CyberKy Labs

Hands-on cybersecurity labs, right in your browser

Hunt threats with osquery, set up SSO with Keycloak, check CIS compliance with OpenSCAP, and manage LDAP groups in real environments that run in your browser. Included with paid CyberKy plans.

How a lab works

  1. Launch in your browser

    Start an isolated environment with a remote desktop right in your browser. Nothing to install.

  2. Follow the steps

    Every lab comes with step-by-step instructions and clear learning objectives.

  3. Work at your pace

    A session timer shows the time you have left, and you can extend the session or end it when you are done.

  4. Pick up where you left off

    One environment runs at a time, and you can return to a running lab from your dashboard.

What you practice

The labs available on the platform today.

  • Identity & Access

    IAM LDAP: Create Your First Group Policy

    Learn LLDAP basics by creating your first user, creating a group policy, adding your user to that group, and validating access behavior.

  • Security Operations

    Endpoint Threat Hunting with osquery

    Investigate a compromised Linux web server with osquery SQL: find a masquerading in-memory implant, hidden persistence and threat-intel matches, then contain it and write the incident report.

  • Identity & Access

    Single Sign-On and Access Control with Keycloak

    Build an identity realm from scratch in Keycloak: password and lockout policy, group-based RBAC, an OpenID Connect application, JWT analysis, TOTP MFA, attack detection and offboarding.

  • GRC

    CIS Benchmark Compliance with OpenSCAP

    Assess a payroll server against the CIS Ubuntu 24.04 benchmark with OpenSCAP, scope the assessment, remediate with change control, document a risk exception and deliver an audit evidence package.

Practice inside lessons, too

Interactive lessons put you in front of simulated security artifacts, so you keep practicing between labs.

  • Investigate

    Work through SIEM searches, sign-in logs, alert queues, process trees, and packet captures.

  • Secure access

    Review access requests, MFA prompts, app permissions, and token details the way an identity team would.

  • Assess risk

    Fill in risk registers, control registers, audit evidence, and vendor questionnaires.

  • Read the network

    Check firewall rules, route tables, DNS records, and network topology.

Questions

Loading...

Start free, then pick a plan.

Launching labs is included with paid plans.