Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Compliance Mapping Guide

See exactly which RansomLeak exercises satisfy requirements for SOC 2, ISO 27001, ISO 27701, NIST CSF 2.0, GDPR, EU AI Act, CCPA / CPRA, HIPAA, HITRUST, PCI DSS, NIS2, DORA, and CMMC. Map your training program to compliance controls.

Each table below links specific framework requirements to the courses and exercises that address them, so you can build a training plan that satisfies your auditors. Coverage by OWASP, CWE, MITRE ATT&CK and CIS identifier follows the framework tables.

Compliance mapping matrix showing four frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS) mapped to four exercise categories (Phishing, BEC, Vishing, Data Handling) with checked coverage cells
13
Frameworks
8
Taxonomies
200+
Exercises
Audit-Ready
Reports

How Does RansomLeak Map to SOC 2 Requirements?

SOC 2 Trust Services Criteria require organizations to demonstrate security awareness across their workforce. RansomLeak exercises map directly to Common Criteria controls, giving auditors the evidence they need.

Requirement Area RansomLeak Courses Example Exercises
CC1.4 Security Awareness & Communication Security Policies & Your Role, Phishing & Impersonation Attacks Employee Security Responsibilities, Phishing, Callback Phishing, Business Email Compromise, Social Engineering, Tech Support Scams, Calendar Invite Scams, Deepfake Audio Detection
CC6.1 Logical Access Controls Passwords & Account Security, Cloud Infrastructure Security, Git & Repository Security MFA Setup & Best Practices, MFA Fatigue Attack, Least Privilege Awareness, Privileged Access Basics, Over-Permissive IAM, Long-Lived Access Keys, Serverless Over-Privilege, Branch Protection Bypass, Leaked Access Tokens
CC6.7 System Operations Monitoring Device Security, Web & Browser Safety, Cloud Infrastructure Security, OWASP Top 10 for API Security Endpoint Patching & EDR Alerts, Safe Browsing & Downloads, Browser Notification Abuse, Audit Logging Gaps, Insufficient Logging & Monitoring
CC7.2 Anomaly & Incident Detection Incident Reporting, Workplace Security, Cloud Infrastructure Security, Git & Repository Security General Incident Reporting, Insider Threat (Accidental), CI/CD Secret Exposure, Audit Logging Gaps
CC7.3 Incident Response GDPR Compliance, Incident Reporting Security Incident Response, Reporting Culture
CC9.2 Risk Mitigation Remote & Home Office Security, Safe Communication & Sharing VPN Usage & Safety, Cloud Sharing Controls, Collaboration Tool Hygiene, Secure Online Meetings, Verification Procedures
CC3.2 Risk Identification (AI & Emerging Tech) AI at Work, OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, Protecting Sensitive Information, OWASP MCP Top 10 Prompt Injection in Documents, Shadow AI Tools, AI Agent Payment Fraud, Clawdbot (Moltbot) Prompt Injection, Sensitive Data Exposure Through AI, AI Agent Goal Hijacking, AI Agent Tool Exploitation, Safe GenAI Usage, Poisoned Tool Descriptions, Shadow MCP Servers, Leaked MCP Tokens
CC8.1 Change Management & Secure Development OWASP Top 10 for Web Applications, OWASP Top 10 for API Security, Git & Repository Security SQL Injection, Cross-Site Request Forgery, Components with Known Vulnerabilities, Mass Assignment, Malicious Pull Requests, Branch Protection Bypass, Secrets in Git History, CI/CD Secret Exposure
Read the full SOC 2 compliance guide

How Does RansomLeak Map to ISO 27001 Requirements?

ISO 27001 Annex A controls require documented security awareness programs. RansomLeak provides structured training content and completion tracking that satisfies these controls during certification audits.

