Hands-on Labs
The attack-surface maps show where systems break. These labs are where you make that real — each one is short, self-contained, and tied to a specific point on a map. Two run right in your browser; three put real security tools in your hands against deliberately-vulnerable targets.
All labs follow the same shape: rules of engagement → hands-on → how it really works → defenses → debrief. Every one stays on the safe side of the line: your own systems, sandboxed targets, or diagram-only.
The labs
Section titled “The labs” 🎣 Spot the Phish & Scam Interactive. Classify real-world messages — OTP, KYC, digital-arrest, task scams. Targets the human layer on every map.
🛒 Web App Exploitation Hands-on. SQLi, XSS, and broken access control against OWASP Juice Shop. Maps to the e-commerce app.
📱 Mobile App Reverse Engineering Hands-on. Decompile a deliberately-vulnerable app with jadx and find the hardcoded secrets. Maps to the mobile app.
🚗 Bluetooth & the Connected Car Hands-on + case study. Passively scan BLE devices; study the two-person relay attack. Maps to the connected car.
🏠 Map Your Home Network Hands-on. Use nmap on your own network to find the IoT devices and the pivot path. Maps to the connected device.
🛡️ Be the SOC Analyst Interactive. Find the one real intrusion hidden in an hour of log noise. Brings the Autonomous SOC chapter to the keyboard.
How they map to the course
Section titled “How they map to the course”| Lab | Attack-surface point | Safety posture |
|---|---|---|
| Spot the Phish | The “human” pin on every map | 🟢 Safe, in-browser |
| Web App Exploitation | E-commerce · pins 1–5 | 🟡 Deliberately-vulnerable sandbox |
| Mobile RE | Mobile · pins 1, 9 | 🟡 Deliberately-vulnerable sandbox |
| Bluetooth & the Car | Connected car · pin 1 | 🟢 Passive / 🔵 diagram |
| Home Network | Connected device · pins 3, 10 | 🟢 Your own network |
| SOC Analyst | The defender’s response (all maps) | 🟢 Synthetic data |