Self-hosted · Docker · offline
RedPlanet is seven intentionally vulnerable training ranges and 17 single-vulnerability labs — web, API, DevSecOps, network, cloud, Kubernetes and blue-team — that each stand up on your host from a single Docker image.
Each range is one Docker image. Run one on its own, stand several up side by side, or
bring up everything at once with the latest tag.
17 Mars-themed labs — one vulnerability class each — plus the Mission Control portal and a CTF scoreboard.
WebGoat, Juice Shop, the full crAPI stack, Metasploitable2 (DVWA / Mutillidae) and 7 OWASP VWAD apps.
The AppSec range plus a DevSecOps toolchain: Jenkins, GitLab CE, SonarQube, Trivy and Gitleaks.
An in-network Kali box and classic vulnerable services on a static-IP LAN; opt-in AD, CVE, ICS and VoIP packs.
A LocalStack "AWS": pivot an SSRF to the metadata service, steal credentials, and loot S3 / Secrets Manager.
A single-node k3s cluster: anonymous cluster-admin RBAC, then a privileged / hostPath escape onto the node.
The defensive range: a Suricata IDS and SOC dashboard replaying attack traffic for you to triage and hunt.
Each lab isolates a single vulnerability class. Exploit it, capture an
RP{…} flag, and track your progress on the scoreboard.
Codenames follow Mars features, moons and rovers. Static IPs on
10.66.6.0/24; the Mission Control portal at :8000 indexes every target.
One image per range, launched through the Docker socket. The controller starts the range and exits; the range keeps running.
curl -sSL https://redplanet.martiandefense.org/install.sh \ | sudo bash # choose a range (default: labs) curl ... | sudo RANGE=full-appsec bash
docker run --rm \ -v /var/run/docker.sock:/var/run/docker.sock \ martiandefense/redplanet:labs # dashboard → http://localhost:8000 # stop: add -e RP_ACTION=down
RANGE = labs · web-pentest · full-appsec · netsec · cloud · k8s · blue · all
Host ports bind to 127.0.0.1 by default. On an isolated lab network, set
LISTEN_IP=0.0.0.0 to reach targets from an attacker box.
These ranges ship real, exploitable vulnerabilities on purpose. Treat the whole project as hostile code and contain it accordingly.
127.0.0.1 binding unless you fully control the network, and never expose these services to the public internet.