A first course in defensive security
Eleven hands-on labs that run in Docker and open in a friendly console or your browser. Real tools — nmap, Wireshark, John the Ripper, iptables — with the plumbing hidden. You just log in and start.
First time? About 10 minutes — most of it Docker installing. Done once.
Free, one-time, and the only software you need. Download for your system ↗, install it, and start it — wait until it shows “running”.
⭳ Download the ZIP, then unzip it. You'll get a folder named assume-breach-labs-main — put it somewhere easy, like your Desktop.
On Windows, “Extract All” nests it one level deeper — assume-breach-labs-main\assume-breach-labs-main. That's normal: the inner folder (the one containing start.bat) is the one you want. Move it somewhere easy and delete the empty outer one.
Prefer the terminal? Open Terminal, type cd (with a trailing space), drag the folder onto the window, press Enter, then run ./start.sh
If a window flashes open and vanishes: right-click an empty spot inside the folder → Open in Terminal, type .\start.bat and press Enter — the message stays on screen. It usually says Docker Desktop isn't running yet.
Or from any terminal: cd path/to/assume-breach-labs-main && ./start.sh
Independent — pick any. Click a card for what it teaches and how to run it.
Hands-on security labs across the lifecycle — plus two companion books and a game that tie it together. Found one? Here's the rest — or browse the whole series on the series home.