Hands-On Practice

20 AI-Powered Security Labs

Real tools. Real scenarios. An AI analyst beside you the whole time — analyzing your output, explaining techniques, and guiding your investigation.

20
Labs
5
VM Environments
AI
Live Analyst
0
Completed
Filter: ⚙️ Lab Environment Setup →
L01 Network Beginner

Wireshark + AI Traffic Analysis

Capture live packets, analyze protocol distributions, and use AI to flag anomalous flows and identify attack signatures in PCAP files.

KaliWiresharktcpdumpAI Analyst
⏱ 45 min AI
L02 Detection Intermediate

AI-Powered SIEM (Splunk)

Build ML-based correlation rules in Splunk, detect brute force and lateral movement patterns in real security logs with AI-assisted query building.

Splunk FreePythonAI Analyst
⏱ 90 min AI
L03 Malware RE Intermediate

Static Malware Analysis with AI

Analyze suspicious executables using REMnux tools — strings, PE headers, FLOSS, Capa. AI helps interpret indicators and map behavior to MITRE ATT&CK.

REMnuxFLOSSCapapefileAI Analyst
⏱ 60 min AI
L04 Malware RE Advanced

Dynamic Malware Analysis + Sandbox

Execute malware in a controlled Flare-VM environment. Monitor processes, registry changes, and network activity. AI synthesizes behavioral IOCs automatically.

Flare-VMProcess Monitorx64dbgWireshark
⏱ 120 min AI
L05 Detection Intermediate

Phishing Detection with NLP

Build a Python NLP model that classifies phishing emails with 95%+ accuracy. Use AI to explain why specific emails are flagged and generate detection rules.

Pythonscikit-learnNLTKAI Analyst
⏱ 75 min AI
L06 Network Advanced

Network Anomaly Detection

Use Isolation Forest and Autoencoder models in Python to detect outliers in NetFlow data. AI explains each anomaly's risk score and suggests next steps.

KaliPythonscikit-learnZeek
⏱ 90 min AI
L07 Detection Intermediate

Behavioral Analytics (UEBA)

Profile normal user activity from Windows event logs. Build AI-powered baselines and trigger alerts on insider threat patterns like off-hours access and bulk downloads.

SIFTPythonWindows Logs
⏱ 60 min AI
L08 Incident Response Advanced

AI Incident Response Automation

Simulate a ransomware incident. AI orchestrates the IR playbook: containment decisions, evidence collection commands, and a full written incident report.

SIFTVolatilityAutopsyAI Analyst
⏱ 120 min AI
L09 Cloud Advanced

Cloud Security AI Monitoring

Ingest AWS CloudTrail logs and use AI to detect privilege escalation, impossible travel, and credential abuse in real time with automated alert triage.

AWS Free TierCloudTrailPython
⏱ 90 min AI
L10 Detection Intermediate

Deepfake & Social Engineering Defense

Analyze deepfake audio/video samples using open-source detection tools. AI explains manipulation artifacts and builds organizational detection policies.

PythonFaceForensics++AI Analyst
⏱ 60 min AI
L11 Network Intermediate

Vulnerability Triage with AI (Nessus)

Run Nessus scans against Metasploitable. AI prioritizes CVEs by CVSS score, exploit availability, and business impact — generating an executive-ready report.

Nessus EssentialsKaliMetasploitable
⏱ 90 min AI
L12 Incident Response Advanced

Active Directory Attack & AI Defense

Execute Kerberoasting and Pass-the-Hash attacks against a lab AD environment. AI detects each attack from Windows event logs and writes Sigma detection rules.

KaliWindows ServerImpacketSigma
⏱ 120 min AI
L13 Forensics Intermediate

Memory Forensics with Volatility

Analyze a memory dump from a compromised system. Extract running processes, network connections, and injected code. AI identifies malware artifacts and persistence mechanisms.

SIFTVolatility 3AI Analyst
⏱ 90 min AI
L14 Forensics Advanced

Disk Forensics & Timeline Analysis

Forensically image a disk, recover deleted files, and build a super-timeline with Plaso/log2timeline. AI correlates artifacts to reconstruct attacker activity.

SIFTAutopsyPlasoSleuth Kit
⏱ 120 min AI
L15 Malware RE Advanced

Reverse Engineering with Ghidra + AI

Decompile a real malware sample in Ghidra. AI explains assembly and decompiled C code, identifies key functions, and maps behavior to MITRE ATT&CK techniques.

Flare-VMGhidrax64dbgAI Analyst
⏱ 120 min AI
L16 Detection Intermediate

AI Threat Intelligence Aggregator

Build a Python tool that pulls OTX, AbuseIPDB, and MISP feeds, then uses AI to surface critical IOCs, cluster threat actors, and prioritize response actions.

PythonOTX APIMISPAI Analyst
⏱ 90 min AI
L17 Incident Response Intermediate

Log Analysis & IOC Extraction with AI

Parse Windows Event Logs, Syslog, and web server access logs. AI automatically extracts IOCs, identifies attack patterns, and writes a detection hypothesis.

SIFTPythonEVTX ParserAI Analyst
⏱ 75 min AI
L18 Malware RE Advanced

YARA Rule Writing with AI

Analyze a malware family, identify unique byte patterns and strings, then use AI to write and test YARA detection rules against a sample corpus.

REMnuxYARAPythonAI Analyst
⏱ 90 min AI
L19 Cloud Advanced

DevSecOps Pipeline Security

Embed SAST (Semgrep), DAST (OWASP ZAP), and AI code review into a GitHub Actions CI/CD pipeline. Block vulnerable builds automatically.

GitHub ActionsSemgrepOWASP ZAP
⏱ 90 min AI
L20 Incident Response Advanced

Full SOC Simulation — AI Analyst

Capstone lab: a full-scope attack scenario (initial access → lateral movement → exfiltration). AI triages alerts, coordinates response, and generates the final post-incident report.

All VMsSplunkSIFTAI Analyst
⏱ 3 hrs AI
🤖
CyberSec AI Analyst
Ready — select a lab to begin

Connect Your AI Analyst →
Add your Claude API key to enable live analysis of your terminal output, log files, and malware indicators.

AI Analyst
Welcome to the CyberSec Pro lab environment. I'm your AI analyst — I can analyze terminal output, interpret malware indicators, guide you through investigation steps, and explain what you're seeing.

To get started: select a lab from the list, then paste any output from your VM into the chat below.

I'll help you understand what it means and what to do next.
Quick Actions
Enter to send • Shift+Enter for new line

Lab Title

Category • Difficulty • Duration