# Pwned Labs > Pwned Labs provides hands-on cloud and AI security training. Learners build skills in guided labs in the Academy, validate them in production-like cyber ranges, and earn certifications through on-demand bootcamps. Every lab and every certification exam runs in real cloud infrastructure rather than a simulation. The company also delivers cloud penetration testing and security assessment services. Customers include enterprises, government bodies and financial institutions. Coverage spans AWS, Microsoft Azure and Microsoft 365, Google Cloud and Google Workspace, Oracle Cloud Infrastructure, Kubernetes, CI/CD pipelines, and AI and agentic systems, from both attacker and defender perspectives. Bootcamps are fully on-demand: there are no live cohorts and learners start immediately. Certification exams are assessed hands-on in a live cloud environment, not by multiple choice. Every customer is screened against international sanctions lists before onboarding, and enterprise plans include SSO/SAML, SCIM provisioning and manager reporting. ## Key facts - 89 hands-on labs are published, covering AWS (49), Azure and Microsoft 365 (24), Google Cloud and Google Workspace (11), Kubernetes (3) and Oracle Cloud Infrastructure (2). Every one runs in a real cloud environment provisioned by Pwned Labs, so learners do not need their own AWS, Azure or Google Cloud account. - The Academy has a free tier. Paid plans unlock premium labs, cyber ranges and certification paths. - Eight bootcamps and certifications are offered across AWS, Azure and Microsoft 365, Google Cloud, multi-cloud, Kubernetes and AI systems. - Six named cyber ranges are available. Three form the SkyFall Enterprise collection delivered privately to a customer's team (PromptStorm, StormShadow and PhantomWave), and three are try-out ranges for annual subscribers (Mirage, Electra and ThunderDome). They span AWS, Azure and Microsoft 365, Google Cloud and Google Workspace, multi-cloud, and AI and LLM workloads. - Certification exams give 24 hours to complete an attack chain from a supplied entry point to a flag. They are not proctored and no penetration test report is required. - Certifications do not expire and never need renewing. A Credly digital badge is issued alongside the certificate. - Bootcamp registration includes 45 days of Academy access across every lab on the platform, plus lifetime access to the custom bootcamp labs, the capstone CTF, course materials and private Discord channels. ## Certifications - [AWS Red Team Certification (ACRTP)](https://pwnedlabs.io/bootcamps/aws-red-team-certification-acrtp): Amazon Cloud Red Team Professional. Hands-on exam in a live AWS account covering IAM abuse, privilege escalation and lateral movement. 399 USD. - [Azure Red Team Certification (MCRTP)](https://pwnedlabs.io/bootcamps/azure-red-team-certification-mcrtp): Microsoft Cloud Red Team Professional. Hands-on exam in a live Azure and Microsoft 365 tenant covering Entra ID abuse, token theft and lateral movement. 399 USD. - [GCP Red Team Certification (GCRTP)](https://pwnedlabs.io/bootcamps/gcp-red-team-certification-gcrtp): Google Cloud Red Team Professional. Hands-on exam in a live Google Cloud and Google Workspace environment covering service account impersonation and privilege escalation. 399 USD. - [Microsoft Cloud Red Team Expert (MCRTE)](https://pwnedlabs.io/bootcamps/microsoft-cloud-red-team-expert-mcrte): expert tier for Microsoft cloud. Requires operating a command and control framework and a phishing component. Lifetime lab access and two exam attempts. 2,500 USD, or 2,000 USD for enterprise customers and MCRTP alumni. - [M-CRTP3 Certification](https://pwnedlabs.io/bootcamps/m-crtp3-certification): Multi-Cloud Red Team Professional, awarded on completing ACRTP, MCRTP and GCRTP. Bundle covers all three bootcamps with two exam attempts for each. 999 USD. - [Expert-Level Certifications](https://pwnedlabs.io/bootcamps/expert-level-certifications): overview of Pwned Labs expert-tier cloud attack and defense certifications ## Bootcamps - [Bootcamps overview](https://pwnedlabs.io/bootcamps): on-demand cloud attack and defense bootcamps leading to certification - [Microsoft Cloud Attack and Defense, Professional (MCRTP)](https://pwnedlabs.io/bootcamps/mcrtp-bootcamp): Azure and Microsoft 365 attack and defense - [Amazon Cloud Attack and Defense, Professional (ACRTP)](https://pwnedlabs.io/bootcamps/placrtp-bootcamp): AWS attack and defense - [Google Cloud Attack and Defense, Professional (GCRTP)](https://pwnedlabs.io/bootcamps/gcrtp-bootcamp): Google Cloud and Workspace attack and defense - [Microsoft Cloud Attack and Defense, Expert (MCRTE)](https://pwnedlabs.io/bootcamps/mcrte-bootcamp): expert-level Microsoft cloud bootcamp for senior practitioners - [Kubernetes Attack and Defense, Professional (KRTP)](https://pwnedlabs.io/bootcamps/krtp-bootcamp): four on-demand sessions, each under four hours, taking you from zero Kubernetes knowledge to root on a node and on into the cloud account behind it. Session one builds fundamentals in minikube, since most Kubernetes attack tradecraft is identical across EKS, GKE and AKS. Sessions two and three cover turning a service account token into a cloud credential on each provider. Session four is the purple capstone, covering in-cluster and cloud-side persistence, weaponizing admission webhooks, evading runtime and audit controls, and analyzing Kubernetes audit logs to hunt your own persistence. Leads to the Kubernetes Red Team Professional (KRTP) certification. - [AI Systems Attack and Defense, Professional (AISRTP)](https://pwnedlabs.io/bootcamps/aisrtp-bootcamp): on-demand bootcamp covering practical attack and defense of LLM-backed and agentic applications, including direct and indirect prompt injection, RAG and embedding poisoning, tool abuse and excessive agency, and agentic compromise across CI/CD agents and MCP-connected tool servers. Applies the same tradecraft across AWS Bedrock, Azure AI Foundry, Google Vertex AI and self-hosted stacks. Leads to the AI Systems Red Team Professional (AISRTP) certification. ## Training - [Academy](https://pwnedlabs.io/): guided red and blue team labs across AWS, Azure, GCP, OCI, Kubernetes and AI environments - [Explore the labs](https://pwnedlabs.io/explore): full catalog of 90 hands-on labs, with red team and blue team scenarios, across AWS, Azure and Microsoft 365, Google Cloud and Workspace, Kubernetes and Oracle Cloud Infrastructure - [Cyber Ranges](https://pwnedlabs.io/cyber-ranges): multi-stage red and blue team scenarios in realistic cloud environments, listed in full below - [Azure Security Training](https://pwnedlabs.io/bootcamps/azure-security-training): hands-on Azure attack and defense skills for individuals - [GCP Security Training](https://pwnedlabs.io/bootcamps/gcp-security-training): hands-on Google Cloud attack and defense skills for individuals - [Plans and pricing](https://pwnedlabs.io/pricing): individual and team subscription options ## Security Services - [Cloud Penetration Testing](https://pwnedlabs.io/business/cloud-penetration-testing): manual testing across AWS, Azure and Google Cloud covering identity, data stores, workloads and CI/CD - [AWS Penetration Testing](https://pwnedlabs.io/business/aws-pentesting): IAM and IAM Identity Center, S3, EC2 and instance metadata, Lambda and API Gateway, ECS and EKS, CI/CD federation - [Azure Penetration Testing](https://pwnedlabs.io/business/azure-pentesting): Entra ID, conditional access, consent and OAuth abuse, storage and Key Vault, managed identities, hybrid Active Directory paths - [GCP Penetration Testing](https://pwnedlabs.io/business/gcp-pentesting): Cloud IAM and service account impersonation, resource hierarchy inheritance, Cloud Storage and BigQuery, GKE, Workload Identity Federation - [Cloud Security Assessment](https://pwnedlabs.io/business/cloud-security-assessment): configuration and architecture review of cloud environments - [Cloud Security Training for Teams](https://pwnedlabs.io/business/cloud-security-training): structured upskilling programs for security and engineering teams - [Azure Security and UAE Cybersecurity Compliance](https://pwnedlabs.io/business/uae-cybersecurity-compliance): cloud security assessment aligned to UAE regulatory requirements - [Cloud Security Assessment for Saudi Arabia](https://pwnedlabs.io/business/cloud-security-assessment-saudi-arabia): cloud security assessment aligned to Saudi Arabia