Find your lab

Get started for free

SSRF to Pwned

We created this beginner-friendly lab to showcase how a Server Side Request Forgery (SSRF) vulnerability can potentially be much more severe, when...

imds CTF ssrf
+6 more

Pillage Exposed RDS Instances

We created this beginner-friendly lab to teach about the danger of publicly accessible Amazon Relational Database Service (RDS) instances, and how...

CTF brute force nmap
+2 more

Abuse Cognito User and Identity Pools

We created this beginner-friendly lab to showcase how Cognito User and Identity Pool configurations can allow malicious actors to gain a foothold in...

lambda source code review ssrf
+4 more

Abuse JWT Assertion in Azure

We created this intermediate-level lab to demonstrate how threat actors can use Certificate-Based Authentication (CBA), Privileged Identity...

SATO JWT Assertion PIM
+4 more

Assume Privileged Role with External ID

We created this beginner-friendly lab to showcase the real-world danger of exposed configuration files, and how using production accounts for testing...

CTF cloud shell external id
+7 more

AWS S3 Enumeration Basics

We created this beginner-friendly lab to give an introduction to one of the most popular AWS services - S3 (Simple Storage Service), and show how...

CTF s3 aws

Azure Blob Container to Initial Access

We created this beginner-friendly lab to give an introduction to one of the most popular Azure services - Blob Storage, and show how attackers can...

entra id CTF blob storage
+1 more

Azure Recon to Foothold and Profit

We created this beginner-friendly lab to showcase how threat actors can get initial access to an Azure environment, and how they can go about gaining...

entra id CTF app service
+4 more

Breach in the Cloud

This lab introduces a realistic cloud security incident based on suspicious AWS CloudTrail activity.

CTF cloudtrail iam
+2 more

Breach the Perimeter via Prompt Injection

In this fun lab, students will learn how prompt-injection attacks can extract secrets from AI assistants and the dangers of leaking SAS tokens and...

prompt injection sas token service principal
+3 more

Bypass Azure MFA with Evilginx

With the hardening network perimeter, threat actors look to target users and bypass external defenses.

bypass mfa social engineering entra id
+8 more

Bypass Restrictions in API Gateway

This fun and beginner friendly lab provides a good methodology to follow when starting to assess the security of Application Programming Interfaces.

api gateway CTF iam
+1 more

Create Custom Tooling to Explore AWS

Coding is fun, and creating our own tools allows us to better understand what is happening when we run them and of the environment in which we run...

python scripting s3
+1 more

Escalate from SSJI to EKS

In this fun EKS lab, you begin from the perspective of an external threat actor and compromise ShopNest's new Node.js customer portal running on an...

ssji idor eks
+4 more

Exfiltrate Secrets via Amazon SNS Abuse

This hands-on lab guides students through the process of understanding this attack technique and implementing defenses against AWS SNS service abuse...

sns api gateway lambda
+3 more

Exploit Jenkins in the Cloud

We created this beginner-friendly lab to showcase how a cloud-based Jenkins instance can be abused due to common misconfigurations and bad practices.

CTF reverse shell groovy
+5 more

Exploit SQL Injection in Azure Function App

We created this fun and beginner-friendly lab to highlight how serverless apps are not immune to vulnerabilities affecting traditional web apps.

entra id function app managed identity
+4 more

File Upload XXE to Initial Access

We created this beginner-friendly lab to showcase how an XXE vulnerability can result in attackers compromising cloud infrastructure and accessing...

CTF lambda sqlite
+5 more

Gain Entry to GCP via GitLab Commit

We have created this beginner-friendly lab to showcase how how accidental commits to public git repositories can result in threat actors getting a...

CTF secret manager cloud sql
+3 more

Hunt in the Cloud with Splunk

We created this beginner-friendly lab to give hands-on experience with using Splunk to investigate security threats in AWS.

splunk cloudtrail aws

Infiltrate GCP via WebApp Exploitation

This intermediate-level lab involves getting hands on with web exploitation to compromise the application, underlying host and cloud environment.

create hmac cloud storage cloud function
+4 more

Intro to AWS IAM Enumeration

We created this beginner-friendly lab to give an introduction to the AWS CLI as well as IAM user, role, group, and policy enumeration.

CTF iam aws

Intro to Azure Recon with BloodHound

We created this beginner-friendly lab to showcase how both attackers and defenders can use BloodHound and the AzureHound collector to better...

entra id CTF virtual machine
+2 more

Leverage Leaked Credentials for Pwnage

We created this beginner-friendly lab to showcase how leaked secrets can result in a malicious actor pwning a cloud environment and accessing...

CTF secrets manager gitleaks
+6 more

Leverage LFI for RCE and OCI Access

In this fun lab, you will abuse path traversal to read files and convert an LFI vulnerability to RCE, then use stolen OCI creds to map cloud...

cron abuse lfi object storage
+5 more

Loot Public EBS Snapshots

We created this beginner-friendly lab to teach about the dangers of public EBS snapshots, and how this can be leveraged by an attacker.

CTF snapshot ebs
+3 more

Phished for Initial Access

Follow along in this beginner-friendly lab as we get hands on with phishing, token abuse and exfiltrating data from Office 365.

social engineering CTF exfil
+5 more

Plunder Public RDS Snapshots

We created this beginner-friendly lab to teach about the danger of public Amazon Relational Database Service (RDS) snapshots, and how this can be...

CTF snapshot postgres
+3 more

Pwn TeamCity in the Cloud

We created this beginner-friendly lab to show how a TeamCity instance installed in a cloud environment can be abused due to common bad practices and...

CTF post exploitation teamcity
+9 more

Reveal Hidden Files in Google Storage

We created this beginner-friendly lab to showcase how misconfigured and misused cloud storage can result in threat actors bypassing the perimeter and...

cloud storage CTF gcp
+2 more

S3 Bucket Brute Force to Breach

We created this beginner-friendly lab to teach about the dangers of sensitive data stored on public S3 buckets, and how threat actors can discover...

lambda ssm ffuf
+3 more

Secure Kubernetes using OPA Gatekeeper

Join us as we explore how to enhance the security and compliance of our Kubernetes clusters using Open Policy Agent (OPA) and the OPA Gatekeeper...

opa gatekeeper kubernetes

Secure S3 with Amazon Macie

We created this beginner-friendly and hand-on lab to teach about Amazon Macie, and how this powerful service can be used to improve the security of...

CTF macie s3
+1 more

SQS and Lambda SQL Injection

We created this beginner-friendly lab to showcase how how serverless applications can also be affected by web vulnerabilities such as SQL injection...

serverless CTF lambda
+5 more

Tunnel Through GCP via JWT Forgery

This fun intermediate-level lab walks through compromising a vulnerable web application to gain code execution on the host, harvest cloud...

set metadata jwt forgery cloud sql
+4 more

Unlock Access with Azure Key Vault

We created this beginner-friendly lab to showcase how attackers can leverage common services to move laterally in an Azure environment.

entra id CTF storage table
+2 more

Unmask Privileged Access in Azure

We created this beginner-friendly lab to showcase how secrets can be unmasked both online and in managed systems, and how this can be leveraged to...

entra id automation account roadrecon
+3 more