AWS Security Labs
AWS Security Labs — practise cloud security in real, isolated AWS accounts.
Every lab spins up its own throwaway AWS account, hands you the real console, and wipes it when you're done. No setup, no bill, no risk to anything real.
3 live · 1 more on the way
All labs
Secure the Bedrock assistant (prompt injection & Guardrails)
A Bedrock-backed support assistant leaks restricted internal notes to a simple prompt injection. Prove the leak, then fix it — attach a Guardrail, scope the invoke role, and turn on model-invocation logging.
IAM privilege escalation
You've found leaked CI/CD credentials for a 'limited' deploy user. Discover how its policy lets it escalate to full admin, prove it by capturing a flag only an admin can read, then remediate so the path is closed.
S3 misconfiguration & data exposure
Find and fix common S3 misconfigurations — public buckets, missing encryption, over-broad IAM — in a realistic mini-account, then verify your fixes.
Storage account public exposure & data leak
Find and fix a leaky Azure Storage account — anonymous blob access, insecure HTTP allowed, and account-key access left on — then verify an anonymous download of the seeded 'secret' file is truly blocked.
Want a lab we don't have yet?
Tell us what to build — your idea shapes what we add next.
Opens WhatsApp with your idea — no account needed.