Cloud security CTF challenges
Hands-on AWS, GCP, and Azure CTF challenges built for security teams who want practice that feels real.
Sample challenge library
Browse a few samples here, then write us for full library access and custom paths.
27 challenges found
Cloud domains we cover
Identity
IAM, service accounts, cloud RBAC, roles, and privilege escalation paths used in real cloud pentests.
Storage
Object storage buckets, key policies, and data exposure scenarios that leak in production.
Networking
Firewall rules, network exposure, and lateral movement inside cloud VPCs.
Containers
Execution roles, registry access, and runtime misconfigs in cloud-native services.
How challenges work
Pick a challenge
Filter by cloud, domain, and difficulty.
Launch your sandbox
An isolated environment spins up for that challenge.
Investigate and exploit
Work the scenario with hints or without them.
Verify and learn
Submit the flag and review the solution path.
Frequently asked questions
Get cloud CTF access for your team
Tell us about your team and we will quote full CTF access for you.