1031 words
5 minutes
CEH Free Labs

Overview#

This collection is organized to help you practice the CEH curriculum hands-on. Each section is mapped to its CEH module, and the labs inside each section progress from fundamentals to more advanced topics. Every link opens the lab directly.

Total labs120
TryHackMe99
PortSwigger Web Security Academy21
Sections16

Note: TryHackMe occasionally moves rooms between free and paid. If you find a lab that is locked, let me know and I will update the list.

Section Map#

#SectionCEH ModuleLabs
01Reconnaissance & OSINTModule 02 - Footprinting and Reconnaissance7
02Scanning & Enumeration (Nmap)Module 03 & 04 - Scanning Networks / Enumeration6
03Vulnerability AssessmentModule 05 - Vulnerability Analysis3
04Networking & ProtocolsFoundation - Networking Fundamentals6
05Web FundamentalsFoundation - Web Fundamentals8
06Web Hacking & OWASPModule 13 & 14 - Hacking Web Servers / Web Applications8
07SQL InjectionModule 15 - SQL Injection24
08Burp SuiteModule 14 - Hacking Web Applications (Tooling)5
09Exploitation & MetasploitModule 06 - System Hacking3
10Privilege EscalationModule 06 - System Hacking6
11Packet Analysis & IDSModule 08 & 12 - Sniffing / Evading IDS, Firewalls & Honeypots10
12Malware & Reverse EngineeringModule 07 - Malware Threats10
13CryptographyModule 20 - Cryptography4
14CTF & Practice MachinesPractice - End-to-End Application9
15CloudModule 19 - Cloud Computing7
16Wireless & IoTModule 16 & 18 - Hacking Wireless Networks / IoT & OT4

Suggested Learning Path#

  1. Foundations: Networking & Protocols → Web Fundamentals
  2. Information gathering and scanning: Recon & OSINT → Scanning (Nmap) → Vulnerability Assessment
  3. Web: Web Hacking & OWASP → Burp Suite → SQL Injection
  4. Exploitation: Metasploit → Privilege Escalation
  5. Defense and analysis: Packet Analysis & IDS → Malware & RE → Cryptography
  6. End-to-end practice: CTF & Practice Machines
  7. Additional topics: Cloud → Wireless & IoT

01. Reconnaissance & OSINT#

CEH Module: Module 02 - Footprinting and Reconnaissance
Labs: 7

The first phase of any engagement: gathering information about the target, either passively or through direct interaction, using OSINT techniques, Google Dorks, and Shodan.

#LabPlatform
1Passive ReconnaissanceTryHackMe
2Active ReconnaissanceTryHackMe
3Shodan.ioTryHackMe
4Google DorkingTryHackMe
5Web OSINTTryHackMe
6Searchlight OSINTTryHackMe
7Red Team ReconTryHackMe

02. Scanning & Enumeration (Nmap)#

CEH Module: Module 03 & 04 - Scanning Networks / Enumeration
Labs: 6

Discovering live hosts, scanning ports and services, and going deeper with Nmap and RustScan.

#LabPlatform
1Nmap: Live Host DiscoveryTryHackMe
2Nmap: Basic Port ScansTryHackMe
3Nmap: Advanced Port ScansTryHackMe
4Further NmapTryHackMe
5NmapTryHackMe
6RustScanTryHackMe

03. Vulnerability Assessment#

CEH Module: Module 05 - Vulnerability Analysis
Labs: 3

Automated vulnerability scanning with tools such as OpenVAS and Nessus, and how to interpret their results.

#LabPlatform
1Vulnerability Scanner OverviewTryHackMe
2OpenVASTryHackMe
3NessusTryHackMe

04. Networking & Protocols#

CEH Module: Foundation - Networking Fundamentals
Labs: 6

The foundation you need before attempting any attack: networking concepts, core protocols, and network security.

#LabPlatform
1Networking ConceptsTryHackMe
2Networking EssentialsTryHackMe
3Networking Core ProtocolsTryHackMe
4Network Security ProtocolsTryHackMe
5Network Security EssentialsTryHackMe
6Layer 2TryHackMe

05. Web Fundamentals#

CEH Module: Foundation - Web Fundamentals
Labs: 8

How websites actually work: HTTP, DNS, and JavaScript. Understand the technology before you attack it.

