medical Group is investigating its inventory dashboard after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

linux_privesc

Script Runner — Case DE86

★★★★☆700 XP35 minlinux

Northstar Medical Group is investigating its customer support portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

forensics

PowerShell Breadcrumbs — Case AA4A

★★★☆☆450 XP25 minwindows

Northstar Medical Group is investigating its operations API after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

crypto

Repeating Evidence — Case 6025

★★★☆☆450 XP25 min

Westgate Insurance is investigating its telemetry service after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

containers_cloud

Metadata Hop — Case 7619

★★★★☆700 XP35 min

Rivermark Foods is investigating its document archive after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

web_api

Crossed Accounts — Case 67AF

★★☆☆☆300 XP17 min

Harborline Logistics is investigating its dispatch console after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

reverse_engineering

XOR Gate — Case ACB7

★★★☆☆450 XP25 minlinux

Northstar Medical Group is investigating its reporting service after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

recon_osint

Shadow Host — Case 6663

★★★☆☆450 XP25 min

Copperline Telecom is investigating its incident dashboard after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

linux_privesc

Archive Operator — Case 7381

★★★☆☆450 XP25 minlinux

Granite Peak Systems is investigating its field-service dashboard after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

forensics

Wire Transfer — Case 8B64

★★☆☆☆300 XP17 min

Copperline Telecom is investigating its asset tracker after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

crypto

Shift Ledger — Case C8EB

★★★☆☆450 XP25 min

Harborline Logistics is investigating its customer support portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

containers_cloud

Service Account Spill — Case BC8B

★★★☆☆450 XP25 minlinux

Mossbrook Pharmacy is investigating its vendor portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

web_api

Trusted Header — Case 4F3E

★★★☆☆450 XP25 min

Ironwood Energy is investigating its maintenance console after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

reverse_engineering

Dispatch Table — Case 7012

★★★★☆700 XP35 minlinux

Silver Creek Transit is investigating its vendor portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

recon_osint

Public Profiles — Case B798

★★☆☆☆300 XP17 min

Westgate Insurance is investigating its vendor portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

linux_privesc

Report Runner — Case 2D7A

★★★★☆700 XP35 minlinux

Redstone Manufacturing is investigating its inventory dashboard after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

forensics

Two Timelines — Case D721

★★★☆☆450 XP25 min

Pine Ridge Utilities is investigating its dispatch console after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

crypto

Proof of Case — Case 863E

★★★☆☆450 XP25 min

Highpoint Hospitality is investigating its vendor portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

containers_cloud

Container Leftovers — Case 5F6C

★★☆☆☆300 XP17 minlinux

Atlas Field Services is investigating its reporting service after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

network_services

Protocol Drift — Case A0E2

★★★☆☆450 XP25 min

Redstone Manufacturing is investigating its customer support portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

network_services

Maintenance Port — Case FAE2

★★☆☆☆300 XP17 min

Redstone Manufacturing is investigating its scheduling portal after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

binary_pwn

Adjacent Memory — Case 1B53

★★★☆☆450 XP25 minlinux

Cedar Vale University is investigating its billing gateway after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

network_services

Diagnostic Socket — Case C522

★★★★☆700 XP35 minlinux

Alder & Finch Legal is investigating its document archive after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

binary_pwn

Length Field — Case 6D4B

★★★★☆700 XP35 minlinux

Meridian Credit Union is investigating its billing gateway after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

web

Stateful Detour

★★★★★1000 XP45 min

Westgate Insurance is investigating its vendor portal after a support workflow exposes a route and state value in different parts of a session handoff. Step in as the responder and follow the evidence.

web

Crawler Maze

★★★☆☆450 XP20 min

Westgate Insurance is investigating its maintenance console after several crawler exclusions were added during a migration, but only one points toward live sensitive content. Step in as the responder and follow the evidence.