regulatory requirements ## For Business - [Pwned Labs for Business](https://pwnedlabs.io/business): team training with manager reporting, SSO/SAML and SCIM - [Book a demo](https://pwnedlabs.io/business/demo): schedule a walkthrough with the team - [Business trial](https://pwnedlabs.io/business/trial): two-week team trial - [Trust and Security](https://pwnedlabs.io/trust): data protection, customer screening and enterprise security review information ## Careers and Learning Paths - [Cloud Security Engineer: role, skills and career path](https://pwnedlabs.io/resources/cloud-security-engineer): what the role involves, the skill areas it requires, how to move into it from five common backgrounds, and interview questions - [Cloud Security Engineer Roadmap](https://pwnedlabs.io/resources/cloud-security-engineer-roadmap): free step-by-step roadmap, readable in full as a web page, covering Linux and containers, cloud provider fundamentals, security principles, the attacker mindset, automation, IAM, network security, data security, logging and monitoring, and incident response ## Cyber Ranges Cyber ranges are realistic, multi-stage red and blue team scenarios across cloud environments, designed to validate capability rather than teach a single technique. They sit above the individual labs: a lab teaches one technique, a range requires chaining many of them under time pressure. ### SkyFall Enterprise Cyber Ranges SkyFall is the enterprise collection, delivered as private scenarios for a customer's own team. Red teams execute multi-stage attack paths across identities, automation and cloud services while blue teams investigate, contain and restore under the same conditions. - Private instances so each team trains in an isolated environment - Red and blue teams operate side by side with role-based access controls - Scoring, checkpoints and after-action review to track progress and debrief outcomes - Custom scenarios tailored to a customer's own stack and threat model on request - [PromptStorm](https://pwnedlabs.io/cyber-ranges/promptstorm): AWS breach targeting AI and LLM workloads. Trace initial access, contain escalation, hunt persistence, remove crypto-mining and restore services. [AWS, AI and LLM] - **StormShadow**: web to cloud breach in AWS. Operators start with no credentials at the application edge, turn a web weakness into a foothold, enumerate what the compromised workload can assume, locate exposed build artifacts, follow weak trust boundaries between the application tier and the control plane, and climb roles to account takeover. Rewards methodical enumeration over a single decisive exploit. [AWS] - **PhantomWave**: exploit web flaws to land in Google Cloud, loot storage buckets and source repositories, pivot to internal applications that trust their network position, steal metadata tokens from over-permissioned workloads, and abuse IAM and the CI/CD pipeline. Built around what makes Google Cloud different: hierarchy-inherited permissions, service account impersonation, and a metadata service that hands credentials to anything on an instance. [GCP and Google Workspace] ### Cyber Ranges for annual subscribers Annual subscribers get access to try-out ranges across AWS, Azure and Microsoft 365, and Google Cloud and Google Workspace. - [Mirage](https://pwnedlabs.io/cyber-ranges/mirage): external adversary scenario across Entra ID, Azure, Microsoft 365, AKS, APIM and AI services. Gain a foothold, expand access, and reach protected assets. [Azure and Microsoft 365] ([overview](https://pwnedlabs.io/cyber-ranges/mirage-overview)) - [Electra](https://pwnedlabs.io/cyber-ranges/electra): a realistic AWS breach that starts with hands-on web exploitation. Map trust, escalate via IAM and resource policies, and reach a high-impact target. [AWS] ([overview](https://pwnedlabs.io/cyber-ranges/electra-overview)) - [ThunderDome](https://pwnedlabs.io/cyber-ranges/thunderdome): cross-cloud campaign via shared identity and integrations. Gain access in one cloud, pivot via trust paths, and complete a cross-cloud objective chain. [Multi-cloud] ([overview](https://pwnedlabs.io/cyber-ranges/thunderdome-overview)) ## Hands-On Labs Every lab runs in a live cloud environment provisioned by Pwned Labs. Learners