Home/Catalogue/Cloud Security
Exercise domain

Cloud Security

6 drills · 0 playable free, no sign-up

Most cloud incidents are configuration, not exploitation. These exercises walk the settings that matter: the bucket that went public, the role that could do anything, the admin console open to the internet, and the root account without a hardware key.

CIS BenchmarksNIST CSFCSA CCMWell-Architected Security
In build

The public bucket

A storage bucket is set to public "just to test", and it is still public a year later. See how it is found and how to close it.

CIS 3ATT&CK T1530
In buildFoundational · 6 min
In build

The role that can do anything

A service uses a wildcard permission because it was quicker. Trim it to least privilege before the credential is the whole account.

CIS 5CWE-269
In buildCore · 8 min
In build

The admin console on the internet

A management dashboard is reachable from anywhere with a default login. Understand exposure and put it behind the controls it needs.

CIS 4ATT&CK T1133
In buildCore · 7 min
In build

Protect the root account

The root account runs daily tasks and has no hardware key. Learn why it should be locked away and how access should really work.

CIS 1NIST PR.AA
In buildFoundational · 6 min
In build

Logging you can actually use

When something happens, the logs are off or nobody looks. Set up the trail that turns an incident into an answer.

CIS 8NIST DE.CM
In buildCore · 7 min
In build

The snapshot shared with the world

A disk snapshot is marked public to share with a contractor, and it holds a whole database. Trace the exposure and the safe alternative.

CIS 3ATT&CK T1530
In buildAdvanced · 8 min
How to play these. Each drill with a Play exercise link opens straight into that scenario in the 3D sim: finish it, then come back and pick another, or hit Play the full track to run them back to back. Drills marked In the program ship with the guided rollout. Book a demo for the full library.