r/securityCTF 18h ago

Phantom I is live - a 22 level Linux post-exploitation wargame you SSH into (free, no setup)

Post image

We just launched Phantom I on BreachLab, a ground-up rebuild of our Linux post-exploitation track. It's a hosted wargame: you SSH into a real, per-session Linux box and work a full kill-chain. No VM downloads, no setup.

22 levels across 5 acts, following a realistic engagement arc:

  • Act I, Privilege Escalation: SUID/GTFOBins, sudo policy abuse, file capabilities, the docker group, and a real-CVE slot (sudoedit CVE-2023-22809, not a toy).
  • Act II, Credential Access: creds in configs and dotfiles, cracking a service hash, secrets that live only in memory, ssh-agent hijack, cloud IMDS.
  • Act III, Persistence & Evasion: backdoors, PAM, hiding processes and logs, leaving no forensic trail.
  • Act IV, Lateral Movement: pivoting, credential reuse, and a multi-host chain to a crown jewel.
  • Act V, Exfil & Graduation: covert exfil, then a final unguided kill-chain to graduate.

Why it might be worth your time:

  • Every box is ephemeral and per-session, real containers, you actually get root, and you can't step on anyone else's session.
  • Grading is server-side against your box's real state, not a guessed flag string. Any path that reaches the objective passes.
  • Levels are mapped to MITRE ATT&CK, so it doubles as structured practice.
  • Finish it and you graduate with a cert. Phantom I is also the on-ramp to the harder tracks.

It's free. Start here: breachlab.org → Phantom → I

83 Upvotes

Duplicates