do not need their own cloud account. Difficulty is shown in brackets. ### AWS labs (49) - [AWS S3 Enumeration Basics](https://pwnedlabs.io/explore/aws-s3-enumeration-basics): Enumerate S3 buckets to gain a foothold and escalate in AWS [Beginner] - [Abuse Cognito User and Identity Pools](https://pwnedlabs.io/explore/abuse-cognito-user-and-identity-pools): Exploit Cognito pool misconfigurations to breach cloud infrastructure and move laterally through Lambda [Beginner] - [Abuse OpenID Connect and GitLab for AWS Access](https://pwnedlabs.io/explore/abuse-openid-connect-and-gitlab-for-aws-access): Ride a permissive OIDC trust policy from GitLab into an AWS account [Beginner] - [Abuse S3 Replication and Batch Ops to Exfiltrate Data](https://pwnedlabs.io/explore/abuse-s3-replication-and-batch-ops-to-exfiltrate-data): Weaponize S3 replication and batch operations to exfiltrate sensitive data [Beginner] - [Abuse Unauthenticated API to Leak Data](https://pwnedlabs.io/explore/abuse-unauthenticated-api-to-leak-data): Exploit a private API Gateway and chain leaked credentials to raid S3 [Intermediate] - [Access Secrets with S3 Bucket Versioning](https://pwnedlabs.io/explore/access-secrets-with-s3-bucket-versioning): Recover secrets from old S3 object versions the admins forgot to lock down [Beginner] - [Assume Privileged Role with External ID](https://pwnedlabs.io/explore/assume-privileged-role-with-external-id): Turn an exposed config file into a privileged AWS role assumption [Beginner] - [Breach in the Cloud](https://pwnedlabs.io/explore/breach-in-the-cloud): Hunt malicious CloudTrail activity to reconstruct a real AWS breach [Beginner] - [Build a Malware Scanning Solution in AWS](https://pwnedlabs.io/explore/build-a-malware-scanning-solution-in-aws): Build a working malware-scanning pipeline for file uploads in AWS [Beginner] - [Bypass Restrictions in API Gateway](https://pwnedlabs.io/explore/bypass-restrictions-in-api-gateway): Follow a red team methodology to bypass restrictions in AWS API Gateway [Beginner] - [Command Injection to EC2 User Data Privilege Escalation](https://pwnedlabs.io/explore/command-injection-to-ec2-user-data-privilege-escalation): Escalate from OS command injection to EC2 user data privilege escalation [Beginner] - [Compromise Splunk for AWS Privilege Escalation](https://pwnedlabs.io/explore/compromise-splunk-for-aws-privilege-escalation): Weaponize a malicious Splunk add-on to seize the host and widen AWS access [Intermediate] - [Create Custom Tooling to Explore AWS](https://pwnedlabs.io/explore/create-custom-tooling-to-explore-aws): Build your own Python tooling to enumerate an AWS environment [Beginner] - [Detect Malicious Activity with AWS Honey Tokens](https://pwnedlabs.io/explore/detect-malicious-activity-with-aws-honey-tokens): Plant native AWS honey tokens with IAM, CloudWatch, CloudTrail, and Lambda [Beginner] - [Detect Threats in the Cloud with ELK Stack](https://pwnedlabs.io/explore/detect-threats-in-the-cloud-with-elk-stack): Track threat actors through AWS CloudTrail logs using the ELK Stack [Beginner] - [Escalate Privileges by IAM Policy Rollback](https://pwnedlabs.io/explore/escalate-privileges-by-iam-policy-rollback): Abuse a dangerous IAM permission to roll back policies and escalate in AWS [Beginner] - [Execute and Identify Credential Abuse in AWS](https://pwnedlabs.io/explore/execute-and-identify-credential-abuse-in-aws): Run and detect a range of AWS credential abuse techniques [Beginner] - [Exfiltrate Secrets via Amazon SNS Abuse](https://pwnedlabs.io/explore/exfiltrate-secrets-via-amazon-sns-abuse): Abuse Amazon SNS to exfiltrate secrets, then build the defenses against it [Intermediate] - [Exploit Jenkins in the Cloud](https://pwnedlabs.io/explore/exploit-jenkins-in-the-cloud): Exploit common Jenkins misconfigurations to compromise a cloud-hosted instance [Beginner] - [Exploit Weak Bucket Policies for Privileged Access](https://pwnedlabs.io/explore/exploit-weak-bucket-policies-for-privileged-access): Leak bucket contents through weak S3 policies to gain privileged access [Beginner] - [File Upload XXE to Initial Access](https://pwnedlabs.io/explore/file-upload-xxe-to-initial-access): Exploit an XXE file upload to compromise cloud