The Best CTF Practice Platforms: A Curated Roundup (2025)
Last updated: September 2025
This post rounds up the CTF practice platforms I come across most often. Since I'm especially drawn to the Web side of things, every platform listed below is guaranteed to have a solid stack of Web challenges. On top of that, if you're like me and enjoy writing writeups to document your learning, I've also put together a list at the end of platforms that welcome published writeups, for your reference.
CTF Practice Platforms at a Glance
Platforms by Type (swipe right on mobile)
| Category | Platform | What Makes It Stand Out | Link | My Hands-On Take (for reference) |
|---|---|---|---|---|
| All-round | picoCTF | Education-focused; its annual competition is hugely popular | https://picoctf.org | Perfect for beginners, covers every category, and the Web challenges are wonderfully varied |
| All-round | TryHackMe | Full learning paths, great for structured study | https://tryhackme.com | Excellent training across all sorts of topics, ideal for building your skills, plus there are challenges to test yourself on |
| All-round | Hack The Box | Well known in the industry, realistic pentesting environments | https://www.hackthebox.com | Quite challenging and great for leveling up; the Academy is really well laid out |
| All-round | OverTheWire | Classic wargames, many people's first choice for getting started | https://overthewire.org | Very different from the usual Jeopardy-style CTF; you clear one level to unlock the next. If you want to learn Web, start with Bandit and Natas |
| Web-focused | PortSwigger | The Web Security Academy has comprehensive material | https://portswigger.net/web-security | This is the gold-standard resource for Web security, and the certification is incredibly useful too |
| Web-focused | websec.fr | Pure Web challenges with a clean interface | https://websec.fr | Web CTF challenges, but they'll touch on source code auditing, so better suited to more advanced players |
| Web-focused | webhacking.kr | Korean platform with fun challenges | https://webhacking.kr | All kinds of Web challenges, and genuinely challenging |
| All-round | HackMyVM | Offers downloadable virtual machines for offline practice | https://hackmyvm.eu | You can download target machines for hands-on practice, plus there are CTF challenges across every category, and even wargames to play! |
| Competition platform | ImaginaryCTF | Runs CTFs regularly, with good-quality challenges | https://imaginaryctf.org | Haven't tried it yet |
| Bug Bounty platform | YesWeHack Dojo | Monthly challenges run by a bug bounty company | https://dojo-yeswehack.com | Haven't tried it yet |
| Competition platform | AlpacaHack | Japanese platform with a built-in solving system | https://alpacahack.com | Haven't tried it yet |
| All-round | Viblo CTF | Vietnamese platform with an active Asian community | https://ctf.viblo.asia | All sorts of challenge types, with a decent number of Web ones. Some challenges are in Vietnamese and need translating, but overall it feels refreshingly new |
| Professional training | PentesterLab | Reproduces real vulnerabilities, very effective for learning | https://pentesterlab.com | Topic-based learning that lets you dive deep into different Web subjects. There's a fair bit of difficulty, but the teaching resources are thorough, so the challenges never feel alien |
| Professional training | Root-Me | A veteran European platform with a huge variety of challenges | https://www.root-me.org | A massive variety of challenges. Web is even split into client-side and server-side, and there's a Network category that Web work often overlaps with too, so you can get to grips with the underlying infrastructure. Super important!!! |
| Other | PwnTillDawn | Gamified design with an achievement system | https://online.pwntilldawn.com/ | Haven't tried it yet |
| All-round, Web-leaning | echoCTF.RED | Open-source platform you can self-host | https://echoctf.red | Machine-based CTF challenges where a single target may hold several flags, letting you dig deep into all kinds of services and vulnerabilities. It also thoughtfully includes a beginners' zone, making it great for learning and getting started |
| All-round | CyberTalents | A Middle Eastern platform | https://cybertalents.com | Challenges of every type, completely free, and great for beginners |
| All-round | Flagyard | A relatively new platform | https://flagyard.com | Haven't tried it yet |
| All-round | HackerLab.pro | An up-and-coming platform | https://hackerlab.pro/en | A Russian CTF platform with a wide variety of challenges that are both distinctive and difficult. Some challenges are in Russian and again need translating, but it's good training precisely because writeups are almost impossible to find and hints are scarce |
| All-round | 316CTF | An up-and-coming platform | https://play.316ctf.com/ | Plenty of Web-related challenges, plus a special "password cracking" category. There's some repetition, but it helps cement what you've learned |
Platforms That Are Good for Writeups
If you want to document your learning journey by writing writeups, all of these platforms welcome you to publish your solutions:
🎯 Writeup-Friendly Platforms
| Platform | Notes | Link |
|---|---|---|
| picoCTF | Education-focused platform that encourages sharing your learning process (hiding the flag values is recommended) | https://picoctf.org |
| TryHackMe | No restrictions at all; the community frequently shares complete walkthroughs | https://tryhackme.com |
| PortSwigger | Officially welcomes technical sharing; explaining the concepts in detail adds even more value | https://portswigger.net/web-security |
| websec.fr | Share freely, no restrictions | https://websec.fr |
| webhacking.kr | Korean platform; you're free to publish | https://webhacking.kr |
| HackMyVM | Virtual machine challenges; sharing is welcome | https://hackmyvm.eu |
| ImaginaryCTF | You can publish once the competition ends, and the organizers release solutions too | https://imaginaryctf.org |
| AlpacaHack | Has a built-in system but doesn't restrict external sharing | https://alpacahack.com |
| echoCTF.RED | Open-source spirit; sharing is allowed (hiding the flag is recommended) | https://echoctf.red |
| OverTheWire | Share your approach and reasoning (avoid posting passwords directly) | https://overthewire.org |
📅 Timing-Restricted Platforms
These platforms welcome writeups too; you just need to mind the timing of your publication:
| Platform | When You Can Publish | Link |
|---|---|---|
| Hack The Box | You can publish for retired machines | https://www.hackthebox.com |
| YesWeHack Dojo | You can publish after that month's challenge ends | https://dojo-yeswehack.com |
💡 Other Platforms
Some platforms may have specific rules (for example, PwnTillDawn requires you to check the licensing of individual machines), some prefer that you use their built-in system (such as Viblo CTF), and a few have policies that aren't entirely clear. If you're unsure, it's best to ask the organizers or the community first.
If you're just getting into CTFs and want to practice writing writeups, these platforms are especially well suited:
- picoCTF - Moderate difficulty and a friendly community
- TryHackMe - Guided, so your writeups come out more structured. TryHackMe is running a promotion right now! Use my invite link to jump in and start learning: tryhackme.com/invite/pcc402
- PortSwigger - Learn Web security and practice your writing at the same time
- OverTheWire Bandit - A classic entry point, and many people's very first writeup
Writing writeups isn't just about sharing; it's also a great way to cement your knowledge. Pick a platform you like and get started!
Continually updated; contributions welcome
📮 Get in Touch
- Email: [email protected]
Happy Hacking! 🚀
Member discussion