Red Team Attack
A self-contained, single-user training range for practising web security skills against a deliberately vulnerable practice app that ships with it.
Red Team Attack is a hands-on learning environment for people who want to understand web application security by practising it, safely and legally. It pairs with Blue Team Defence: one teaches you to defend an application, the other to understand how an attacker thinks about one — so the two sides reinforce each other.
Everything is self-contained and isolated by design. You bring it up locally with Docker, and it ships with its own fictional, deliberately weak practice application as the only target. It is built to be single-user: each person runs their own private copy on their own machine and only ever works against that copy, so no shared or real systems are ever involved. Progress through the material is structured as a series of graded exercises.
It reuses the lesson runtime, progress tracking and authoring tooling from Blue Team Defence, with a practice target and a guided exercise flow built on top. It is intended purely for self-education in an isolated environment and explicitly not for use against anything you do not own.
Key features
- Runs entirely locally in Docker; nothing is installed on the host
- Ships with its own deliberately vulnerable practice application as the only target
- Single-user by design: each person works only against their own private copy
- Graded, structured exercises that build skills step by step
- Built on the Blue Team Defence lesson runtime and authoring tools
- Intended for isolated self-education, never against systems you do not own