Security Training Catalogue
Interactive 3D exercises across phishing, GDPR compliance, the EU AI Act, OWASP Top 10 for LLM & Agentic AI, OWASP Privacy Risks, and real-world incident case studies. Free to play, no sign-up required.
Security Awareness
87 exercises · Build a security-first culture with interactive exercises covering phishing, social engineering, device security, and more.
Phishing
Spot a phishing email before you click.
- ATT&CKT1566.002
- CIS 14.2
Ransomware
Survive a ransomware attack in real time.
- ATT&CKT1486
- CIS 10
- NIST CSFPR.PS
Social Engineering
Recognize manipulation before you comply.
- ATT&CKT1598
- CIS 14.2
Vishing
Handle a realistic voice phishing call.
- ATT&CKT1566.004
- CIS 14.2
Whaling With A Deepfake
Spot an AI-generated executive on a video call.
- ATT&CKT1566.004
- CIS 14.2
USB Drop Attack
Think twice before plugging in that USB drive.
- ATT&CKT1091
- CIS 10
- NIST CSFPR.PS
Privacy & Compliance Frameworks
48 exercises · Master GDPR, the EU AI Act, and OWASP privacy risks with hands-on exercises covering data protection, breach response, AI governance, and privacy by design.
Data Breach Response
Report a misdirected-email breach inside the 72-hour clock.
- GDPRArt. 33
- CIS 3
- NIST CSFPR.DS
Cross-Border Data Transfers
Navigate transfer mechanisms for data leaving the EEA.
- GDPRArt. 44
- CIS 3
- NIST CSFPR.DS
Legitimate DSAR Processing
Process a data subject access request end to end.
- GDPRArt. 15
- CIS 3
- NIST CSFPR.DS
Marketing Consent Management
Segment a marketing list by the consent each contact gave.
- GDPRArt. 7
- CIS 3
- NIST CSFPR.DS
PII Document Redaction
Redact personal data from a report before it goes to auditors.
- GDPRArt. 5
- CIS 3
- NIST CSFPR.DS
Data Protection Impact Assessment
Run a DPIA for a high-risk data processing activity.
- GDPRArt. 35
- CIS 3
- NIST CSFPR.DS
AI & LLM Security
43 exercises · Prepare for AI-powered threats including prompt injection, deepfake attacks, and LLM manipulation.
Clawdbot (Moltbot) Prompt Injection
Stop a hidden prompt from hijacking your AI assistant mid-task.
- OWASP LLMLLM01:2026
- CWE-1427
- CIS 16
- NIST CSFPR.PS
AI Knowledge Base Poisoning
Watch poisoned documents corrupt your AI's answers in real time.
- OWASP LLMLLM05:2026
- CIS 16
- NIST CSFPR.PS
Sensitive Data Exposure Through AI
See what happens when confidential data enters a consumer AI tool.
- OWASP LLMLLM02:2026
- CWE-200
- CIS 16
- NIST CSFPR.PS
AI System Prompt Leakage
Extract hidden instructions from a customer-facing AI chatbot.
- OWASP LLMLLM08:2026
- CWE-200
- CIS 16
- NIST CSFPR.PS
AI Agent Goal Hijacking
Spot the moment an AI agent's goal is quietly rewritten.
- OWASPASI01:2026
- CWE-1427
- CIS 16
- NIST CSFPR.PS
Rogue AI Agents
Healthy metrics, clean output, one agent acting on its own.
- OWASPASI10:2026
- CIS 16
- NIST CSFPR.PS
Real-World Incidents
2 exercises · Learn from actual security breaches. Walk through the MGM Resorts attack, BEC fraud cases, and more.
The Developer Track
Application security split by attack surface. Free, hands-on, no sign-up.
-
Application Security
22 exercisesSQL Injection · Stored XSS · Server-Side Request Forgery
-
API Security
10 exercisesBroken Object Level Authorization · Mass Assignment · Excessive Data Exposure
-
Git & Repository Security
8 exercisesSecrets in Git History · Exposed .git Directory · Malicious Pull Requests
-
Cloud Security
17 exercisesPublic Storage Buckets · Over-Permissive IAM · Secrets in Image Layers
See RansomLeak in Action
Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.