SShieldSync Labs

AWS Security Labs

Practise cloud security in real, isolated AWS accounts.

Every lab spins up its own throwaway AWS account, hands you the real console, and wipes it when you're done. No setup, no bill, no risk to anything real.

2 live · 4 more on the way · first beginner lab is free.

BeginnerFREE

S3 misconfiguration & data exposure

Find and fix public buckets, missing encryption, and over-broad IAM in a realistic mini-account, then verify your fixes.

S3IAMEncryption
~30 minOpen lab
Intermediate

IAM privilege escalation

Leaked CI credentials can quietly escalate to full admin. Discover the path, prove it by capturing a flag, then close the hole.

IAMPrivilege EscalationLeast Privilege
~75 minOpen lab
BeginnerComing soon

KMS & data protection

Encrypt the right things the right way: KMS key policies, grants, and enforcing encryption across services.

KMSEncryptionKey Policy
~80 minSoon
IntermediateComing soon

GuardDuty & Security Hub triage

Work a stream of findings: separate signal from noise, triage by severity, and decide what to action.

GuardDutySecurity HubDetection
~90 minSoon
AdvancedComing soon

CloudTrail forensics

Reconstruct an attacker's actions from CloudTrail: trace the access path, find what was touched, and scope the blast radius.

CloudTrailForensicsIR
~120 minSoon
IntermediateComing soon

VPC network exposure

Hunt down over-permissive security groups and network paths that expose workloads, and lock them down.

VPCSecurity GroupsNetworking
~90 minSoon