infrastructure and steal secrets [Beginner] - [Get Situational Awareness in AWS with Cloudfox](https://pwnedlabs.io/explore/get-situational-awareness-in-aws-with-cloudfox): Map an AWS environment fast with CloudFox after finding committed keys [Beginner] - [Hijack Orphaned S3 Buckets for Data Access](https://pwnedlabs.io/explore/hijack-orphaned-s3-buckets-for-data-access): Hijack orphaned S3 buckets to intercept requests and access sensitive data [Intermediate] - [Hunt for Secrets in Git Repos](https://pwnedlabs.io/explore/hunt-for-secrets-in-git-repos): Hunt leaked credentials across git repositories to breach a target [Beginner] - [Hunt in the Cloud with Splunk](https://pwnedlabs.io/explore/hunt-in-the-cloud-with-splunk): Investigate AWS security threats hands-on with Splunk [Beginner] - [Identify IAM Breaches with CloudTrail and Athena](https://pwnedlabs.io/explore/identify-iam-breaches-with-cloudtrail-and-athena): Query CloudTrail with Amazon Athena to identify compromised IAM users [Beginner] - [Identify the AWS Account ID from a Public S3 Bucket](https://pwnedlabs.io/explore/identify-the-aws-account-id-from-a-public-s3-bucket): Recover an AWS account ID from a public S3 bucket and leverage it [Beginner] - [Intro to AWS IAM Enumeration](https://pwnedlabs.io/explore/intro-to-aws-iam-enumeration): Enumerate AWS IAM users, roles, groups, and policies with the CLI [Beginner] - [Investigate Threats with Amazon Detective](https://pwnedlabs.io/explore/investigate-threats-with-amazon-detective): React fast to security events by investigating threats with Amazon Detective [Beginner] - [Investigate a Ransomware Attack in AWS using Splunk](https://pwnedlabs.io/explore/investigate-a-ransomware-attack-in-aws-using-splunk): Trace a cloud ransomware attack through AWS CloudTrail using Splunk [Intermediate] - [Leverage Insecure Storage and Backups for Profit](https://pwnedlabs.io/explore/leverage-insecure-storage-and-backups-for-profit): Turn backup files on accessible storage into deeper cloud and domain access [Beginner] - [Leverage Leaked Credentials for Pwnage](https://pwnedlabs.io/explore/leverage-leaked-credentials-for-pwnage): Turn leaked secrets into full compromise of a cloud environment and its PII [Beginner] - [Leverage Writable S3 Bucket to Steal Admin Cookie](https://pwnedlabs.io/explore/leverage-writable-s3-bucket-to-steal-admin-cookie): Abuse a writable S3 bucket to steal a privileged admin session cookie [Beginner] - [Loot Public EBS Snapshots](https://pwnedlabs.io/explore/loot-public-ebs-snapshots): Mine exposed public EBS snapshots for credentials and sensitive data [Beginner] - [Path Traversal to AWS credentials to S3](https://pwnedlabs.io/explore/path-traversal-to-aws-credentials-to-s3): Exploit path traversal to steal AWS credentials and reach S3 [Beginner] - [Pillage Exposed RDS Instances](https://pwnedlabs.io/explore/pillage-exposed-rds-instances): Brute-force a publicly exposed Amazon RDS instance and pillage its data [Beginner] - [Plunder Public RDS Snapshots](https://pwnedlabs.io/explore/plunder-public-rds-snapshots): Restore an exposed public RDS snapshot to plunder its database contents [Beginner] - [Prevent Breaches with AWS IAM Access Analyzer](https://pwnedlabs.io/explore/prevent-breaches-with-aws-iam-access-analyzer): Harden IAM hands-on with AWS IAM Access Analyzer to prevent breaches [Beginner] - [Pwn TeamCity in the Cloud](https://pwnedlabs.io/explore/pwn-teamcity-in-the-cloud): Abuse default settings and misconfigurations to pwn a cloud-hosted TeamCity server [Beginner] - [Remediate Risks with Prowler and AWS Security Hub CPSM](https://pwnedlabs.io/explore/remediate-risks-with-prowler-and-aws-security-hub): Audit an AWS environment with Prowler and report findings to Security Hub [Beginner] - [Remediate Vulnerabilities with Amazon Inspector](https://pwnedlabs.io/explore/remediate-vulnerabilities-with-amazon-inspector): Harden your attack surface with Amazon Inspector vulnerability scanning [Beginner] - [Reveal Hidden Risks with AWS Security Hub CSPM](https://pwnedlabs.io/explore/reveal-hidden-risks-with-aws-security-hub): Surface and prioritize security issues across AWS with Security Hub CSPM [Beginner] - [S3 Bucket Brute Force to