Hands-On Cloud Security Labs

Hands-on cloud security labs in live AWS, Azure, GCP, Kubernetes and OCI environments. Real attack and defense scenarios, with nothing to install and no cloud account needed.

Get started for free

SSRF to Pwned

We created this beginner-friendly lab to showcase how a Server Side Request Forgery (SSRF) vulnerability can potentially be much more severe, when...

imds CTF ssrf
+6 more

Pillage Exposed RDS Instances

We created this beginner-friendly lab to teach about the danger of publicly accessible Amazon Relational Database Service (RDS) instances, and how...

CTF brute force nmap
+2 more

Abuse Cognito User and Identity Pools

We created this beginner-friendly lab to showcase how Cognito User and Identity Pool configurations can allow malicious actors to gain a foothold in...

lambda source code review ssrf
+4 more

Abuse JWT Assertion in Azure

We created this intermediate-level lab to demonstrate how threat actors can use Certificate-Based Authentication (CBA), Privileged Identity...

SATO JWT Assertion PIM
+4 more

Assume Privileged Role with External ID

We created this beginner-friendly lab to showcase the real-world danger of exposed configuration files, and how using production accounts for testing...

CTF cloud shell external id
+7 more

AWS S3 Enumeration Basics

We created this beginner-friendly lab to give an introduction to one of the most popular AWS services - S3 (Simple Storage Service), and show how...

CTF s3 aws

Azure Blob Container to Initial Access

We created this beginner-friendly lab to give an introduction to one of the most popular Azure services - Blob Storage, and show how attackers can...

entra id CTF blob storage
+1 more

Azure Recon to Foothold and Profit

We created this beginner-friendly lab to showcase how threat actors can get initial access to an Azure environment, and how they can go about gaining...

entra id CTF app service
+4 more

Breach in the Cloud

This lab introduces a realistic cloud security incident based on suspicious AWS CloudTrail activity.

CTF cloudtrail iam
+2 more

Breach the Perimeter via Prompt Injection

In this fun lab, students will learn how prompt-injection attacks can extract secrets from AI assistants and the dangers of leaking SAS tokens and...

prompt injection sas token service principal
+3 more

Bypass Azure MFA with Evilginx

With the hardening network perimeter, threat actors look to target users and bypass external defenses.

bypass mfa social engineering entra id
+8 more

Bypass Restrictions in API Gateway

This fun and beginner friendly lab provides a good methodology to follow when starting to assess the security of Application Programming Interfaces.

api gateway CTF iam
+1 more

Create Custom Tooling to Explore AWS

Coding is fun, and creating our own tools allows us to better understand what is happening when we run them and of the environment in which we run...

python scripting s3
+1 more

Escalate from SSJI to EKS

In this fun EKS lab, you begin from the perspective of an external threat actor and compromise ShopNest's new Node.js customer portal running on an...

ssji idor eks
+4 more

Exfiltrate Secrets via Amazon SNS Abuse

This hands-on lab guides students through the process of understanding this attack technique and implementing defenses against AWS SNS service abuse...

sns api gateway lambda
+3 more

Exploit Jenkins in the Cloud

We created this beginner-friendly lab to showcase how a cloud-based Jenkins instance can be abused due to common misconfigurations and bad practices.

CTF reverse shell groovy
+5 more

Exploit SQL Injection in Azure Function App

We created this fun and beginner-friendly lab to highlight how serverless apps are not immune to vulnerabilities affecting traditional web apps.

entra id function app managed identity
+4 more

File Upload XXE to Initial Access

We created this beginner-friendly lab to showcase how an XXE vulnerability can result in attackers compromising cloud infrastructure and accessing...

CTF lambda sqlite
+5 more

Gain Entry to GCP via GitLab Commit

We have created this beginner-friendly lab to showcase how how accidental commits to public git repositories can result in threat actors getting a...

CTF secret manager cloud sql
+3 more

Hunt in the Cloud with Splunk

We created this beginner-friendly lab to give hands-on experience with using Splunk to investigate security threats in AWS.

splunk cloudtrail aws

Infiltrate GCP via WebApp Exploitation

This intermediate-level lab involves getting hands on with web exploitation to compromise the application, underlying host and cloud environment.

create hmac cloud storage cloud function
+4 more

Intro to AWS IAM Enumeration

We created this beginner-friendly lab to give an introduction to the AWS CLI as well as IAM user, role, group, and policy enumeration.

CTF iam aws

Intro to Azure Recon with BloodHound

We created this beginner-friendly lab to showcase how both attackers and defenders can use BloodHound and the AzureHound collector to better...

entra id CTF virtual machine
+2 more

Leverage Leaked Credentials for Pwnage

We created this beginner-friendly lab to showcase how leaked secrets can result in a malicious actor pwning a cloud environment and accessing...

CTF secrets manager gitleaks
+6 more

Leverage LFI for RCE and OCI Access

In this fun lab, you will abuse path traversal to read files and convert an LFI vulnerability to RCE, then use stolen OCI creds to map cloud...

cron abuse lfi object storage
+5 more

Loot Public EBS Snapshots

We created this beginner-friendly lab to teach about the dangers of public EBS snapshots, and how this can be leveraged by an attacker.

CTF snapshot ebs
+3 more

Phished for Initial Access

Follow along in this beginner-friendly lab as we get hands on with phishing, token abuse and exfiltrating data from Office 365.

social engineering CTF exfil
+5 more

Plunder Public RDS Snapshots

We created this beginner-friendly lab to teach about the danger of public Amazon Relational Database Service (RDS) snapshots, and how this can be...

