Home/Catalogue
Security Training Catalogue

Every drill, one place.

Interactive 3D exercises across phishing, ransomware, GDPR and the EU AI Act, LLM and agent security, and the bugs your developers actually ship. Pick a threat and play it. Free, no sign-up.

No exercises match that. Try another word, or clear the search.

Security Awareness

24 exercises · Phishing, ransomware, social engineering, and the everyday judgement calls that keep an attacker out.

Play now

Night Shift at Veltrix

A late shift in a logistics office. A vendor asks to change their bank details, a push keeps buzzing, and a caller says he is the CEO. Handle a full evening of pressure.

ATT&CK T1566NIST PR.ATISO A.6
Play exerciseCore · 12 min
Play now

Read the sender, not the name

A display name says one thing, the real address another. Learn where to look before you trust a message, and how a lookalike domain is built.

ATT&CK T1566.001NIST PR.AT
Play exerciseFoundational · 6 min
Play now

The bank-detail switch

A supplier emails new payment details before an invoice run. Verify the request through a channel the sender does not control before a payment leaves.

ATT&CK T1566.002NIST PR.ATISO A.5.14
Play exerciseCore · 8 min
In build

Gift cards for the boss

A short, urgent message from a manager asks you to buy gift cards quietly. Spot the business email compromise pattern and shut it down.

ATT&CK T1566NIST PR.AT
In buildFoundational · 6 min
In build

Double barrel: the call before the click

A friendly phone call warns you an email is coming, so you trust it when it lands. See how a two-step lure lowers your guard, and where it slips.

ATT&CK T1566NIST PR.AT
In buildCore · 7 min
In build

Spear phishing from your own profile

Your public posts are the attacker’s script. Watch a message built from details only a colleague should know, and learn what gives it away.

ATT&CK T1566.001ATT&CK T1598
In buildCore · 7 min
In build

Callback phishing

A receipt for something you never bought, and a number to call to cancel. The link is the phone number. Practise not dialling it.

ATT&CK T1598NIST PR.AT
In buildCore · 7 min
New

QR code phishing (quishing)

A poster or an email asks you to scan a code, and the code skips every email filter you have. Learn to treat a QR code like any other link.

ATT&CK T1566.002CIS 14
In buildFoundational · 5 min
Play now

The helpful voice on the phone

Someone from support needs a code to fix your account. Codes are never read aloud. Practise hanging up, calling back on a known number, and reporting.

ATT&CK T1598NIST PR.AT
Play exerciseCore · 8 min
In build

Smishing: the package that never came

A text says a delivery is stuck and a small fee will release it. SMS has no spam filter in front of it. Learn to read the link, not the panic.

ATT&CK T1660NIST PR.AT
In buildFoundational · 5 min
In build

Your boss on the chat app

A new number messages you as the CEO, urgent and off the usual channel. Practise moving it back to a channel you both trust before you act.

ATT&CK T1585NIST PR.AT
In buildCore · 6 min
New

Whaling with a deepfake

A finance approval comes from a face and a voice you know, live on a call. Learn the tells and the call-back rule that beats a convincing fake.

ATT&CK T1656NIST PR.AT
In buildAdvanced · 8 min
In build

Ransomware in the first ten minutes

A shared drive is encrypting file by file. Know the early signs, disconnect the right way, and raise it before it spreads across the team.

ATT&CK T1486NIST RS.MIISO A.5.24
In buildCore · 9 min
In build

The attachment that runs

A routine-looking invoice arrives with a document that wants you to enable content. See what one click sets off, and how to handle it safely.

ATT&CK T1204ATT&CK T1566.001
In buildCore · 7 min
In build

The tech support scam

A full-screen warning says your machine is infected and to call the number now. The warning is the attack. Practise closing it and reporting.

ATT&CK T1656CIS 14
In buildFoundational · 6 min
Play now

The MFA prompt that will not stop

Approvals keep arriving on your phone at 11pm. Understand push fatigue, why you never approve one you did not start, and how to report it.

ATT&CK T1621NIST PR.AACIS 6
Play exerciseCore · 7 min
In build

Account recovery, the back door

An attacker does not need your password if they can reset it. Lock down recovery email, phone and questions before someone else uses them.

ATT&CK T1098NIST PR.AA
In buildCore · 7 min
In build

One password, everywhere

A breach at one site becomes a break-in at yours when a password is reused. See credential stuffing work, then set up a manager and passkeys.

ATT&CK T1110.004CIS 5
In buildFoundational · 5 min
Play now

The USB in the car park

A branded memory stick is left by the door. Decide what to do with a device of unknown origin, and why curiosity is the whole attack.

ATT&CK T1091CIS 10
Play exerciseFoundational · 5 min
In build

Tailgating through the side door

A courier with full hands asks you to hold the door. Practise the polite, firm habit that keeps a stranger out of the building.

ATT&CK T1200ISO A.7
In buildFoundational · 6 min
In build

The unlocked workstation

You step away for two minutes and leave the screen open. See how much an insider or a visitor can do in that window, and build the lock habit.

ATT&CK T1078CIS 4
In buildFoundational · 4 min
In build

Working from the coffee shop

Open wifi, a shoulder near your screen, and a login page that looks a little off. Handle sensitive work outside the office safely.

ATT&CK T1557CIS 12
In buildFoundational · 6 min
In build

The lock icon is not enough

The padlock means the connection is private, not that the site is honest. Learn what the address bar really tells you before you type a password.