Requirement Area RansomLeak Courses Example Exercises
A.6.3 Information Security Awareness Security Policies & Your Role, Phishing & Impersonation Attacks ISMS Policy Awareness, Phishing, Spear Phishing, Double Barrel Phishing, WhatsApp Social Engineering, Audit Mindset Basics, Audit Portal Training, Calendar Invite Scams, Deepfake Audio Detection, Invoice & Payment Fraud
A.5.10 Acceptable Use of Assets Protecting Sensitive Information, Device Security Internet & Email Acceptable Use, USB Drop Attack, File Extension Awareness
A.8.3 Access Restriction Passwords & Account Security, Cloud Infrastructure Security, Git & Repository Security, OWASP Top 10 for API Security MFA Fatigue Attack, Least Privilege Awareness, Joiner-Mover-Leaver Awareness, Over-Permissive IAM, Long-Lived Access Keys, Branch Protection Bypass, Broken Function Level Authorization, Vertical Privilege Escalation
A.5.24 Incident Management Incident Reporting, GDPR Compliance General Incident Reporting, Security Incident Response
A.8.7 Malware Protection Device Security, Web & Browser Safety, Container & Image Security Ransomware, IoT & Smart Device Security, SEO Poisoning Awareness, Browser Extension Safety, HTTPS & Website Security, Image-Based Attacks (Stegosploit), Malicious Base Images, Vulnerable Base Images
A.5.14 Information Transfer Safe Communication & Sharing, Protecting Sensitive Information Secure Messaging Practices, Secure Sharing Practices, Collaboration Tool Hygiene, Metadata Awareness, Log Sensitivity Awareness, Secure Online Meetings
A.5.23 Security for Cloud & AI Services OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, Protecting Sensitive Information, Cloud Infrastructure Security, OWASP MCP Top 10 AI Supply Chain Attack, Agentic AI Supply Chain Attack, Over-Permissioned AI Agent, Agent Identity and Privilege Abuse, Agent-to-Agent Communication Spoofing, AI Denial-of-Service Attack, Safe GenAI Usage, Public Storage Buckets, Multi-Account Boundaries, Instance Metadata Abuse, Cross-Tenant Context Leak
A.8.25 / A.8.28 Secure Development & Coding OWASP Top 10 for Web Applications, OWASP Top 10 for API Security, Git & Repository Security SQL Injection, Stored XSS, Server-Side Request Forgery, XXE Injection, Mass Assignment, Malicious Pull Requests, Commit Author Spoofing
A.8.9 Configuration Management Cloud Infrastructure Security, Container & Image Security, OWASP Top 10 for Web Applications Security Misconfiguration, Public Storage Buckets, Cloud Network Exposure, Privileged Containers, Exposed Docker Daemon, Minimal Container Images, Leftover Debug Code
Read the full ISO 27001 compliance guide

How Does RansomLeak Map to ISO 27701 Requirements?

ISO 27701 extends ISO 27001 with privacy information management controls aligned to GDPR. Annex B covers PII controllers (purpose, lawful basis, consent, data subject rights, transfers) and Annex C covers PII processors (processing under instructions, sub-processors, return and disposal of PII).

Requirement Area RansomLeak Courses Example Exercises
B.7.2 Conditions for Collection & Processing GDPR Compliance, OWASP Top 10 Privacy Risks Privacy by Design Review, Marketing Consent Management, Data Mapping and Records of Processing, Excessive Personal Data Collection, Consent Dark Patterns and Bundled Permissions
B.7.3 Obligations to PII Principals (DSAR) GDPR Compliance, OWASP Top 10 Privacy Risks Legitimate DSAR Processing, Fraudulent DSAR Detection, Blocked Data Subject Access Requests, Personal Data Deletion Failures
B.7.4 Privacy by Design & Default GDPR Compliance, OWASP Top 10 Privacy Risks Privacy by Design Review, Data Protection Impact Assessment, Privacy Breach Through Application Vulnerabilities, Session Hijacking Through Missing Expiration
B.7.5 PII Sharing, Transfer & Disclosure GDPR Compliance, Safe Communication & Sharing, Protecting Sensitive Information, OWASP Top 10 Privacy Risks, Cloud Infrastructure Security Cross-Border Data Transfers, Third-Party Data Processor Vetting, Cloud Sharing Controls, Metadata Awareness, Log Sensitivity Awareness, Internal Data Leakage to Unauthorized Parties, Public Storage Buckets
C.8.5 Customer Obligations & Notification GDPR Compliance, Incident Reporting, OWASP Top 10 Privacy Risks Data Breach Response, General Incident Reporting, Handling a Personal Data Breach
A.6.3 / A.5.10 ISMS Awareness Foundation Security Policies & Your Role, Phishing & Impersonation Attacks Employee Security Responsibilities, Phishing, Internet & Email Acceptable Use
A.5.23 Privacy in AI / Cloud Services AI at Work, OWASP Top 10 for LLM Applications, Protecting Sensitive Information, OWASP MCP Top 10 Unapproved AI Notetakers, Shadow AI Tools, Unreviewed AI Output, Sensitive Data Exposure Through AI, AI Training Data Poisoning, AI System Prompt Leakage, Safe GenAI Usage, Cross-Tenant Context Leak

How Does RansomLeak Map to NIST CSF 2.0?

