Welcome To
Free Lab Fridays
Free Lab Fridays is an initiative started by
Black Hills Information Security, Antisyphon Training, and their partner, MetaCTF
This initiative has a simple goal: Education for All.

HOW IT WORKS
Looking for a place to safely complete all of the labs you see?
Free Lab Fridays has the answer.
By providing your email at the link below, you will receive a special code that will grant you 2 HOURS of access to a meticulously crafted lab environment,
hosted on MetaCTF’s CloudLab platform.
On this platform, you will be able to spin up a snapshotted instance of a virtual machine that has everything you will need to complete all 200+ labs,
and the best part? It's all accessible with the click of a button.
One VM. Unlimited Capability.
What If I Use All 2 Free Hours?
Don’t worry! Come back next Friday,
and you’ll get another 2 VM Lab HOURS, for Free!
Please Note: Stacking Hours is NOT possible!
Looking for something Specific?
Browse through our Lab Database
12 items
Access Token Manipulation
July 29, 2026
Access Token Manipulation When you log into a system, it does not keep asking for your password on every request. Instead, it gives you a token - a small piece of data that says "this person is…
Broadcast Multicast Protocol Poisoning
July 29, 2026
Broadcast / Multicast Protocol Poisoning Networks rely on broadcast and multicast protocols to do things like resolve hostnames, find services, and route traffic. The problem is that these protocols…
Cleartext Passwords in Files
July 29, 2026
Cleartext Passwords in Files When passwords are stored as plain text inside files on a system - no hashing, no encryption, nothing - they become a free gift to any attacker who manages to get a…
Credential Harvesting
July 29, 2026
Credential Harvesting When attackers get into a network, one of the first things they go after is credentials - usernames and passwords. Not because they need one account, but because one account…
Internal Password Spray
July 29, 2026
Internal Password Spray A password spray attack is when an attacker tries a small set of commonly used passwords across a large number of accounts. Instead of hammering one account with hundreds of…
Internal Spearphishing
July 29, 2026
Internal Spearphishing Most phishing attacks come from outside - random emails, fake domains, obvious scams. Internal spearphishing is different. Here, the attacker already has a foot in the door.…
Are You An Educator?
Black Hills Information Security & Antisyphon Training offer special functionality for verified educators.
Want to check it out? Fill out the form below to get verified and unlock custom lesson building, quiz building, and more!