Skip to main content
This page aggregates cross-platform resources to practice Brute Force / Rate-Limit Bypass: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 21 challenges across 3 platforms — 12 HackTheBox · 1 PortSwigger · 8 TryHackMe. 12 with a Spanish writeup, 12 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. TryHackMeEnumeration & Brute Force (Easy · ~30 min) · 🇬🇧
  2. TryHackMeFowsniff CTF (Easy · ~45 min) · 🇬🇧
  3. TryHackMeh4cked (Easy · ~45 min) · 🇬🇧
  4. TryHackMeMS Sentinel: Just Looking (Easy · ~60 min) · 🇬🇧
  5. TryHackMeWindows Logging for SOC (Easy · ~60 min) · 🇬🇧
  6. PortSwiggerBypassing GraphQL brute force protections (Practitioner) · 🇬🇧

Curated resources

HTB machines practicing Brute Force / Rate-Limit Bypass (12)

PortSwigger labs practicing Brute Force / Rate-Limit Bypass (1)

TryHackMe rooms practicing Brute Force / Rate-Limit Bypass (8)


Back to the full glossary Last updated: 2026-08-13