StormShadow
Red Team Cyber Range

Part of the SkyFall Enterprise Cyber Range Collection, built to validate offensive capability against a realistic web to cloud attack path in AWS.

  • Start at the application edge and finish in control of the AWS account
  • Chain pivots through exposed artifacts and weak trust boundaries rather than a single exploit
  • Private instance for your team, with scoring, checkpoints and an after-action review


    Ideal for: red teamers, penetration testers, cloud security engineers and application security specialists
StormShadow_SkyFall

Overview

StormShadow is an offensive cyber range in the SkyFall Enterprise collection, built around the route attackers most often take into a cloud account: through the application sitting in front of it.

Operators begin with no credentials and work from the web tier inward, turning an application weakness into a foothold, then following the trust relationships that connect that workload to the wider AWS environment. The range rewards methodical enumeration over a single decisive exploit, because progress depends on noticing what a compromised component is permitted to do.

source_code-1

The scenario

An internet-facing application runs in an AWS environment that has grown organically.

  • Build artifacts are reachable by more principals than intended
  • Trust boundaries were drawn once and never revisited
  • Roles carry permissions that are safe alone and dangerous combined
  • Nothing here is flagged as a misconfiguration by a scanner


None of this is unusual. The objective is to demonstrate how an attacker moves from the outside of that application to administrative control of the account it runs in.

aws_admin_access-1

The attack path

Operators work the full arc from external reconnaissance to account takeover.

Exploit the application to establish a foothold. Enumerate what the compromised workload can reach and what it is permitted to assume. Locate exposed artifacts and use them to widen access. Follow weak trust boundaries between the application tier and the control plane. Climb through roles until the account is yours. Each stage requires evidence from the one before it, so there is no fixed sequence to memorise.

attack_chain

What StormShadow is designed to test

StormShadow puts offensive judgment to the test under realistic conditions.

  • Exploiting an application as a route into cloud infrastructure
  • Enumerating IAM permissions and identifying escalation paths
  • Recognising exposed build artifacts as an access vector
  • Reasoning about trust between workloads and the control plane
  • Chaining small weaknesses into a single high-impact outcome
  • Working without prior knowledge of the environment


The test is in the reasoning and the chaining, not in executing a fixed sequence of commands.

aws_graph-2

The Environment

Teams operate inside a realistic AWS environment matched to the scenario, with:

  • A private instance so your team trains in isolation
  • An internet-facing application tier with a genuine route inward
  • Identity and permissions that reflect real abuse paths
  • Build and deployment artifacts positioned as they are in production
  • Scoring and checkpoints to track progress through the chain
  • An after-action review to debrief outcomes and identify gaps


Red and blue teams can run side by side with role-based access controls, and custom scenarios matched to your own stack are available on request.

See StormShadow in action and request pricing
 

Got any Questions? Get in touch