NIST Cybersecurity Framework 2.0 organizes security around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. The Protect function explicitly mandates a workforce awareness program (PR.AT-1), with adjacent functions requiring competency in detection, response, and recovery.

Function & Category RansomLeak Courses Example Exercises
GV.OC / PR.AT-1 Awareness & Training Security Policies & Your Role, Phishing & Impersonation Attacks, AI at Work Employee Security Responsibilities, ISMS Policy Awareness, Phishing, Whaling With A Deepfake, Business Email Compromise, Social Engineering, Calendar Invite Scams, Deepfake Audio Detection, AI-Written Phishing, AI Voice Phishing Calls
ID.RA Risk Assessment (incl. AI risk) Real-World Incidents, OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, OWASP Top 10 for Web Applications, Container & Image Security MGM Resorts Breach, OneNote Email Attack, Sensitive Data Exposure Through AI, Rogue AI Agents, Components with Known Vulnerabilities, Vulnerable Base Images, OS Updates & Patching Basics
PR.AA Identity Management & Authentication Passwords & Account Security, Cloud Infrastructure Security, Git & Repository Security, OWASP Top 10 for API Security MFA Setup & Best Practices, MFA Fatigue Attack, Password Manager Habits, Privileged Access Basics, Least Privilege Awareness, Joiner-Mover-Leaver Awareness, Account Recovery Security, Guest Access Management, Over-Permissive IAM, Long-Lived Access Keys, Leaked Access Tokens, Broken User Authentication
PR.DS Data Security Protecting Sensitive Information, Safe Communication & Sharing, Git & Repository Security, Cloud Infrastructure Security, Container & Image Security Data Classification Basics, Data Leakage, Identity Theft Prevention, Secure Sharing Practices, Cloud Sharing Controls, Metadata Awareness, Log Sensitivity Awareness, Safe GenAI Usage, Committed Secret Files, Secrets in Git History, Public Storage Buckets, Secrets in Image Layers, Encryption & Lock Discipline
PR.IR Infrastructure Resilience & Backup Device Security, Cloud Infrastructure Security, Container & Image Security Backup Best Practices, Ransomware, Endpoint Patching & EDR Alerts, Cloud Network Exposure, Container Network Exposure, Subdomain Takeover, VPN Usage & Safety
DE.AE / DE.CM Anomaly & Event Detection Web & Browser Safety, Workplace Security, Cloud Infrastructure Security, Git & Repository Security, OWASP Top 10 for API Security SEO Poisoning Awareness, Browser Extension Safety, Insider Threat (Accidental), Shadow IT Awareness, Typosquatting Awareness, CI/CD Secret Exposure, Audit Logging Gaps, Insufficient Logging & Monitoring, File Extension Awareness, USB Drop Attack
RS.MA / RS.CO Incident Response & Communication Incident Reporting, GDPR Compliance General Incident Reporting, Reporting Culture, Data Breach Response, Security Incident Response
PR.PS Platform Security OWASP Top 10 for Web Applications, Container & Image Security, OWASP Top 10 for Agentic Applications, OWASP MCP Top 10 SQL Injection, Command Injection, Components with Known Vulnerabilities, Privileged Containers, Minimal Container Images, AI Agent Code Injection, MCP Command Injection, Unauthenticated MCP Server
ID.AM Asset Management Cloud Infrastructure Security, Container & Image Security, OWASP Top 10 for API Security, Workplace Security Container Registry Exposure, Malicious Base Images, Minimal Container Images, Subdomain Takeover, Vulnerable Base Images, Improper Inventory Management, Shadow MCP Servers, Shadow IT Awareness

How Does RansomLeak Map to GDPR Requirements?

GDPR Articles 39 and 47 require data protection training for employees who process personal data. RansomLeak offers a dedicated GDPR Compliance course with exercises that cover breach response, data subject rights, and privacy by design.