web

Cache Me If You Can

★★★★☆700 XP30 min

Harborline Logistics is investigating its asset tracker after a maintenance endpoint treats a cache validator as an authorization condition. Step in as the responder and follow the evidence.

web

Three Things At Once

★★★★★ (6/7)1500 XP70 min

Cedar Vale University is investigating its reporting service after three separate diagnostic surfaces leak the header, cookie, and query value required by one protected route. Step in as the responder and follow the evidence.

forensics

Three Witnesses

★★★★★1000 XP45 min

Alder & Finch Legal is investigating its field-service dashboard after three independent evidence sources each preserve one part of a privileged request. Step in as the responder and follow the evidence.

web

Percent Problem

★★★☆☆450 XP20 min

Cedar Vale University is investigating its asset tracker after a support note preserved a route in percent-encoded form after a copy-and-paste cleanup. Step in as the responder and follow the evidence.

crypto

Repeating Trouble

★★★★☆700 XP30 min

Ironwood Energy is investigating its billing gateway after a troubleshooting artifact stores a route XORed with a short repeating key printed in the same incident bundle. Step in as the responder and follow the evidence.

api

Versioned Access

★★★★★1000 XP45 min

Meridian Credit Union is investigating its dispatch console after an API migration split the authentication token and required version marker across two different resources. Step in as the responder and follow the evidence.

web

Refresh Notice

★☆☆☆☆150 XP8 min

Ironwood Energy is investigating its field-service dashboard after a stale refresh directive survived a portal redesign and still points at a maintenance location. Step in as the responder and follow the evidence.

crypto

Known Key

★★★★☆700 XP30 min

Granite Peak Systems is investigating its vendor portal after a route was encrypted with a Vigenere-style shift using a key explicitly recorded in the maintenance notes. Step in as the responder and follow the evidence.

forensics

Needle Stack

★★★☆☆450 XP20 min

Cedar Vale University is investigating its incident dashboard after web, application, and maintenance messages were merged into one evidence file during collection. Step in as the responder and follow the evidence.

web

Change Window

★★☆☆☆300 XP12 min

Ironwood Energy is investigating its maintenance console after a change-management file under .well-known still references a temporary operations route. Step in as the responder and follow the evidence.

api

Approval Chain

★★★★★1000 XP45 min

Copperline Telecom is investigating its operations API after a two-step approval API exposes the approval token after a preliminary validation request. Step in as the responder and follow the evidence.

web

After Hours Change

★★★★★ (6/7)1500 XP70 min

Alder & Finch Legal is investigating its incident dashboard after an after-hours emergency change left a four-step trail across redirects, encoded notes, and request metadata. Step in as the responder and follow the evidence.

crypto

Shift Change

★★★☆☆450 XP20 min

Alder & Finch Legal is investigating its field-service dashboard after a deployment note records a route after applying a documented alphabet shift. Step in as the responder and follow the evidence.

crypto

Double Wrapped

★★★★☆700 XP30 min

Redstone Manufacturing is investigating its billing gateway after a support value was transformed twice before being pasted into a change ticket. Step in as the responder and follow the evidence.

forensics

Rebuild the Request

★★★★★1000 XP45 min

Summit Municipal IT is investigating its employee portal after incident evidence records a protected route in one file and the trusted request header in another. Step in as the responder and follow the evidence.

web

Linked Out

★★☆☆☆300 XP12 min

Atlas Field Services is investigating its employee portal after a reverse proxy is attaching an undocumented Link header to ordinary responses. Step in as the responder and follow the evidence.

api

Healthy Enough

★☆☆☆☆150 XP8 min

Bluehaven Aviation is investigating its inventory dashboard after the health endpoint is returning internal routing metadata alongside its status. Step in as the responder and follow the evidence.

forensics

One Bad Line

★★★☆☆450 XP20 min

Copperline Telecom is investigating its reporting service after a JSON-lines audit export contains one privileged event hidden among routine records. Step in as the responder and follow the evidence.