Breach](https://pwnedlabs.io/explore/s3-bucket-brute-force-to-breach): Brute-force public S3 buckets to breach and move through a cloud environment [Beginner] - [SQS and Lambda SQL Injection](https://pwnedlabs.io/explore/sqs-and-lambda-sql-injection): Exploit SQL injection through SQS and Lambda in a serverless application [Intermediate] - [SSRF to Pwned](https://pwnedlabs.io/explore/ssrf-to-pwned): See how SSRF turns severe when the target runs on an EC2 instance [Beginner] - [Secure S3 with Amazon Macie](https://pwnedlabs.io/explore/secure-s3-with-amazon-macie): Discover sensitive data and secure exposed S3 buckets with Amazon Macie [Beginner] - [Unauthenticated AWS IAM Principals Enumeration](https://pwnedlabs.io/explore/unauthenticated-aws-iam-principals-enumeration): Enumerate IAM users and roles across AWS accounts without any credentials [Beginner] - [Uncover Secrets in CodeCommit and Docker](https://pwnedlabs.io/explore/uncover-secrets-in-codecommit-and-docker): Uncover leaked credentials buried in CodeCommit repositories and Docker images [Beginner] - [Understand Authentication Mechanisms Using Boto3](https://pwnedlabs.io/explore/understand-authentication-mechanisms-using-boto3): Explore AWS authentication with Python and boto3 across STS, S3, and Secrets Manager [Intermediate] ### Azure and Microsoft 365 labs (24) - [Abuse Azure Logic App Automation](https://pwnedlabs.io/explore/abuse-azure-logic-app-automation): Turn a misconfigured Logic App into a foothold across Microsoft Cloud [Beginner] - [Abuse Dynamic Groups in Entra ID for Privilege Escalation](https://pwnedlabs.io/explore/abuse-dynamic-groups-in-entra-id-for-privilege-escalation): Hijack dynamic group membership in Entra ID to escalate your privileges [Beginner] - [Abuse JWT Assertion in Azure](https://pwnedlabs.io/explore/abuse-jwt-assertion-in-azure): Chain certificate authentication, PIM, and container registry to escalate privileges in Azure [Intermediate] - [Abuse Open Redirect for Token Stealing and Hybrid Attacks](https://pwnedlabs.io/explore/abuse-open-redirect-for-token-stealing-and-hybrid-attacks): Phish OAuth2 tokens and pivot between Azure and on-premises Active Directory [Intermediate] - [Azure Blob Container to Initial Access](https://pwnedlabs.io/explore/azure-blob-container-to-initial-access): Mine an exposed Azure Blob container for secrets and initial cloud access [Beginner] - [Azure Recon to Foothold and Profit](https://pwnedlabs.io/explore/azure-recon-to-foothold-and-profit): Break into Azure, build situational awareness, and steadily widen your access [Beginner] - [Breach the Perimeter via Prompt Injection](https://pwnedlabs.io/explore/breach-the-perimeter-via-prompt-injection): Prompt-inject an AI assistant to steal SAS tokens and service principal credentials [Beginner] - [Bypass Azure MFA with Evilginx](https://pwnedlabs.io/explore/bypass-azure-mfa-with-evilginx): Phish and capture cloud credentials using the Evilginx adversary-in-the-middle framework [Beginner] - [Bypass Azure Web App Authentication with Path Traversal](https://pwnedlabs.io/explore/bypass-azure-web-app-authentication-with-path-traversal): Exploit path traversal to bypass authentication on a locked-down Azure Web App [Beginner] - [Emulate Storm-0501 Tactics for Cloud Compromise](https://pwnedlabs.io/explore/emulate-storm-0501-tactics-for-cloud-compromise): Emulate Storm-0501 tradecraft to exfiltrate a managed identity token from Azure [Intermediate] - [Execute Azure Credential Shuffle to Achieve Objectives](https://pwnedlabs.io/explore/execute-azure-credential-shuffle-to-achieve-objectives): Work the Azure kill chain with the credential shuffle to reach your objectives [Beginner] - [Exploit Indirect Prompt Injection for Azure Access](https://pwnedlabs.io/explore/exploit-indirect-prompt-injection-for-azure-access): Abuse indirect prompt injection in an AI assistant to breach the Azure perimeter [Beginner] - [Exploit MFA Enablement Gaps for Resource Access](https://pwnedlabs.io/explore/exploit-mfa-enablement-gaps-for-resource-access): Bypass MFA through enablement gaps and abuse native API calls in Azure [Intermediate] - [Exploit SQL Injection in Azure Function App](https://pwnedlabs.io/explore/exploit-sql-injection-in-azure-function-app): Exploit