Requirement Area RansomLeak Courses Example Exercises
Art. 35 / 39 DPIA & DPO Awareness Training GDPR Compliance, EU AI Act Compliance Data Mapping and Records of Processing, Data Protection Impact Assessment, AI and Data Protection, Fundamental Rights Impact Assessment
Art. 33-34 Breach Notification GDPR Compliance, Incident Reporting, OWASP Top 10 Privacy Risks Data Breach Response, Handling a Personal Data Breach, General Incident Reporting, Breach Response Tabletop, Everyday Privacy Duties, Security Incident Response
Art. 25 Privacy by Design GDPR Compliance, OWASP Top 10 Privacy Risks Privacy by Design Review, Cookie Consent Management, Privacy Breach Through Application Vulnerabilities, Session Hijacking Through Missing Expiration
Art. 15-22 Data Subject Rights GDPR Compliance, OWASP Top 10 Privacy Risks Legitimate DSAR Processing, Fraudulent DSAR Detection, Blocked Data Subject Access Requests, Personal Data Deletion Failures
Art. 28 Processor Obligations GDPR Compliance, AI at Work Third-Party Data Processor Vetting, Shadow AI Tools, Unapproved AI Notetakers
Art. 44-49 International Transfers GDPR Compliance Cross-Border Data Transfers
Art. 5 Data Principles GDPR Compliance, Protecting Sensitive Information, OWASP Top 10 Privacy Risks, EU AI Act Compliance Data Retention Compliance, Data Classification Basics, PII Document Redaction, Metadata Awareness, Log Sensitivity Awareness, Excessive Personal Data Collection, Outdated and Inaccurate Personal Data, Opaque Privacy Policies and Hidden Data Practices, AI Data Governance, Employee Data Collection, Everyday Privacy Duties, Principles and Legal Bases
Art. 22 Automated Decision-Making & AI Profiling OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, Protecting Sensitive Information, OWASP Top 10 Privacy Risks Sensitive Data Exposure Through AI, AI Training Data Poisoning, AI Agent Memory Poisoning, Safe GenAI Usage, Consent Dark Patterns and Bundled Permissions
Art. 6-7 Lawful Basis & Consent GDPR Compliance, OWASP Top 10 Privacy Risks Principles and Legal Bases, Cookie Consent Management, Marketing Consent Management, Consent Dark Patterns and Bundled Permissions
Art. 9 Special Categories of Personal Data GDPR Compliance, Protecting Sensitive Information Employee Data Collection, Personal Data Essentials, Data Classification Basics
Read the full GDPR compliance guide

How Does RansomLeak Map to EU AI Act Requirements?

The EU AI Act establishes legally binding obligations for organizations that develop, deploy, or use AI systems in the European Union. Articles 4, 14, 26, 27, 50, and 62 explicitly mandate workforce training, AI literacy, and competency in human oversight. RansomLeak ships a dedicated EU AI Act Compliance course with 16 interactive exercises that map article-by-article to the regulation.

Requirement Area RansomLeak Courses Example Exercises
Art. 4 AI Literacy Requirement EU AI Act Compliance, AI at Work, OWASP Top 10 for LLM Applications AI Literacy Essentials, Using AI Tools Responsibly at Work, Shadow AI Tools, Unreviewed AI Output, Prompt Injection in Documents, AI Agent Payment Fraud, Sensitive Data Exposure Through AI, Safe GenAI Usage
Art. 5 Prohibited AI Practices EU AI Act Compliance Prohibited AI Practices, AI Risk Classification
Art. 10 Data Governance (High-Risk AI) EU AI Act Compliance, GDPR Compliance AI Data Governance, Data Mapping and Records of Processing, Bias and Discrimination in AI
Art. 14 Human Oversight EU AI Act Compliance Meaningful Human Oversight, High-Risk AI: Deployer Obligations
Art. 16 / 26 Provider & Deployer Obligations EU AI Act Compliance High-Risk AI: Deployer Obligations, Provider vs. Deployer: Who's Responsible?, AI Governance in Your Organization
Art. 27 Fundamental Rights Impact Assessment EU AI Act Compliance, GDPR Compliance Fundamental Rights Impact Assessment, AI and Data Protection, Bias and Discrimination in AI
Art. 50 Transparency & Disclosure EU AI Act Compliance, AI at Work AI Transparency and Disclosure, Using AI Tools Responsibly at Work, AI Support Chatbot Scam, AI Voice Phishing Calls, Cloned Voice Payment Fraud, Deepfake Hiring Fraud
Art. 51-56 General-Purpose AI Models EU AI Act Compliance, OWASP Top 10 for LLM Applications General-Purpose AI Model Obligations, AI Supply Chain Attack, AI System Prompt Leakage
Art. 62 Serious Incident Reporting EU AI Act Compliance, Incident Reporting, GDPR Compliance AI Incident Reporting, General Incident Reporting, Reporting Culture
Art. 99 Penalties & Personal Liability EU AI Act Compliance, Security Policies & Your Role EU AI Act Penalties and Enforcement, AI Governance in Your Organization, Employee Security Responsibilities
Read the full EU AI Act compliance guide

How Does RansomLeak Map to CCPA / CPRA Requirements?