web

Two Part Request

★★★★☆700 XP30 min

Alder & Finch Legal is investigating its vendor portal after a diagnostics workflow split its trust signal between a browser cookie and a proxy header. Step in as the responder and follow the evidence.

api

Three Factor Service

★★★★★ (6/7)1500 XP70 min

Alder & Finch Legal is investigating its field-service dashboard after a service migration left three independent trust signals exposed across bootstrap, configuration, and client metadata endpoints. Step in as the responder and follow the evidence.

crypto

ASCII Accounting

★★☆☆☆300 XP12 min

Cedar Vale University is investigating its document archive after an old integration logged a maintenance route as decimal character codes. Step in as the responder and follow the evidence.

forensics

Encoded Evidence

★★★☆☆450 XP20 min

Cedar Vale University is investigating its maintenance console after an evidence note contains one encoded field copied directly from application telemetry. Step in as the responder and follow the evidence.

web

Two Halves

★★★★★1000 XP45 min

Meridian Credit Union is investigating its reporting service after two unrelated-looking pages expose separate fragments of a request key used by a maintenance endpoint. Step in as the responder and follow the evidence.

api

Header Meets Body

★★★★☆700 XP30 min

Redstone Manufacturing is investigating its incident dashboard after an internal operation validates both a client header and a JSON case identifier. Step in as the responder and follow the evidence.

forensics

Resolver Breadcrumb

★☆☆☆☆150 XP8 min

Stonebridge Property Services is investigating its incident dashboard after a resolver troubleshooting note records the path used immediately after an internal name lookup. Step in as the responder and follow the evidence.

crypto

Bits and Pieces

★★☆☆☆300 XP12 min

Meridian Credit Union is investigating its customer support portal after a support utility exported a short maintenance path as eight-bit binary groups. Step in as the responder and follow the evidence.

api

Allow List

★★★☆☆450 XP20 min

Redstone Manufacturing is investigating its inventory dashboard after an OPTIONS response is disclosing an operational endpoint used by a retired client. Step in as the responder and follow the evidence.

web

Preflight Whisper

★★★★★1000 XP45 min

Granite Peak Systems is investigating its asset tracker after an API gateway exposes diagnostic routing metadata only during preflight-style requests. Step in as the responder and follow the evidence.

forensics

Join the Dots

★★★★☆700 XP30 min

Summit Municipal IT is investigating its reporting service after one artifact contains a request identifier while another maps that identifier to a hidden route. Step in as the responder and follow the evidence.

crypto

Split Cipher

★★★★★ (6/7)1500 XP70 min

Ironwood Energy is investigating its inventory dashboard after two artifacts contain separate ciphertext fragments while a third records the transformation key and assembly order. Step in as the responder and follow the evidence.

web

Wrong Verb

★★★☆☆450 XP20 min

Mossbrook Pharmacy is investigating its asset tracker after a legacy support handler is still reachable but only responds to the HTTP verb used by the old console. Step in as the responder and follow the evidence.

api

Next Page, Wrong Place

★★☆☆☆300 XP12 min

Atlas Field Services is investigating its billing gateway after a pagination cursor is accidentally crossing from public records into an internal result set. Step in as the responder and follow the evidence.

crypto

Escaped Route

★☆☆☆☆150 XP8 min

Westgate Insurance is investigating its asset tracker after a route copied through a ticketing system was percent-encoded and never converted back before being archived. Step in as the responder and follow the evidence.

forensics

Four Minute Window

★★★★☆700 XP30 min

Westgate Insurance is investigating its dispatch console after two logs overlap for only four minutes, and the sensitive request can be identified only by matching timestamps and request identifiers. Step in as the responder and follow the evidence.

web

Readable Token

★★★★★1000 XP45 min

Pine Ridge Utilities is investigating its reporting service after a browser diagnostic token contains a readable payload with an internal path. Step in as the responder and follow the evidence.