SQL injection and a managed identity in a serverless Azure Function App [Beginner] - [Gain Initial Access via Social Engineering](https://pwnedlabs.io/explore/gain-initial-access-via-social-engineering): Target the human layer with social engineering to bypass a hardened perimeter [Intermediate] - [Intro to Azure Recon with BloodHound](https://pwnedlabs.io/explore/intro-to-azure-recon-with-bloodhound): Map abusable Azure attack paths with BloodHound and the AzureHound collector [Beginner] - [Leverage Device Code Phishing for Initial Access](https://pwnedlabs.io/explore/leverage-device-code-phishing-for-initial-access): Run device code phishing to breach Azure and compromise a Windows user [Intermediate] - [Loot Exchange, Teams and SharePoint with GraphRunner](https://pwnedlabs.io/explore/loot-exchange-teams-sharepoint-with-graphrunner): Loot Exchange, Teams, and SharePoint using the GraphRunner post-exploitation toolset [Beginner] - [Maneuver Through Azure Service Firewalls](https://pwnedlabs.io/explore/maneuver-through-azure-service-firewalls): Slip through configuration gaps in Azure Service Firewalls to reach protected assets [Intermediate] - [Passwordless Credentials for Access and Escalation](https://pwnedlabs.io/explore/passwordless-credentials-for-access-and-escalation): Abuse service principals and managed identities to move laterally through Azure [Beginner] - [Phished for Initial Access](https://pwnedlabs.io/explore/phished-for-initial-access): Get hands-on with phishing, token abuse, and Office 365 data exfiltration [Beginner] - [Plunder Azure DevOps for Cloud Credentials](https://pwnedlabs.io/explore/plunder-azure-devops-for-cloud-credentials): Exploit Azure DevOps pipelines to extract secrets and reach Azure resources [Beginner] - [Unlock Access with Azure Key Vault](https://pwnedlabs.io/explore/unlock-access-with-azure-key-vault): Abuse Azure Key Vault and storage tables to move laterally through Azure [Beginner] - [Unmask Privileged Access in Azure](https://pwnedlabs.io/explore/unmask-privileged-access-in-azure): Unmask hidden secrets to escalate laterally and vertically through Azure [Beginner] ### Google Cloud and Google Workspace labs (11) - [Abuse SSTI and IAP Tunneling to Increase Access](https://pwnedlabs.io/explore/abuse-ssti-and-iap-tunneling-to-increase-access): Exploit template injection, then tunnel through IAP into a GCP production database [Beginner] - [Escalate GCP privileges with Implicit Delegation](https://pwnedlabs.io/explore/escalate-gcp-privileges-with-implicit-delegation): Escalate GCP privileges with implicit delegation and the Token Creator role [Beginner] - [Exploit SSRF with Gopher for GCP Initial Access](https://pwnedlabs.io/explore/exploit-ssrf-with-gopher-for-gcp-initial-access): Abuse SSRF with the Gopher protocol to reach GCP instance metadata [Beginner] - [Gain Entry to GCP via GitLab Commit](https://pwnedlabs.io/explore/gain-entry-to-gcp-via-gitlab-commit): Turn an accidental GitLab commit into a foothold in a GCP environment [Beginner] - [Illuminate GCP by Fuzzing IAM Permissions](https://pwnedlabs.io/explore/illuminate-gcp-by-fuzzing-iam-permissions): Fuzz testIamPermissions to map GCP access and exfiltrate from Artifact Registry [Beginner] - [Impersonate GCP Service Account for Privileged Access](https://pwnedlabs.io/explore/impersonate-gcp-service-account-for-privileged-access): Exploit an exposed git directory and impersonate a GCP service account [Beginner] - [Infiltrate GCP via WebApp Exploitation](https://pwnedlabs.io/explore/infiltrate-gcp-via-webapp-exploitation): Exploit a web app to compromise the host and infiltrate GCP [Intermediate] - [Leverage Google Workspace for GCP Resource Access](https://pwnedlabs.io/explore/leverage-google-workspace-for-gcp-resource-access): Pivot from a Windows jumpbox through Google Workspace into GCP resources [Beginner] - [Pivot Through Service Accounts using Dangerous Permissions](https://pwnedlabs.io/explore/pivot-through-service-accounts-using-dangerous-permissions): Abuse dangerous IAM permissions to pivot and escalate through GCP service accounts [Intermediate] - [Reveal Hidden Files in Google Storage](https://pwnedlabs.io/explore/reveal-hidden-files-in-google-storage): Exploit