The California Consumer Privacy Act and its successor the California Privacy Rights Act grant California residents specific rights over their personal information. Businesses must train staff on identifying valid requests, opt-out workflows, sensitive PI handling, and breach response under §1798.150.

How Does RansomLeak Map to HIPAA Requirements?

HIPAA Security and Privacy Rules mandate workforce training on safeguarding protected health information. RansomLeak exercises address the specific administrative, physical, and technical safeguards outlined in 45 CFR Part 164.

Requirement Area RansomLeak Courses Example Exercises
§164.308(a)(5) Security Awareness Security Policies & Your Role, Phishing & Impersonation Attacks Employee Security Responsibilities, Phishing, Callback Phishing, Double Barrel Phishing, Whaling With A Deepfake, Social Engineering, Tech Support Scams, Calendar Invite Scams, Deepfake Audio Detection, Invoice & Payment Fraud
§164.530(b) Privacy Training Protecting Sensitive Information, GDPR Compliance Data Classification Basics, PII Document Redaction, Identity Theft Prevention, Metadata Awareness, Log Sensitivity Awareness
§164.308(a)(6) Incident Procedures Incident Reporting, GDPR Compliance General Incident Reporting, Security Incident Response
§164.312(d) Authentication Passwords & Account Security MFA Setup & Best Practices, MFA Fatigue Attack, Password Manager Habits
§164.310(b) Workstation Security Device Security, Workplace Security Encryption & Lock Discipline, Mobile Device Security, Mobile App Permissions
§164.308(a)(3) Workforce Security Workplace Security Insider Threat (Accidental), Insider Threat (Intentional), Joiner-Mover-Leaver Awareness
§164.308(a)(1)(ii)(B) Risk Analysis (AI Tools) OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, Protecting Sensitive Information, OWASP MCP Top 10 Sensitive Data Exposure Through AI, AI Hallucination and Misinformation, Over-Permissioned AI Agent, Safe GenAI Usage, Cross-Tenant Context Leak, Shadow MCP Servers
§164.312(a)(1) Access Control (Cloud & Repositories) Cloud Infrastructure Security, Git & Repository Security Over-Permissive IAM, Long-Lived Access Keys, Public Storage Buckets, Committed Secret Files, Leaked Access Tokens
Read the full HIPAA compliance guide

How Does RansomLeak Map to HITRUST CSF Requirements?

HITRUST CSF is the dominant framework for healthcare and high-trust environments, harmonizing HIPAA, NIST, ISO 27001, and PCI DSS into a single certifiable control set. Workforce awareness and training requirements appear across multiple control categories from Information Security Management to Privacy Practices.

Control Category RansomLeak Courses Example Exercises
01 Information Security Management Program Security Policies & Your Role Employee Security Responsibilities, ISMS Policy Awareness, Internet & Email Acceptable Use, Audit Mindset Basics, Audit Portal Training
07 Vulnerability Management Device Security, Web & Browser Safety, OWASP Top 10 for Web Applications, Container & Image Security Endpoint Patching & EDR Alerts, OS Updates & Patching Basics, Browser Extension Safety, HTTPS & Website Security, Image-Based Attacks (Stegosploit), Components with Known Vulnerabilities, Vulnerable Base Images, Malicious Base Images
08 Access Control Passwords & Account Security MFA Setup & Best Practices, Least Privilege Awareness, Joiner-Mover-Leaver Awareness, Privileged Access Basics
09 Communications & Operations Safe Communication & Sharing, Protecting Sensitive Information, Cloud Infrastructure Security Secure Sharing Practices, Cloud Sharing Controls, Data Classification Basics, Metadata Awareness, Log Sensitivity Awareness, Secure Online Meetings, Public Storage Buckets, Cloud Network Exposure, Audit Logging Gaps
11 Information Security Incident Management Incident Reporting, GDPR Compliance General Incident Reporting, Reporting Culture, Data Breach Response
12 Business Continuity & Disaster Recovery Device Security Backup Best Practices, Ransomware
15 Privacy Practices GDPR Compliance, Protecting Sensitive Information PII Document Redaction, Privacy by Design Review, Data Classification Basics, Excessive Personal Data Collection, Outdated and Inaccurate Personal Data, Opaque Privacy Policies and Hidden Data Practices, Safe GenAI Usage

How Does RansomLeak Map to NIS2 Requirements?