#LabPlatform
1Web FundamentalsTryHackMe
2Web Application BasicsTryHackMe
3Web App Security 101TryHackMe
4JavaScript EssentialsTryHackMe
5How Websites WorkTryHackMe
6HTTP in DetailTryHackMe
7DNS in DetailTryHackMe
8Putting It All TogetherTryHackMe

06. Web Hacking & OWASP#

CEH Module: Module 13 & 14 - Hacking Web Servers / Web Applications
Labs: 8

Hands-on practice with the OWASP Top 10: content discovery, authentication bypass, file upload flaws, and command injection.

#LabPlatform
1OWASP Top 10 - 2021TryHackMe
2OWASP Juice ShopTryHackMe
3Walking An ApplicationTryHackMe
4Content DiscoveryTryHackMe
5Authentication BypassTryHackMe
6Subdomain EnumerationTryHackMe
7OS Command InjectionTryHackMe
8Upload VulnerabilitiesTryHackMe

07. SQL Injection#

CEH Module: Module 15 - SQL Injection
Labs: 24

From the basics to Blind, Out-of-Band, and NoSQL injection. This section is split between TryHackMe and the PortSwigger Web Security Academy. Start with TryHackMe to build the foundation, then work through PortSwigger in order.

TryHackMe#

#LabPlatform
1SQL FundamentalsTryHackMe
2Advanced SQL InjectionTryHackMe
3SQL Injection LabTryHackMe

PortSwigger - Basic#

#LabLevel
1SQL injection vulnerability in WHERE clause allowing retrieval of hidden dataApprentice
2SQL injection vulnerability allowing login bypassApprentice

PortSwigger - Examining the Database#

#LabLevel
1Querying the database type and version on OraclePractitioner
2Querying the database type and version on MySQL and MicrosoftPractitioner
3Listing the database contents on non-Oracle databasesPractitioner
4Listing the database contents on OraclePractitioner

PortSwigger - UNION Attacks#

#LabLevel
1UNION attack: determining the number of columnsPractitioner
2UNION attack: finding a column containing textPractitioner
3UNION attack: retrieving data from other tablesPractitioner
4UNION attack: retrieving multiple values in a single columnPractitioner

PortSwigger - Blind SQL Injection#

#LabLevel
1Blind SQLi with conditional responsesPractitioner
2Blind SQLi with conditional errorsPractitioner
3Visible error-based SQLiPractitioner
4Blind SQLi with time delays and information retrievalPractitioner
5Blind SQLi with out-of-band interactionPractitioner
6Blind SQLi with out-of-band data exfiltrationPractitioner

PortSwigger - Filter Bypass#

#LabLevel
1SQLi with filter bypass via XML encodingPractitioner

PortSwigger - NoSQL Injection#

#LabLevel
1Detecting NoSQL injectionApprentice
2Exploiting NoSQL operator injection to bypass authenticationPractitioner
3Exploiting NoSQL injection to extract dataPractitioner
4Exploiting NoSQL operator injection to extract unknown fieldsExpert

08. Burp Suite#

CEH Module: Module 14 - Hacking Web Applications (Tooling)
Labs: 5

The core tool for any web pentester: Proxy, Repeater, Intruder, and extensions.

#LabPlatform
1Burp Suite: The BasicsTryHackMe
2Burp Suite: RepeaterTryHackMe
3Burp Suite: IntruderTryHackMe
4Burp Suite: Other ModulesTryHackMe
5Burp Suite: ExtensionsTryHackMe

09. Exploitation & Metasploit#

CEH Module: Module 06 - System Hacking
Labs: 3

Exploiting vulnerabilities with Metasploit and working with Meterpreter post-exploitation.

#LabPlatform
1Metasploit: IntroductionTryHackMe
2Metasploit: ExploitationTryHackMe
3Metasploit: MeterpreterTryHackMe

10. Privilege Escalation#

CEH Module: Module 06 - System Hacking
Labs: 6

Escalating privileges on Linux and Windows, bypassing UAC, and establishing persistence.

