Learn ethical hacking.
Assess real targets.
CyberaHAT is an AI-first platform to master offensive security in isolated Docker labs, then run an automated assessment pipeline that plans, scans, and reports — all in one place.
Two disciplines, one platform
Most tools teach or assess. CyberaHAT does both: a personalized, AI-guided learning path that builds real skills, wired directly into a working security-assessment pipeline — so what you learn flows straight into practice.
Everything the platform can do
A complete toolkit for learning offensive security and running real assessments.
AI-Guided Courses
Structured courses → modules → lessons spanning core ethical-hacking domains, with theory, labs, and graded quizzes.
Hands-On Docker Labs
Launch isolated, ephemeral lab containers with a live in-browser terminal to practice on real environments safely.
AI Coach & Tutor
An AI coach gives progressive hints while you work in a lab, plus a general tutor chat for any security question.
On-Demand Study Guides
Generate a full, structured study guide on any cybersecurity topic — concepts, examples, and practice, on demand.
Adaptive Quizzes
AI generates quizzes tuned to your current mastery and targets your weakest topics, across multiple question types.
AI Learning Profile
Per-topic mastery tracking, a skill level from beginner to expert, strengths, weaknesses, and focus recommendations.
Automated Security Scanning
An AI-planned DAST pipeline points 10 industry scanners at an authorized target, each in its own isolated container.
Professional Reports
Findings scored with CVSS and mapped to CWE & OWASP, exported as four PDF formats with AI-written narratives.
Gamification & Certificates
Capture flags inside labs and earn a certificate when you complete a course — progress that feels rewarding.
Instructor Analytics
Class-wide dashboards: engagement trends, hardest topics, level distribution, and students who need support.
Admin & Role Management
A full RBAC model with an admin dashboard to manage users and assign roles and permissions in real time.
Built-In Practice Target
A bundled OWASP Juice Shop instance lets you validate scans against a deliberately-vulnerable app out of the box.
Your journey, step by step
From your first lesson to a full security report — here is the real flow.
Create your account
Sign up in seconds. You start as a learner with your own AI learning profile and personalized dashboard.
Learn hands-on
Work through courses and launch ephemeral Docker labs with a live terminal — your AI coach nudges you with hints, never spoilers.
Test your knowledge
Take adaptive quizzes tuned to your mastery and generate on-demand study guides for any topic you want to sharpen.
Assess real targets
With scanning access, point the pipeline at an authorized target — the AI plans a toolchain and runs each scanner in isolation.
Review & report
Findings are risk-scored and mapped to CWE/OWASP. Export executive, technical, developer, or learning PDF reports.
Track growth & earn certificates
Your topic mastery updates automatically, recommendations adapt, and completing a course earns you a certificate.
Built to actually make you better
Real strengths of the platform — no fluff, just what it does well.
AI-first & personalized
Adaptive quizzes, per-topic mastery, an AI coach, and a living learning profile — the platform adapts to you, not the other way around.
Genuinely hands-on
Real tools in real, isolated Docker containers. You practice by doing — safely — instead of just reading slides.
A real assessment pipeline
Not a toy scanner. Ten industry-standard tools, AI-driven planning, a job queue, and structured findings.
Presentation-ready reporting
CVSS scoring, CWE/OWASP mapping, and four polished PDF report formats generated for you automatically.
Built for security
Role-based access control, JWT with refresh-token rotation, bcrypt password hashing, and full audit logging.
Learn-to-assess in one place
Education and real-world assessment live in the same product, so skills flow straight into practice.
The people behind CyberaHAT
Muhammad Haroon Rashid
Team Lead
Leads the project and architects the full-stack platform across the API, web app, and AI integration.
Awais Farhan Alam
Member
Works across backend services and the security-assessment pipeline, wiring tools, scans, and reporting.
Muhammad Tayyab Ur Rehman
Member
Focuses on the learning experience and front-end — courses, labs, quizzes, and the AI-guided UI.
Frequently asked questions
CyberaHAT is an AI-first cybersecurity platform that combines guided, hands-on ethical-hacking education with a real automated security-assessment pipeline. You learn in isolated Docker labs and, with the right access, run scans against authorized targets and generate professional reports.
You use the platform in your browser. The hands-on labs and the security scanners run inside Docker containers managed by the platform, so a Docker environment is required on the server that hosts CyberaHAT.
No — scanning is protected by role-based access control. New accounts start as learners focused on courses, labs, and quizzes. Running active scans requires the scanner (or admin) role, which an administrator can grant from the admin dashboard.
The pipeline orchestrates ten industry-standard tools: Nmap, WhatWeb, Gobuster, ffuf, Dirb, Nuclei, Nikto, OWASP ZAP, Wapiti, and SQLMap. In smart mode, the AI fingerprints the target and selects an appropriate toolchain.
Findings are scored with CVSS and mapped to CWE and OWASP categories, with an overall risk score. You can export four PDF report formats — executive, technical, developer, and learning — each with an AI-generated narrative.
As you take quizzes and complete labs, the platform tracks your mastery per topic and builds an AI learning profile with your level, strengths, weaknesses, and focus areas. Adaptive quizzes then target your weakest topics.
CyberaHAT is for authorized security testing and education only. Labs and scanners run in isolated containers, and a bundled OWASP Juice Shop target lets you practice scanning legally out of the box. Never scan systems you are not authorized to test.
Passwords are hashed with bcrypt, authentication uses JSON Web Tokens with refresh-token rotation, access is governed by role-based permissions, and sensitive actions are recorded in an audit log.