The NIS2 Directive requires essential and important entities across the EU to implement cybersecurity training and hygiene practices. Article 21 specifically mandates human resources security and awareness programs.

Requirement Area RansomLeak Courses Example Exercises
Art. 21(2)(g) Cyber Hygiene & Training Security Policies & Your Role, Phishing & Impersonation Attacks, Device Security Employee Security Responsibilities, Phishing, Callback Phishing, Whaling With A Deepfake, Business Email Compromise, Vishing, Mobile Device Security, Browser Autofill Risks, Calendar Invite Scams, Deepfake Audio Detection, Mobile App Permissions
Art. 21(2)(b) Incident Handling Incident Reporting, GDPR Compliance, OWASP Top 10 Privacy Risks General Incident Reporting, Reporting Culture, Handling a Personal Data Breach
Art. 21(2)(d) Supply Chain Security Safe Communication & Sharing, Phishing & Impersonation Attacks Third-Party App OAuth Risks, Guest Access Management, Verification Procedures, Invoice & Payment Fraud
Art. 21(2)(i) Human Resources Security Workplace Security, Passwords & Account Security Joiner-Mover-Leaver Awareness, Insider Threat (Intentional)
Art. 21(2)(j) Cryptography & Encryption Device Security, Git & Repository Security, Container & Image Security Encryption & Lock Discipline, VPN Usage & Safety, Safe Bluetooth Practices, IoT & Smart Device Security, Secrets in Git History, Secrets in Image Layers
Art. 21(2)(e) ICT Acquisition & Development (AI Systems) OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, OWASP Top 10 for Web Applications, Git & Repository Security, OWASP MCP Top 10 AI Agent Code Injection, Unsafe AI Output Handling, Agentic AI Supply Chain Attack, AI Denial-of-Service Attack, Agent-to-Agent Communication Spoofing, SQL Injection, Server-Side Request Forgery, Components with Known Vulnerabilities, Malicious Pull Requests, CI/CD Secret Exposure, Typosquatted MCP Package
Read the full NIS2 compliance guide

How Does RansomLeak Map to PCI DSS Requirements?

PCI DSS v4.0 Requirement 12.6 mandates a formal security awareness program for all personnel. RansomLeak training satisfies this requirement with documented completion records and threat-specific content updates.

Requirement Area RansomLeak Courses Example Exercises
12.6 Security Awareness Program Security Policies & Your Role Employee Security Responsibilities, ISMS Policy Awareness
12.6.3 Threat Awareness Updates Phishing & Impersonation Attacks, AI & LLM Security, Device Security Phishing, Callback Phishing, Double Barrel Phishing, Whaling With A Deepfake, Business Email Compromise, Smishing, QR Code Phishing (Quishing), Typosquatting Awareness, Mobile Device Security, Clawdbot (Moltbot) Prompt Injection, Calendar Invite Scams, Deepfake Audio Detection, Invoice & Payment Fraud
9.4 Media Protection Protecting Sensitive Information, Device Security PII Document Redaction, USB Drop Attack
8.3 Authentication Management Passwords & Account Security MFA Setup & Best Practices, MFA Fatigue Attack, Credential Stuffing Awareness
12.10 Incident Response Incident Reporting General Incident Reporting, Reporting Culture
6.2 Secure Software Development (AI Systems) OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, OWASP Top 10 for Web Applications, OWASP Top 10 for API Security Unsafe AI Output Handling, AI Agent Code Injection, RAG Pipeline Exploitation, SQL Injection, Stored XSS, Server-Side Request Forgery, XXE Injection, Mass Assignment, Components with Known Vulnerabilities
3.x Protection of Stored Account Data Cloud Infrastructure Security, Git & Repository Security, Container & Image Security Public Storage Buckets, Secrets in Git History, Committed Secret Files, Secrets in Image Layers, PII in URL, Token Exposure in URL
10.2 Audit Logs Cloud Infrastructure Security, OWASP Top 10 for API Security, OWASP MCP Top 10 Audit Logging Gaps, Insufficient Logging & Monitoring, Missing MCP Audit Trail
Read the full PCI DSS compliance guide

How Does RansomLeak Map to DORA Requirements?

The Digital Operational Resilience Act (DORA) requires financial entities to implement ICT security awareness programs and test their operational resilience. RansomLeak delivers training that addresses Articles 13, 17, 25, and 28.

