oscarlunatech.com GitHub ↗

Find a vulnerability, exploit it, then watch it get closed.

A per-visitor, isolated security lab. A vulnerable target sits beside an attacker shell in your browser, gone in 30 minutes, with an AI coach for every challenge.

How it's built

Terraform AWS · EC2 / Route 53 / S3 Docker Node.js Caddy · Let's Encrypt WebSockets xterm.js Wazuh · OpenSearch Grafana

Defined as code, rebuilt with one command. A single web server faces the internet. A private control program behind it creates your two throwaway containers, and a separate machine handles monitoring and the public stats page.

AWS · VPC (per-env: prod / dev) Lab box · EC2 (Ubuntu) Monitoring box . EC2 (Ubuntu) per-session internal network · no egress www.<HOST> · <HOST> stats.<host> · monitoring.<host> Docker API · create / proxy / reap target GET /api/stats · aggregate-only AI guide · Bedrock boot private VPC · 1514/1515 scoped read-only Visitor browser · internet Caddy TLS · :443 · web tier Wazuh agent host + container events Orchestrator Node · Docker API 127.0.0.1:8080 Attacker shell Shell · xterm.js Vulnerable target iframe · checked Caddy TLS · stats / monitoring Wazuh SIEM manager · dashboard monitoring.<host> Grafana stats.<host> Docker · read-only S3 · artifacts static files · read-only Amazon Bedrock Gemma 4 · AI guide

Where it's going

Next up: an automated test suite that checks every change before it ships, and an easier way to add new challenges. The goal is a lab that stays reliable and secure on its own, not just on the day it launched.

Privacy & terms