SSRF to Pwned
We created this beginner-friendly lab to showcase how a Server Side Request Forgery (SSRF) vulnerability can potentially be much more severe, when...
We created this beginner-friendly lab to showcase how a Server Side Request Forgery (SSRF) vulnerability can potentially be much more severe, when...
We created this beginner-friendly lab to teach about the danger of publicly accessible Amazon Relational Database Service (RDS) instances, and how...
We all want to automate tasks, and focus on more enjoyable problems!
We created this beginner-friendly lab to showcase how Cognito User and Identity Pool configurations can allow malicious actors to gain a foothold in...
The lab introduces a fun scenario where our red team needs to access the secret algorithm of Mega Big Tech's social media app.
We created this intermediate-level lab to demonstrate how threat actors can use Certificate-Based Authentication (CBA), Privileged Identity...
This intermediate lab takes you end-to-end through phishing, exploiting web app flaws for OAuth2 abuse, Azure and on-premises hybrid connections...
We created this lab to highlight how an overly permissive (and realistic) OpenID Connect role assumption policy can lead to threat actors gaining...
This fun lab explores the powerful S3 features of replication and batch operations, and how they can be used by threat actors to access sensitive...
This lab simulates a realistic penetration test of a startup's Google Cloud Platform (GCP) environment.
In this fun lab, you'll pivot from external recon to internal access, exploiting a misconfigured private AWS API Gateway.
We created this beginner-friendly lab to teach about the potential dangers of S3 bucket versioning, if the admins have not sufficiently restricted...
We created this beginner-friendly lab to showcase the real-world danger of exposed configuration files, and how using production accounts for testing...
We created this beginner-friendly lab to give an introduction to one of the most popular AWS services - S3 (Simple Storage Service), and show how...
We created this beginner-friendly lab to give an introduction to one of the most popular Azure services - Blob Storage, and show how attackers can...
We created this beginner-friendly lab to showcase how threat actors can get initial access to an Azure environment, and how they can go about gaining...
This lab introduces a realistic cloud security incident based on suspicious AWS CloudTrail activity.
In this fun lab, students will learn how prompt-injection attacks can extract secrets from AI assistants and the dangers of leaking SAS tokens and...
Build, break and fix! This is the way to have fun when learning cybersecurity.
With the hardening network perimeter, threat actors look to target users and bypass external defenses.
This lab highlights that securely configured Azure Web App resources can still be undone by flaws in deployed code!
This fun and beginner friendly lab provides a good methodology to follow when starting to assess the security of Application Programming Interfaces.
We created this beginner-friendly lab to showcase how an OS command injection vulnerability can result in attackers compromising cloud infrastructure.
Learn how to leverage defensive infrastructure to achieve our objectives in this intermediate lab.
In this fun lab, your red team has obtained valid Oracle Cloud Infrastructure (OCI) CLI credentials issued to an auditor.
Coding is fun, and creating our own tools allows us to better understand what is happening when we run them and of the environment in which we run...
We created this beginner-friendly and hands-on lab to teach about honey tokens and how digital tripwires can be implemented natively using AWS...
We created this beginner-friendly lab to give hands-on experience with using ELK Stack to investigate security threats in AWS.
In this fun lab, students will examine and emulate tradecraft associated with Storm-0501, exploit a vulnerable Function App to exfiltrate a managed...
In this fun EKS lab, you begin from the perspective of an external threat actor and compromise ShopNest's new Node.js customer portal running on an...
In this challenge, you will escalate your privileges by leveraging both the implicitDelegation privilege and the Service Account Token Creator role...
We created this beginner-friendly lab to showcase a potentially dangerous IAM permission, and how it could be leveraged to increase our access in an...
We created this beginner-friendly lab to showcase variety of credential abuse techniques and how they can be detected and mitigated.
We created this beginner-friendly red team lab to showcase how threat actors can achieve their objectives in Azure by performing the "credential...
This hands-on lab guides students through the process of understanding this attack technique and implementing defenses against AWS SNS service abuse...
In this fun prompt injection lab, you'll assess a newly deployed AI assistant to see if its features can be abused to breach the perimeter...
We created this beginner-friendly lab to showcase how a cloud-based Jenkins instance can be abused due to common misconfigurations and bad practices.
Join us as we explore the risks of overly permissive Role-Based Access Control (RBAC) in Kubernetes with this hands-on lab.
We can often come up against MFA on engagements.
We created this fun and beginner-friendly lab to highlight how serverless apps are not immune to vulnerabilities affecting traditional web apps.
The beginner-friendly and fun web exploitation lab shows how the impact of an SSRF (Server-Side Request Forgery) vulnerability can be much more...
We created this beginner-friendly lab to teach about the dangers of overly permissive bucket policies, that can leak information about bucket...
We created this beginner-friendly lab to showcase how an XXE vulnerability can result in attackers compromising cloud infrastructure and accessing...
We have created this beginner-friendly lab to showcase how how accidental commits to public git repositories can result in threat actors getting a...