ATT&CK T1566.002NIST PR.AT
In buildFoundational · 5 min
In build

Report it in the first minute

The fastest control you have is a report. Practise the one action that turns a near miss into an early warning for the whole team.

NIST RS.COISO A.6.8
In buildFoundational · 4 min

Privacy & Compliance

9 exercises · GDPR, data handling, retention, and the EU AI Act, taught through the decisions people make with real data.

In build

The subject access request

A customer asks for everything you hold on them. Learn what counts, the clock you are on, and how to answer without leaking someone else’s data.

GDPR Art.15ISO 27701
In buildCore · 8 min
In build

Right to be forgotten

An erasure request lands. Work out what can be deleted, what must be kept, and why a backup is not an exception you can ignore.

GDPR Art.17ISO 27701
In buildCore · 7 min
In build

The over-shared spreadsheet

A colleague needs a report, so a full customer export is on its way. Practise minimising data, masking fields, and sharing the least that does the job.

GDPR Art.5NIST Privacy
In buildFoundational · 6 min
In build

A breach, and the 72 hours

A laptop with personal data is gone. Understand what makes it notifiable, who to tell, and how the first hour shapes the next 72.

GDPR Art.33NIST RS.CO
In buildCore · 9 min
In build

Lawful basis in one screen

Marketing wants to email a list. Consent or legitimate interest? Walk the decision that decides whether you can send it at all.

GDPR Art.6GDPR Art.7
In buildFoundational · 6 min
In build

The vendor with your data

A new SaaS tool will hold customer records. Check the processor, the contract, and where the data actually lives before you sign up.

GDPR Art.28ISO 27701SOC 2 CC9
In buildCore · 8 min
In build

Cross-border transfer

Data is about to leave the region. Know when that is fine, when it needs safeguards, and how to spot a transfer hiding inside a support ticket.

GDPR Ch.VISO 27701
In buildAdvanced · 8 min
New

The AI note-taker in the meeting

A bot joins the call to transcribe. Under the EU AI Act and privacy law, who consents, what is recorded, and where does the transcript go?

EU AI ActGDPR Art.5
In buildCore · 7 min
In build

Retention that runs itself

Old records pile up because deleting feels risky. Learn why keeping everything is the risk, and how a retention schedule protects people.

GDPR Art.5ISO 27701
In buildFoundational · 6 min

AI & LLM Security

8 exercises · Prompt injection, data leakage, shadow AI, and giving an assistant only the reach it should have.

In build

The email that talks to your assistant

Your AI assistant summarises an inbox, and one message contains instructions aimed at it, not you. See indirect prompt injection do its work.

OWASP LLM01MITRE ATLAS
In buildAdvanced · 9 min
New

What you paste into the chatbot

A deadline is close, so source code and a customer list go into a public assistant. Understand where that data goes and why it may not come back.

OWASP LLM06GDPR Art.5
In buildCore · 7 min
In build

Shadow AI in the browser

A free extension promises to write your replies and reads every page you open. Weigh the offer against what it quietly takes.

OWASP LLMCIS 2
In buildCore · 7 min
Play now

How much can the agent do?

An AI agent can read mail, send mail, and move files. Decide the reach it actually needs before a clever prompt uses the rest.

OWASP LLM08NIST AI RMF
Play exerciseAdvanced · 8 min
In build

The confident wrong answer

An assistant gives a policy citation that does not exist. Build the habit of checking before you act on generated text.

OWASP LLM09NIST AI RMF
In buildFoundational · 6 min
In build

Poisoned training data

A model learns from user uploads, and someone feeds it exactly what they want it to repeat. See a poisoning attempt take shape.

OWASP LLM03MITRE ATLAS
In buildAdvanced · 8 min
New

The deepfake on the video call

A finance approval comes from a face and voice you know, on a call. Learn the tells and the call-back rule that beats a convincing fake.

ATT&CK T1656NIST PR.AT
In buildCore · 8 min
In build

Secrets in the prompt

An API key goes into a prompt to "help the model help you". Understand why the prompt is not a safe place for a secret.

OWASP LLM06CWE-522
In buildCore · 6 min

Real-World Incidents

5 exercises · Playable case studies drawn from documented breaches, with the names changed and the lessons kept.

Play now

The help desk that reset the wrong account

Modelled on a 2023 casino-sector breach: a caller talks a service desk into a password reset. See how one polite call became a full intrusion.

ATT&CK T1078ATT&CK T1598
Play exerciseCore · 9 min
Play now

The invoice attachment

Based on the wave of malicious document attachments: a routine-looking invoice arrives with a payload one click away. Handle it the safe way.

ATT&CK T1566.001ATT&CK T1204
Play exerciseCore · 8 min
In build

The open storage bucket

Modelled on repeated cloud exposures: a storage bucket set to public spills customer records. Trace how it happened and how it is found.

ATT&CK T1530CIS 3
In buildAdvanced · 8 min
In build

The payroll diversion

A composite of business email compromise cases: an employee’s salary is redirected by a single convincing email to HR. Catch it in time.

ATT&CK T1566.002NIST PR.AT
In buildCore · 8 min
In build

The third party that let them in

Drawn from supply-chain intrusions: access came through a trusted supplier, not the front door. See why vendor access is your attack surface.

ATT&CK T1195ISO A.5.19
In buildAdvanced · 9 min

The Developer Track

Application security split by attack surface. Break a real bug, then write the fix. Free, hands-on, no sign-up.

Get started

Bring it to your team.

Tell us a little about your team and we will set up a walkthrough and a pilot. No data leaves this page until you press send: it opens your own email to us.

Prefer email? Write to labs@hamcodes.com.