misconfigured Google Cloud Storage to bypass the perimeter and reach customer data [Beginner] - [Tunnel Through GCP via JWT Forgery](https://pwnedlabs.io/explore/tunnel-through-gcp-via-jwt-forgery): Forge JWTs to pivot through over-privileged roles and exfiltrate GCP data [Intermediate] ### Kubernetes labs (3) - [Escalate from SSJI to EKS](https://pwnedlabs.io/explore/escalate-from-ssji-to-eks): Chain Node.js application flaws into administrative control of an AWS EKS cluster [Beginner] - [Exploit Kubernetes Overly Permissive RBAC](https://pwnedlabs.io/explore/exploit-kubernetes-overly-permissive-rbac): Identify and exploit overly permissive Kubernetes RBAC to take over a cluster [Intermediate] - [Secure Kubernetes using OPA Gatekeeper](https://pwnedlabs.io/explore/secure-kubernetes-using-opa-gatekeeper): Enforce Kubernetes security and compliance policies with OPA Gatekeeper [Intermediate] ### Oracle Cloud Infrastructure labs (2) - [Compromise, Recon and Exfiltration in OCI](https://pwnedlabs.io/explore/compromise-recon-and-exfiltration-in-oci): Use stolen auditor credentials to enumerate and exfiltrate data from Oracle Cloud [Beginner] - [Leverage LFI for RCE and OCI Access](https://pwnedlabs.io/explore/leverage-lfi-for-rce-and-oci-access): Convert local file inclusion into RCE and loot OCI Vault secrets [Beginner] ## Security A-Z Glossary - [Glossary index](https://pwnedlabs.io/glossary): plain-language explanations of cloud and AI security concepts - [What is AI Red Teaming?](https://pwnedlabs.io/glossary/ai-red-teaming) - [What is AiTM?](https://pwnedlabs.io/glossary/what-is-aitm) - [What is Attack Path Analysis?](https://pwnedlabs.io/glossary/attack-path-analysis) - [What is AWS IAM PassRole?](https://pwnedlabs.io/glossary/what-is-aws-iam-passrole) - [What is AWS Privilege Escalation?](https://pwnedlabs.io/glossary/aws-privilege-escalation) - [What is Cloud Controller Manager?](https://pwnedlabs.io/glossary/what-is-cloud-controller-manager) - [What is Cloud Detection Engineering?](https://pwnedlabs.io/glossary/cloud-detection-engineering) - [What is Cloud IAM Privilege Escalation?](https://pwnedlabs.io/glossary/cloud-iam-privilege-escalation) - [What is Cloud Incident Response?](https://pwnedlabs.io/glossary/cloud-incident-response) - [What is a Cloud Misconfiguration?](https://pwnedlabs.io/glossary/cloud-misconfiguration) - [What is Cloud Security Posture Management (CSPM)?](https://pwnedlabs.io/glossary/cloud-security-posture-management-cspm) - [What is CNAPP?](https://pwnedlabs.io/glossary/what-is-cnapp) - [What is a DaemonSet?](https://pwnedlabs.io/glossary/what-is-deamonset) - [What is Detection as Code?](https://pwnedlabs.io/glossary/what-is-detection-as-code) - [What is Entra ID Security?](https://pwnedlabs.io/glossary/entra-id-security) - [What is GitHub Actions OIDC?](https://pwnedlabs.io/glossary/github-actions-oidc) - [What is Indirect Prompt Injection?](https://pwnedlabs.io/glossary/what-is-indirect-prompt-injection) - [What is a Kubernetes Admission Controller?](https://pwnedlabs.io/glossary/what-is-kubernetes-admission-controller) - [What is MFA Fatigue?](https://pwnedlabs.io/glossary/what-is-mfa-fatigue) - [What is an OCI Instance Principal?](https://pwnedlabs.io/glossary/what-is-oci-instance-principal) - [What is a Privileged Container?](https://pwnedlabs.io/glossary/what-is-privileged-container) - [What is Sidecar Injection?](https://pwnedlabs.io/glossary/what-is-sidecar-injection) ## Resources - [Blog](https://pwnedlabs.io/blog): cloud and cyber security tradecraft articles - [PWNCLOUDOS](https://pwnedlabs.io/pwncloudos): multi-cloud security tooling environment - [Events](https://pwnedlabs.io/events): webinars and meetups - [Community](https://discord.gg/pwnedlabs): Pwned Labs Discord community - [About](https://pwnedlabs.io/about): company background and team ## Security - [Vulnerability Disclosure Policy](https://pwnedlabs.io/security-policy): scope, safe harbor and how to report security issues in Pwned Labs services - [security.txt](https://pwnedlabs.io/.well-known/security.txt): machine-readable security contact ## Legal - [Privacy Policy](https://pwnedlabs.io/privacy-policy) - [Terms and Conditions](https://pwnedlabs.io/terms-and-conditions)