Requirement Area RansomLeak Courses Example Exercises
Art. 13.6 ICT Security Awareness Security Policies & Your Role, Device Security Employee Security Responsibilities, Callback Phishing, Whaling With A Deepfake, Endpoint Patching & EDR Alerts, Mobile Device Security, IoT & Smart Device Security, Browser Notification Abuse, Mobile App Permissions
Art. 17 ICT Incident Reporting Incident Reporting, GDPR Compliance, OWASP Top 10 Privacy Risks General Incident Reporting, Security Incident Response, Handling a Personal Data Breach
Art. 28 Third-Party ICT Risk Safe Communication & Sharing, Phishing & Impersonation Attacks Third-Party App OAuth Risks, Cloud Sharing Controls, Verification Procedures, Invoice & Payment Fraud
Art. 25 ICT Testing Requirements Real-World Incidents MGM Resorts Breach, OneNote Email Attack, General Incident Reporting
Art. 11 Communication & Resilience Remote & Home Office Security VPN Usage & Safety, Home Router Security
Art. 16 ICT Risk Management (AI & Agentic Systems) OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, Protecting Sensitive Information, OWASP MCP Top 10 AI Agent Goal Hijacking, Multi-Agent Cascading Failure, Rogue AI Agents, Over-Trusting AI Agent Recommendations, AI Denial-of-Service Attack, Agent-to-Agent Communication Spoofing, Safe GenAI Usage, Shadow MCP Servers, Unauthenticated MCP Server
Art. 9 ICT Protection & Prevention Cloud Infrastructure Security, Container & Image Security, OWASP Top 10 for Web Applications Over-Permissive IAM, Public Storage Buckets, Cloud Network Exposure, Privileged Containers, Security Misconfiguration, Components with Known Vulnerabilities

How Does RansomLeak Map to CMMC Level 1 Requirements?

CMMC Level 1 (Foundational) implements the 17 basic safeguarding requirements of FAR 52.204-21 for U.S. defense contractors handling Federal Contract Information. While many requirements are technical, several mandate workforce awareness around access control, identification, media handling, physical security, and malicious-code protection.

Practice RansomLeak Courses Example Exercises
AC.L1-3.1.1 Limit System Access Passwords & Account Security, Cloud Infrastructure Security, Git & Repository Security Least Privilege Awareness, Privileged Access Basics, Account Recovery Security, Over-Permissive IAM, Long-Lived Access Keys, Branch Protection Bypass
AC.L1-3.1.20 / 3.1.22 External Connections & Public Systems Web & Browser Safety, Safe Communication & Sharing Safe Browsing & Downloads, Social Media Oversharing, Social Media Policy
IA.L1-3.5.1 / 3.5.2 Identify & Authenticate Users Passwords & Account Security MFA Setup & Best Practices, MFA Fatigue Attack, Password Manager Habits
MP.L1-3.8.3 Media Sanitization & Protection Device Security, Protecting Sensitive Information, Cloud Infrastructure Security, Git & Repository Security USB Drop Attack, Data Classification Basics, Metadata Awareness, Log Sensitivity Awareness, Public Storage Buckets, Committed Secret Files
PE.L1-3.10.1 / 3.10.3 Physical Access & Visitor Control Workplace Security Insider Threat (Accidental), Insider Threat (Intentional), Shadow IT Awareness
SI.L1-3.14.1 / 3.14.2 Identify Malicious Code Phishing & Impersonation Attacks, Device Security, Web & Browser Safety, OWASP Top 10 for Web Applications, Container & Image Security Phishing, Callback Phishing, Tech Support Scams, Ransomware, Image-Based Attacks (Stegosploit), Components with Known Vulnerabilities, Malicious Base Images
SI.L1-3.14.5 Periodic Scans & Updates Device Security OS Updates & Patching Basics, Endpoint Patching & EDR Alerts

Coverage by Security Taxonomy

The tables above answer an auditor asking which control a course satisfies. The tables below answer a security team asking which specific risk an exercise teaches. Every identifier is read from the catalogue itself, so a content release keeps them current instead of leaving them stale.

Which OWASP Top 10 Web Risks Does RansomLeak Cover?

The Application Security course drills each web risk as an exploitable scenario rather than a definition. Both the 2021 and 2025 lists appear, because most audit programmes still reference 2021 while newer work cites 2025.

