Cloud security CTF challenges

Hands-on AWS, GCP, and Azure CTF challenges built for security teams who want practice that feels real.

Sample challenge library

Browse a few samples here, then write us for full library access and custom paths.

27 challenges found

  • IAM Privilege Escalation
    Hard
    Chain IAM permissions to gain admin access in a locked-down account.
    privilege escalationpolicy chaining
    AWS2-4 hr
  • S3 Bucket Misconfig
    Medium
    A bucket policy grants public read access. Find the flaw and restrict it.
    bucket policiesdata exposure
    AWS45 min
  • Overly Permissive KMS Key Policy
    Medium
    A key policy grants decrypt to the wrong principal. Find the exposure and tighten it.
    key policiesencryption
    AWS1 hr
  • Public ECR Repository
    Easy
    An ECR repository allows anonymous pull. Locate the policy flaw and lock it down.
    registry accesscontainer images
    AWS30 min
  • Lambda Execution Role
    Easy
    A Lambda function inherits excessive permissions. Scope the execution role.
    IAM rolesleast privilege
    AWS30 min
  • GCS Bucket Misconfig
    Medium
    A Cloud Storage bucket allows public object listing. Find and fix the exposure.
    Cloud Storagedata exposure
    GCP45 min
  • Service Account Escalation
    Hard
    Chain IAM roles and service account permissions to reach project admin.
    service accountsprivilege escalation
    GCP2-3 hr
  • Overly Broad RBAC Role
    Hard
    A Contributor assignment is wider than intended. Trace the path and tighten scope.
    privilege escalation
    Azure2-3 hr
  • Public Blob Container
    Medium
    A storage container allows anonymous read. Find the exposure and lock it down.
    Azure Storageblob accessdata exposure
    Azure45 min
  • S3 Bucket Policy Misconfiguration
    Easy
    Identify and exploit overly permissive S3 bucket policies that expose sensitive data. Practice least-privilege fixes.
    IAM policiesdata exposureleast privilege
    AWS30-45 min
  • Instance Metadata Credential Theft
    Medium
    Abuse IMDSv1 to obtain credentials and pivot. Compare metadata service hardening options.
    credential theftlateral movement
    AWS60-90 min
  • Lambda Environment Injection
    Medium
    Exploit a vulnerable Lambda path to inject environment values and reach command execution.
    environment variablesinjectionserverless
    AWS45-60 min
  • CloudTrail Log Analysis and Forensics
    Hard
    Analyze CloudTrail events to reconstruct a credential compromise chain.
    log analysisforensicsincident response
    AWS90-120 min
  • EFS Encryption Misconfiguration
    Medium
    Find improperly protected EFS data and tighten encryption and access controls.
    encryptiondata-at-rest
    AWS45-60 min
  • Secrets in Parameter Store
    Easy
    Extract secrets from Parameter Store via overly permissive IAM access.
    secrets managementleast privilege
    AWS30-45 min
  • VPC Endpoint Policy Abuse
    Hard
    Abuse VPC endpoint policies to reach restricted storage resources.
    endpointsnetwork securitydata exfiltration
    AWS75-90 min
  • Cognito Identity Pool Exploitation
    Medium
    Abuse a misconfigured Cognito identity pool to obtain temporary credentials.
    identitytemporary credentialsauthentication
    AWS60-75 min
  • Cloud Storage ACL Enumeration
    Easy
    Enumerate and abuse overly permissive Cloud Storage ACLs.
    Cloud Storagedata exposureenumeration
    GCP30-45 min
  • Service Account Impersonation
    Medium
    Abuse IAM allow policies to impersonate privileged service accounts.
    service accountsimpersonationprivilege escalation
    GCP60-90 min
  • Cloud Run Privilege Escape
    Hard
    Escape a vulnerable Cloud Run deployment and reach project metadata.
    containersprivilege escapemetadata
    GCP75-90 min
  • BigQuery SQL Injection
    Medium
    Use SQL injection against a BigQuery-backed path to reach unauthorized datasets.
    SQL injectiondata access
    GCP45-60 min
  • Firewall Rule Analysis and Bypass
    Hard
    Analyze VPC firewall rules, find gaps, and bypass intended controls.
    network securityrules analysisbypass
    GCP90-120 min
  • Storage Account Shared Access Signature
    Easy
    Abuse overly permissive SAS tokens to access Storage containers.
    Azure Storagedata accesstoken security
    Azure30-45 min
  • Managed Identity Privilege Escalation
    Medium
    Abuse a misconfigured managed identity to reach Key Vault secrets.
    privilege escalation
    Azure60-90 min
  • Container Instance Escape
    Hard
    Escape a vulnerable Azure Container Instance and assess host exposure.
    container escapeisolation
    Azure75-90 min
  • Entra ID OAuth Manipulation
    Medium
    Abuse a weak OAuth flow to obtain tokens and reach unauthorized resources.
    tokensauthentication
    Azure60-75 min
  • Network Security Group Rule Abuse
    Hard
    Analyze and abuse misconfigured NSG rules to reach restricted resources.
    network securityrule analysislateral movement
    Azure90-120 min

Cloud domains we cover

  • Identity

    IAM, service accounts, cloud RBAC, roles, and privilege escalation paths used in real cloud pentests.

  • Storage

    Object storage buckets, key policies, and data exposure scenarios that leak in production.

  • Networking

    Firewall rules, network exposure, and lateral movement inside cloud VPCs.

  • Containers

    Execution roles, registry access, and runtime misconfigs in cloud-native services.

How challenges work

  1. Pick a challenge

    Filter by cloud, domain, and difficulty.

  2. Launch your sandbox

    An isolated environment spins up for that challenge.

  3. Investigate and exploit

    Work the scenario with hints or without them.

  4. Verify and learn

    Submit the flag and review the solution path.

Frequently asked questions

Get cloud CTF access for your team

Tell us about your team and we will quote full CTF access for you.