There is a general perception that hackers suddenly infiltrate systems and devices and launch attacks. However, the reality is different. Hackers take time to understand the networks and systems they are targeting before launching an attack. They try to understand the network topologies, as well as the software and devices used. Then, they try to understand how they can exploit these to their advantage.
On the other hand, defending against attacks also cannot be done in real time. Security prefer to focus on defense by ensuring that all external systems are patched and properly configured. If a hacker somehow manages to breach the external defenses, the automated intrusion prevention systems (IPS) and threat detection systems (IDS), security teams take on the task of limiting the damage caused.

One can configure a server to scan the Internet, looking for obvious “holes” that can be exploited with script-based attacks. Because these occur at such a high volume, it is not really reliable to deal with them manually. Security teams are usually involved in this process after a breach . Among the steps they take are trying to determine the point of entry and closing it so that it cannot be used again. Security incident response teams also try to determine what damage has been caused and how to fix it, while also looking for any regulatory compliance issues that they need to address.
Hackers occasionally carry out their attacks in real time, however, it is usually for “support” rather than strategic purposes. A typical example is Capture the Flag (CTF) competitions. These are often held at infosec conferences, such as the various BSides events. There, hackers compete against each other to complete challenges within a set time frame. The more challenges they win, the more points they accumulate. There are two types of CTF competitions. During a Red Team event, hackers individually (or a team of hackers) attempt to successfully penetrate specific systems that do not have active defenses. They are challenged to “break” a form of protection that was introduced prior to the competition.

The second type of competition pits Red Teams against defensive Blue Teams. Red Teams earn points by successfully infiltrating target systems, while Blue Teams are judged on how effectively they thwart these attacks.
Challenges vary between events, but are typically designed to test skills used by security professionals every day. These include programming, exploiting known vulnerabilities in systems, and reverse engineering. While CTF events are quite competitive, they are rarely “hostile.” Hackers are, by nature, curious and eager to share their knowledge with others. Therefore, it is common for opposing teams or spectators to share information that could help an opponent.

Such events were scheduled to take place in 2020, but were postponed or canceled due to the COVID-19. However, interested parties can still participate in a CTF event, while adhering to social distancing rules and other required protective measures.
Additionally, sites like CTFTime aggregate upcoming CTF events. CTFTime even displays a leaderboard of the most successful teams. Additionally, interested parties can also take part in solo hacking challenges. The site Root-Me offers various challenges that test hackers to their limits.

Another option, if you're not afraid to create a hacker environment on your personal computer, is the Damn Vulnerable Web Application (DVWA). As the name suggests, this web application is intentionally full of security flaws, allowing would-be hackers to test their skills in a safe and legal way.