This fun, intermediate-level lab explores a scenario where social engineering is used to gain access to a target environment.
Cloudfox by Seth Art is a great tool for getting situational awareness in the cloud, and this hands-on lab will introduce you to some of the really...
This lab showcases realistic tradecraft and techniques that we have seen on penetration tests for our clients.
We created this beginner-friendly lab to showcase a common issue, leaked credentials in git repositories.
We created this beginner-friendly lab to give hands-on experience with using Splunk to investigate security threats in AWS.
We created this beginner-friendly and hands-on lab to teach about AWS CloudTrail and Amazon Athena, and how these powerful services can be used to...
We created this beginner-friendly lab to teach a technique that can find an AWS account ID given a public S3 bucket, and how this can be leveraged.
The challenge revolves around leveraging the testIAMPermission method to identify IAM permissions and situational awareness.
In this scenario, you'll encounter a web server with an exposed .git directory, leading to the discovery of a GCP key file.
This intermediate-level lab involves getting hands on with web exploitation to compromise the application, underlying host and cloud environment.
We created this beginner-friendly lab to give an introduction to the AWS CLI as well as IAM user, role, group, and policy enumeration.
We created this beginner-friendly lab to showcase how both attackers and defenders can use BloodHound and the AzureHound collector to better...
Ransomware attacks in cloud environments can be made more severe by misconfigured AWS IAM and KMS services.
We created this beginner-friendly and hands-on lab to teach about Amazon Detective, and how this service can enable defenders to react quickly to...
Device code phishing is a dangerous technique, both in seeming legitimate to end users and in evading detection.
In this red team lab, you'll pivot from a compromised Windows jumpbox into Google Workspace and GCP.
We created this beginner-friendly lab to showcase how backup files on accessible storage can be used to further access within a cloud environment and...
We created this beginner-friendly lab to showcase how leaked secrets can result in a malicious actor pwning a cloud environment and accessing...
In this fun lab, you will abuse path traversal to read files and convert an LFI vulnerability to RCE, then use stolen OCI creds to map cloud...
We created this beginner-focused lab to showcase how insecure S3 bucket permissions combined with weak web server security can result in threat...
We created this beginner-friendly lab to showcase the GraphRunner Microsoft 365 post-exploitation toolset, and how it can be used to loot data from...
We created this beginner-friendly lab to teach about the dangers of public EBS snapshots, and how this can be leveraged by an attacker.
Azure Service Firewalls enforce network access controls, giving them an appearance of strong security.
We have created this fun lab to highlight alternate forms of credential that can be abused to get access and move laterally in Azure.
We created this beginner-friendly lab to showcase how a path traversal vulnerability can result in gaining a foothold in a cloud environment.
Follow along in this beginner-friendly lab as we get hands on with phishing, token abuse and exfiltrating data from Office 365.
In this lab, you'll simulate the compromise of a low-privilege service account and explore how to abuse dangerous IAM permissions to move laterally...
Compromise a developer account with access to Azure DevOps but no permissions in Azure.
We created this beginner-friendly lab to teach about the danger of public Amazon Relational Database Service (RDS) snapshots, and how this can be...
IAM is a critical component of cloud security, and it's highly recommended to get familiar with AWS IAM Access Analyzer as part of maintaining a...
We created this beginner-friendly lab to show how a TeamCity instance installed in a cloud environment can be abused due to common bad practices and...
In this lab, you will explore Prowler, an impressive open-source tool for Cloud Security Posture Management (CSPM), and report its findings to AWS...
As a blue teamer, vulnerability scanning and management tools are a perfect complement to more manual red team activities.
We created this beginner-friendly lab to showcase how misconfigured and misused cloud storage can result in threat actors bypassing the perimeter and...
We created this beginner-friendly and hands-on lab to teach about AWS Security Hub CSPM, and how this service can enable defenders see and prioritize...
We created this beginner-friendly lab to teach about the dangers of sensitive data stored on public S3 buckets, and how threat actors can discover...
Join us as we explore how to enhance the security and compliance of our Kubernetes clusters using Open Policy Agent (OPA) and the OPA Gatekeeper...
We created this beginner-friendly and hand-on lab to teach about Amazon Macie, and how this powerful service can be used to improve the security of...
We created this beginner-friendly lab to showcase how how serverless applications can also be affected by web vulnerabilities such as SQL injection...
This fun intermediate-level lab walks through compromising a vulnerable web application to gain code execution on the host, harvest cloud...
We created this beginner-friendly lab to teach various unauthenticated, cross-account IAM enumeration techniques that can be used to enumerate...
We created this beginner-friendly lab to showcase a common issue, leaked credentials in Docker images.
We created this lab to continue understanding how to interact with AWS services using Python3 and the boto3 module.
We created this beginner-friendly lab to showcase how attackers can leverage common services to move laterally in an Azure environment.
We created this beginner-friendly lab to showcase how secrets can be unmasked both online and in managed systems, and how this can be leveraged to...
No labs match your search.