4 min read

The Best CTF Practice Platforms: A Curated Roundup (2025)

The Best CTF Practice Platforms: A Curated Roundup (2025)

Last updated: September 2025

This post rounds up the CTF practice platforms I come across most often. Since I'm especially drawn to the Web side of things, every platform listed below is guaranteed to have a solid stack of Web challenges. On top of that, if you're like me and enjoy writing writeups to document your learning, I've also put together a list at the end of platforms that welcome published writeups, for your reference.

CTF Practice Platforms at a Glance

Platforms by Type (swipe right on mobile)

Category Platform What Makes It Stand Out Link My Hands-On Take (for reference)
All-round picoCTF Education-focused; its annual competition is hugely popular https://picoctf.org Perfect for beginners, covers every category, and the Web challenges are wonderfully varied
All-round TryHackMe Full learning paths, great for structured study https://tryhackme.com Excellent training across all sorts of topics, ideal for building your skills, plus there are challenges to test yourself on
All-round Hack The Box Well known in the industry, realistic pentesting environments https://www.hackthebox.com Quite challenging and great for leveling up; the Academy is really well laid out
All-round OverTheWire Classic wargames, many people's first choice for getting started https://overthewire.org Very different from the usual Jeopardy-style CTF; you clear one level to unlock the next. If you want to learn Web, start with Bandit and Natas
Web-focused PortSwigger The Web Security Academy has comprehensive material https://portswigger.net/web-security This is the gold-standard resource for Web security, and the certification is incredibly useful too
Web-focused websec.fr Pure Web challenges with a clean interface https://websec.fr Web CTF challenges, but they'll touch on source code auditing, so better suited to more advanced players
Web-focused webhacking.kr Korean platform with fun challenges https://webhacking.kr All kinds of Web challenges, and genuinely challenging
All-round HackMyVM Offers downloadable virtual machines for offline practice https://hackmyvm.eu You can download target machines for hands-on practice, plus there are CTF challenges across every category, and even wargames to play!
Competition platform ImaginaryCTF Runs CTFs regularly, with good-quality challenges https://imaginaryctf.org Haven't tried it yet
Bug Bounty platform YesWeHack Dojo Monthly challenges run by a bug bounty company https://dojo-yeswehack.com Haven't tried it yet
Competition platform AlpacaHack Japanese platform with a built-in solving system https://alpacahack.com Haven't tried it yet
All-round Viblo CTF Vietnamese platform with an active Asian community https://ctf.viblo.asia All sorts of challenge types, with a decent number of Web ones. Some challenges are in Vietnamese and need translating, but overall it feels refreshingly new
Professional training PentesterLab Reproduces real vulnerabilities, very effective for learning https://pentesterlab.com Topic-based learning that lets you dive deep into different Web subjects. There's a fair bit of difficulty, but the teaching resources are thorough, so the challenges never feel alien
Professional training Root-Me A veteran European platform with a huge variety of challenges https://www.root-me.org A massive variety of challenges. Web is even split into client-side and server-side, and there's a Network category that Web work often overlaps with too, so you can get to grips with the underlying infrastructure. Super important!!!
Other PwnTillDawn Gamified design with an achievement system https://online.pwntilldawn.com/ Haven't tried it yet
All-round, Web-leaning echoCTF.RED Open-source platform you can self-host https://echoctf.red Machine-based CTF challenges where a single target may hold several flags, letting you dig deep into all kinds of services and vulnerabilities. It also thoughtfully includes a beginners' zone, making it great for learning and getting started
All-round CyberTalents A Middle Eastern platform https://cybertalents.com Challenges of every type, completely free, and great for beginners
All-round Flagyard A relatively new platform https://flagyard.com Haven't tried it yet
All-round HackerLab.pro An up-and-coming platform https://hackerlab.pro/en A Russian CTF platform with a wide variety of challenges that are both distinctive and difficult. Some challenges are in Russian and again need translating, but it's good training precisely because writeups are almost impossible to find and hints are scarce
All-round 316CTF An up-and-coming platform https://play.316ctf.com/ Plenty of Web-related challenges, plus a special "password cracking" category. There's some repetition, but it helps cement what you've learned

Platforms That Are Good for Writeups

If you want to document your learning journey by writing writeups, all of these platforms welcome you to publish your solutions:

🎯 Writeup-Friendly Platforms

Platform Notes Link
picoCTF Education-focused platform that encourages sharing your learning process (hiding the flag values is recommended) https://picoctf.org
TryHackMe No restrictions at all; the community frequently shares complete walkthroughs https://tryhackme.com
PortSwigger Officially welcomes technical sharing; explaining the concepts in detail adds even more value https://portswigger.net/web-security
websec.fr Share freely, no restrictions https://websec.fr
webhacking.kr Korean platform; you're free to publish https://webhacking.kr
HackMyVM Virtual machine challenges; sharing is welcome https://hackmyvm.eu
ImaginaryCTF You can publish once the competition ends, and the organizers release solutions too https://imaginaryctf.org
AlpacaHack Has a built-in system but doesn't restrict external sharing https://alpacahack.com
echoCTF.RED Open-source spirit; sharing is allowed (hiding the flag is recommended) https://echoctf.red
OverTheWire Share your approach and reasoning (avoid posting passwords directly) https://overthewire.org

📅 Timing-Restricted Platforms

These platforms welcome writeups too; you just need to mind the timing of your publication:

Platform When You Can Publish Link
Hack The Box You can publish for retired machines https://www.hackthebox.com
YesWeHack Dojo You can publish after that month's challenge ends https://dojo-yeswehack.com

💡 Other Platforms

Some platforms may have specific rules (for example, PwnTillDawn requires you to check the licensing of individual machines), some prefer that you use their built-in system (such as Viblo CTF), and a few have policies that aren't entirely clear. If you're unsure, it's best to ask the organizers or the community first.

If you're just getting into CTFs and want to practice writing writeups, these platforms are especially well suited:

  1. picoCTF - Moderate difficulty and a friendly community
  2. TryHackMe - Guided, so your writeups come out more structured. TryHackMe is running a promotion right now! Use my invite link to jump in and start learning: tryhackme.com/invite/pcc402
  3. PortSwigger - Learn Web security and practice your writing at the same time
  4. OverTheWire Bandit - A classic entry point, and many people's very first writeup

Writing writeups isn't just about sharing; it's also a great way to cement your knowledge. Pick a platform you like and get started!


Continually updated; contributions welcome

📮 Get in Touch

Happy Hacking! 🚀