CTF snapshot postgres
+3 more

Pwn TeamCity in the Cloud

We created this beginner-friendly lab to show how a TeamCity instance installed in a cloud environment can be abused due to common bad practices and...

CTF post exploitation teamcity
+9 more

Reveal Hidden Files in Google Storage

We created this beginner-friendly lab to showcase how misconfigured and misused cloud storage can result in threat actors bypassing the perimeter and...

cloud storage CTF gcp
+2 more

S3 Bucket Brute Force to Breach

We created this beginner-friendly lab to teach about the dangers of sensitive data stored on public S3 buckets, and how threat actors can discover...

lambda ssm ffuf
+3 more

Secure Kubernetes using OPA Gatekeeper

Join us as we explore how to enhance the security and compliance of our Kubernetes clusters using Open Policy Agent (OPA) and the OPA Gatekeeper...

opa gatekeeper kubernetes

Secure S3 with Amazon Macie

We created this beginner-friendly and hand-on lab to teach about Amazon Macie, and how this powerful service can be used to improve the security of...

CTF macie s3
+1 more

SQS and Lambda SQL Injection

We created this beginner-friendly lab to showcase how how serverless applications can also be affected by web vulnerabilities such as SQL injection...

serverless CTF lambda
+5 more

Tunnel Through GCP via JWT Forgery

This fun intermediate-level lab walks through compromising a vulnerable web application to gain code execution on the host, harvest cloud...

set metadata jwt forgery cloud sql
+4 more

Unlock Access with Azure Key Vault

We created this beginner-friendly lab to showcase how attackers can leverage common services to move laterally in an Azure environment.

entra id CTF storage table
+2 more

Unmask Privileged Access in Azure

We created this beginner-friendly lab to showcase how secrets can be unmasked both online and in managed systems, and how this can be leveraged to...

entra id automation account roadrecon
+3 more

Escalate from Prototype Pollution to EKS Takeover

In this fun lab, you perform an external penetration test against ShopNest, a public seller portal, chaining a prototype pollution flaw into EJS template remote code execution to gain a foothold inside the environment.

aws eks prototype pollution
+8 more

What these cloud security labs cover

Every lab runs in a real cloud account that we provision for you. You get credentials, a scenario and an objective, and you work the problem the way you would at work: enumerate what you can see, find the weakness, and either exploit it or catch it in the logs. There is no simulation layer and no screenshots to click through, which is why the skills transfer.

The catalog covers 90 scenarios across five providers. 50 are AWS, 24 are Azure and Microsoft 365, 11 are Google Cloud and Workspace, 3 are Kubernetes and 2 are Oracle Cloud Infrastructure. Each one is built around a technique that appears in real cloud intrusions rather than a contrived puzzle, so the tools, log sources and API calls you use are the ones you will see again.

70 labs are rated beginner, which means they assume basic Linux command line familiarity and nothing else. The rest are intermediate and expect that you have already worked through the fundamentals of identity, storage and logging in at least one cloud provider.

Red team and blue team scenarios

75 labs are offensive. They cover initial access through leaked credentials, exposed storage, web application flaws and phishing, then privilege escalation and lateral movement through IAM roles, service accounts, service principals and federated trust. If you are preparing for cloud penetration testing work, this is the bulk of the catalog.

15 labs are defensive. They cover CloudTrail and Athena investigation, detection engineering with GuardDuty, Security Hub and Amazon Detective, hunting with Splunk and the ELK stack, honey tokens, and remediation with Prowler, Inspector and IAM Access Analyzer. Defensive content is the part of cloud security training that is most often missing elsewhere, and it is the part hiring managers ask about.

Working both directions is the fastest way to get good. An attack you can only describe in theory is one you will not recognize in log data during an incident, and a detection you have never tried to evade is one you will trust more than you should.

How to choose your first lab

Filter by the provider your organization actually runs, set the difficulty to beginner, and pick a scenario whose title describes something you have wondered about. Order matters less than starting. If you have no strong preference, the AWS beginner labs on storage enumeration and IAM enumeration are the usual entry point, because almost every later technique builds on understanding how identity and storage interact.

If you are working toward a role rather than a specific skill, the cloud security engineer roadmap sets out the ten areas to learn in order and links the labs that cover each one. If you want structured, guided progression with assessment, the bootcamps and certifications take the same material further and are assessed hands-on in a live cloud account.

Frequently asked questions

Do I need my own cloud account?

No. Every lab runs in an environment that Pwned Labs provisions and pays for. There is nothing to set up, no risk of running anything against infrastructure you care about, and no surprise bill.

Are the labs free?

Many of them are. Over 30 hands-on scenarios are free to play with a free account, and premium labs and the bootcamp tracks are available if you want the full catalog and guided progression.

What do I need to know before starting?

Basic Linux command line familiarity is enough for the beginner labs. Prior cloud experience helps but is not assumed, and each lab explains the services involved as you go.

Can I use these to prepare for a cloud security job?

That is what they are for. The scenarios are drawn from techniques used in real cloud intrusions, so the work you do here is the work the role involves. Being able to talk through an attack path you have actually executed, or an investigation you have actually run, is what separates candidates in interviews.

Do the labs cover defense as well as attack?

Yes. Alongside the offensive scenarios there are defensive labs on log analysis, detection engineering, threat hunting and remediation using the native tooling in each cloud, plus Splunk and the ELK stack.