api

Bootstrap Cookie

★★★☆☆450 XP20 min

Granite Peak Systems is investigating its operations API after an old bootstrap endpoint still issues the session cookie required by a protected API route. Step in as the responder and follow the evidence.

crypto

Peel Back

★★★★★1000 XP45 min

Bluehaven Aviation is investigating its billing gateway after a maintenance path was wrapped in three lightweight transformations before being stored in a support artifact. Step in as the responder and follow the evidence.

forensics

Forwarded Evidence

★★☆☆☆300 XP12 min

Bluehaven Aviation is investigating its field-service dashboard after a proxy log records the original request path separately from the public path. Step in as the responder and follow the evidence.

api

Legacy Query

★★★★☆700 XP30 min

Harborline Logistics is investigating its dispatch console after a legacy integration exposes both Basic credentials and a required account selector in separate configuration fields. Step in as the responder and follow the evidence.

web

Midnight Relay

★★★★★ (6/7)1500 XP70 min

Summit Municipal IT is investigating its field-service dashboard after an emergency maintenance workflow leaked clues through three different HTTP surfaces during an overnight incident. Step in as the responder and follow the evidence.

crypto

URL Safe

★★★☆☆450 XP20 min

Summit Municipal IT is investigating its operations API after a client token stores a route using URL-safe Base64 without padding. Step in as the responder and follow the evidence.

forensics

Odd Browser

★☆☆☆☆150 XP8 min

Westgate Insurance is investigating its incident dashboard after a short access log contains one request made by an unusual automated client just before sensitive data was accessed. Step in as the responder and follow the evidence.

api

Helpful 400

★★☆☆☆300 XP12 min

Bluehaven Aviation is investigating its dispatch console after a validation error includes an internal recovery route intended only for developers. Step in as the responder and follow the evidence.

web

Entity Tag Trail

★★★★★1000 XP45 min

Summit Municipal IT is investigating its operations API after cache metadata on a health resource contains a route marker that was never meant for users. Step in as the responder and follow the evidence.

crypto

Mirror Alphabet

★★★☆☆450 XP20 min

Meridian Credit Union is investigating its inventory dashboard after a legacy support macro obscures a route with a mirrored alphabet substitution. Step in as the responder and follow the evidence.

forensics

Chain of Custody

★★★★★ (6/7)1500 XP70 min

Ironwood Energy is investigating its field-service dashboard after a chain-of-custody package includes multiple transformed artifacts and one signed handoff note that ties them together. Step in as the responder and follow the evidence.

api

Undocumented Docs

★☆☆☆☆150 XP8 min

Meridian Credit Union is investigating its customer support portal after the API landing response still advertises a documentation route the application team forgot was public. Step in as the responder and follow the evidence.

web

Shadow Host

★★★★☆700 XP30 min

Rivermark Foods is investigating its customer support portal after a legacy reverse proxy left a trusted original-host header path in front of a diagnostics handler. Step in as the responder and follow the evidence.

crypto

Hash It Out

★★★★★1000 XP45 min

Granite Peak Systems is investigating its dispatch console after an API diagnostic request expects the SHA-256 digest of a disclosed case identifier as its verification token. Step in as the responder and follow the evidence.

forensics

What Changed?

★★☆☆☆300 XP12 min

Pine Ridge Utilities is investigating its telemetry service after a before-and-after configuration diff shows one route added during the incident window. Step in as the responder and follow the evidence.

api

Strictly JSON

★★★☆☆450 XP20 min

Granite Peak Systems is investigating its employee portal after a validation endpoint accepts a case token only when the request body matches the original JSON client. Step in as the responder and follow the evidence.

web

Trusted Console

★★★★☆700 XP30 min

Northstar Medical Group is investigating its vendor portal after a sensitive diagnostics route trusts requests that appear to come from the application console. Step in as the responder and follow the evidence.