StormShadow
Red Team Cyber Range
Part of the SkyFall Enterprise Cyber Range Collection, built to validate offensive capability against a realistic web to cloud attack path in AWS.
- Start at the application edge and finish in control of the AWS account
- Chain pivots through exposed artifacts and weak trust boundaries rather than a single exploit
- Private instance for your team, with scoring, checkpoints and an after-action review
Ideal for: red teamers, penetration testers, cloud security engineers and application security specialists
Overview
StormShadow is an offensive cyber range in the SkyFall Enterprise collection, built around the route attackers most often take into a cloud account: through the application sitting in front of it.
Operators begin with no credentials and work from the web tier inward, turning an application weakness into a foothold, then following the trust relationships that connect that workload to the wider AWS environment. The range rewards methodical enumeration over a single decisive exploit, because progress depends on noticing what a compromised component is permitted to do.
The scenario
An internet-facing application runs in an AWS environment that has grown organically.
- Build artifacts are reachable by more principals than intended
- Trust boundaries were drawn once and never revisited
- Roles carry permissions that are safe alone and dangerous combined
- Nothing here is flagged as a misconfiguration by a scanner
None of this is unusual. The objective is to demonstrate how an attacker moves from the outside of that application to administrative control of the account it runs in.
The attack path
Operators work the full arc from external reconnaissance to account takeover.
Exploit the application to establish a foothold. Enumerate what the compromised workload can reach and what it is permitted to assume. Locate exposed artifacts and use them to widen access. Follow weak trust boundaries between the application tier and the control plane. Climb through roles until the account is yours. Each stage requires evidence from the one before it, so there is no fixed sequence to memorise.
What StormShadow is designed to test
StormShadow puts offensive judgment to the test under realistic conditions.
- Exploiting an application as a route into cloud infrastructure
- Enumerating IAM permissions and identifying escalation paths
- Recognising exposed build artifacts as an access vector
- Reasoning about trust between workloads and the control plane
- Chaining small weaknesses into a single high-impact outcome
- Working without prior knowledge of the environment
The test is in the reasoning and the chaining, not in executing a fixed sequence of commands.
The Environment
Teams operate inside a realistic AWS environment matched to the scenario, with:
- A private instance so your team trains in isolation
- An internet-facing application tier with a genuine route inward
- Identity and permissions that reflect real abuse paths
- Build and deployment artifacts positioned as they are in production
- Scoring and checkpoints to track progress through the chain
- An after-action review to debrief outcomes and identify gaps
Red and blue teams can run side by side with role-based access controls, and custom scenarios matched to your own stack are available on request.