PhantomWave
Red Team Cyber Range

Part of the SkyFall Enterprise Cyber Range Collection, built to validate offensive capability across Google Cloud and Google Workspace.

  • Move from a web application weakness into the Google Cloud project behind it
  • Loot storage and source repositories, then pivot to internal applications
  • Private instance for your team, with scoring, checkpoints and an after-action review


    Ideal for: red teamers, penetration testers, cloud security engineers and CI/CD security specialists
PhantomWave_SkyFall

Overview

PhantomWave is an offensive cyber range in the SkyFall Enterprise collection, set across Google Cloud and Google Workspace, where operators start outside the environment and work inward through a web application.

Google Cloud concentrates risk in places that differ from AWS and Azure. The resource hierarchy inherits permissions downward, service accounts can act as one another, and the metadata service will hand credentials to anything running on an instance. PhantomWave is built so operators have to understand those specifics rather than transfer assumptions from another provider.

enterprise_security

The scenario

A Google Cloud project supports an internet-facing application, with everything the team needs behind it.

  • Source repositories and storage buckets sit behind the application
  • A deployment pipeline holds permissions to change the project
  • Access was granted at the level convenient at the time
  • Internal applications trust anything already inside the perimeter


The objective is to demonstrate how far an attacker gets from a single web flaw when storage, source control, identity and automation are connected by permissions nobody mapped end to end.

raincloud-3

The attack path

Operators work the full arc from external access to the most sensitive assets in the project.

Exploit web flaws to land in Google Cloud. Loot storage buckets and source repositories for what has been left in them. Pivot to internal applications that trust their position inside the network. Phish active users and harvest data from Google Workspace. Steal metadata tokens from workloads holding more permission than they need. Abuse IAM and the CI/CD pipeline to consolidate access. Each stage depends on evidence gathered in the one before it.

dangerous_permissions

What PhantomWave is designed to test

PhantomWave puts offensive judgment to the test under realistic conditions.

  • Exploiting web application flaws as a route into a cloud project
  • Finding value in storage buckets and source repositories
  • Recognising the metadata service as a credential source
  • Understanding service account impersonation and the resource hierarchy
  • Abusing CI/CD pipelines that hold deployment permissions
  • Pivoting to internal applications that trust their network position


The test is in the reasoning and the chaining, not in executing a fixed sequence of commands.

google_cloud2

The Environment

Teams operate inside a realistic Google Cloud and Google Workspace environment, with:

  • A private instance so your team trains in isolation
  • An internet-facing application with a genuine route into the project
  • Identity and permissions reflect real abuse paths, including inherited roles
  • Production storage, source control and a deployment pipeline
  • Scoring and checkpoints to track progress through the chain
  • An after-action review to debrief outcomes and identify gaps


Red and blue teams can run side by side with role-based access controls, and custom scenarios matched to your own stack are available on request.

See PhantomWave in action and request pricing
 

Got any Questions? Get in touch