Linux#

#LabPlatform
1Linux Privilege EscalationTryHackMe
2Common Linux PrivescTryHackMe
3Linux PrivEscTryHackMe

Windows#

#LabPlatform
1Windows PrivEscTryHackMe
2Bypassing UACTryHackMe
3Windows Local PersistenceTryHackMe

11. Packet Analysis & IDS#

CEH Module: Module 08 & 12 - Sniffing / Evading IDS, Firewalls & Honeypots
Labs: 10

Traffic analysis with Wireshark, Tcpdump, and TShark, plus intrusion detection systems such as Snort and Zeek and how they are evaded.

#LabPlatform
1Wireshark 101TryHackMe
2Wireshark: The BasicsTryHackMe
3Wireshark: Packet OperationsTryHackMe
4TcpdumpTryHackMe
5TShark: The BasicsTryHackMe
6SnortTryHackMe
7Snort Challenge 1TryHackMe
8IDS FundamentalsTryHackMe
9IDS EvasionTryHackMe
10ZeekTryHackMe

12. Malware & Reverse Engineering#

CEH Module: Module 07 - Malware Threats
Labs: 10

From the history of malware to static and dynamic analysis and anti-reverse-engineering techniques.

#LabPlatform
1History of MalwareTryHackMe
2Malware IntroductoryTryHackMe
3Basic Malware RETryHackMe
4REMnux v2TryHackMe
5Basic Dynamic AnalysisTryHackMe
6Advanced Dynamic AnalysisTryHackMe
7Static AnalysisTryHackMe
8Advanced Static AnalysisTryHackMe
9Anti-Reverse EngineeringTryHackMe
10MalDocTryHackMe

13. Cryptography#

CEH Module: Module 20 - Cryptography
Labs: 4

Cryptography fundamentals, common encryption types, and cracking hashes.

#LabPlatform
1Cryptography for DummiesTryHackMe
2Encryption - Crypto 101TryHackMe
3Crack The HashTryHackMe
4Crack The Hash Level 2TryHackMe

14. CTF & Practice Machines#

CEH Module: Practice - End-to-End Application
Labs: 9

Full machines where you apply everything you have learned: recon, exploitation, and privilege escalation. Best tackled after finishing the previous sections.

#MachineOSDifficultyPlatform
1VulnversityLinuxEasyTryHackMe
2Basic PentestingLinuxEasyTryHackMe
3Steel MountainWindowsEasyTryHackMe
4KenobiLinuxEasyTryHackMe
5RootMeLinuxEasyTryHackMe
6Pickle RickLinuxEasyTryHackMe
7Simple CTFLinuxEasyTryHackMe
8Lazy AdminLinuxEasyTryHackMe
9IgniteLinuxEasyTryHackMe

15. Cloud#

CEH Module: Module 19 - Cloud Computing
Labs: 7

Cloud security fundamentals, AWS, Infrastructure as Code, and VPC attacks.

#LabPlatform
1Introduction to Cloud SecurityTryHackMe
2Cloud 101 (AWS)TryHackMe
3Cloud-based IaCTryHackMe
4Azure DevSecOpsTryHackMe
5Attacking and Defending VPCsTryHackMe
6Eyes Wide ShutTryHackMe
7Can You GATryHackMe

16. Wireless & IoT#

CEH Module: Module 16 & 18 - Hacking Wireless Networks / IoT & OT
Labs: 4

Attacking wireless networks, printers, and IoT devices.

#LabPlatform
1WiFi Hacking 101TryHackMe
2Printer Hacking 101TryHackMe
3IoT IntroTryHackMe
4Royal RouterTryHackMe

Tips for Getting the Most Out of These Labs#

  • Take notes on every lab: the tool, the command, and the idea behind it, so you can come back to them later.
  • Avoid walkthroughs until you have genuinely tried on your own.
  • Repeat labs a few days later without looking at the solution. This is what makes the knowledge stick.
  • Map each lab to its CEH module to reinforce your exam preparation.

These labs are for learning and practice in authorized environments only. Never test any technique on systems you do not own or have explicit permission to test.

CEH Free Labs
https://bad-glitch.github.io/posts/labs/cehv13---labs/ceh/
Author
Amr Abdel Hamide
Published at
2026-09-19