Identifier What it covers Exercises
OWASP A01:2021 Broken Access Control Cross-Site Request Forgery, Directory Traversal, Forced Browsing, Horizontal Privilege Escalation, Insecure URL Redirect, Vertical Privilege Escalation
OWASP A01:2025 Broken Access Control Cross-Site Request Forgery, Directory Traversal, Forced Browsing, Horizontal Privilege Escalation, Insecure URL Redirect, Server-Side Request Forgery, Vertical Privilege Escalation
OWASP A02:2021 Cryptographic Failures PII in URL, Weak Randomness
OWASP A02:2025 Security Misconfiguration Clickjacking, Host Header Injection, Leftover Debug Code, XXE Injection
OWASP A03:2021 Injection Command Injection, DOM XSS, Reflected XSS, SQL Injection, Stored XSS
OWASP A03:2025 Software Supply Chain Failures Components with Known Vulnerabilities
OWASP A04:2025 Cryptographic Failures PII in URL, Weak Randomness
OWASP A05:2021 Security Misconfiguration Clickjacking, Host Header Injection, Leftover Debug Code, XXE Injection
OWASP A05:2025 Injection Command Injection, DOM XSS, Reflected XSS, SQL Injection, Stored XSS
OWASP A06:2021 Vulnerable and Outdated Components Components with Known Vulnerabilities
OWASP A07:2021 Identification and Authentication Failures Session Fixation, Token Exposure in URL, User Enumeration
OWASP A07:2025 Authentication Failures Session Fixation, Token Exposure in URL, User Enumeration
OWASP A09:2021 Security Logging and Monitoring Failures PII in URL, Token Exposure in URL
OWASP A09:2025 Security Logging and Alerting Failures PII in URL, Token Exposure in URL
OWASP A10:2021 Server-Side Request Forgery (SSRF) Server-Side Request Forgery

Which OWASP API Security Top 10 Risks Does RansomLeak Cover?

API failures are usually authorization logic rather than input handling, so these exercises put the learner on the endpoint that trusts its client. Coverage spans the 2019 and 2023 editions.

Identifier What it covers Exercises
OWASP API API1:2023 Broken Object Level Authorization Broken Object Level Authorization
OWASP API API2:2023 Broken Authentication Broken User Authentication
OWASP API API3:2019 Excessive Data Exposure Excessive Data Exposure
OWASP API API4:2023 Unrestricted Resource Consumption Unrestricted Resource Consumption
OWASP API API5:2023 Broken Function Level Authorization Broken Function Level Authorization
OWASP API API6:2019 Mass Assignment Mass Assignment
OWASP API API8:2019 Injection Injection
OWASP API API8:2023 Security Misconfiguration Security Misconfiguration
OWASP API API9:2023 Improper Inventory Management Improper Inventory Management
OWASP API API10:2019 Insufficient Logging & Monitoring Insufficient Logging & Monitoring

Which OWASP Top 10 LLM Risks Does RansomLeak Cover?

Prompt injection, sensitive data exposure and supply chain risk in language model applications. The 2025 and 2026 lists are both mapped, since procurement questionnaires still cite either one.

Identifier What it covers Exercises
OWASP LLM LLM01:2025 Prompt Injection Clawdbot (Moltbot) Prompt Injection
OWASP LLM LLM01:2026 Prompt Injection Clawdbot (Moltbot) Prompt Injection, Prompt Injection in Documents, AI Agent Payment Fraud
OWASP LLM LLM02:2025 Sensitive Information Disclosure Safe GenAI Usage, Sensitive Data Exposure Through AI
OWASP LLM LLM02:2026 Sensitive Information Disclosure Sensitive Data Exposure Through AI, Unreviewed AI Output
OWASP LLM LLM03:2025 Supply Chain AI Supply Chain Attack
OWASP LLM LLM03:2026 Excessive Agency Over-Permissioned AI Agent, AI Agent Payment Fraud
OWASP LLM LLM04:2025 Data and Model Poisoning AI Training Data Poisoning
OWASP LLM LLM04:2026 Supply Chain AI Supply Chain Attack
OWASP LLM LLM05:2025 Improper Output Handling Unsafe AI Output Handling
OWASP LLM LLM05:2026 Data and Model Poisoning AI Training Data Poisoning
OWASP LLM LLM06:2025 Excessive Agency Over-Permissioned AI Agent
OWASP LLM LLM06:2026 Unbounded Consumption AI Denial-of-Service Attack
OWASP LLM LLM07:2025 System Prompt Leakage AI System Prompt Leakage
OWASP LLM LLM07:2026 Misinformation AI Hallucination and Misinformation
OWASP LLM LLM08:2025 Vector and Embedding Weaknesses RAG Pipeline Exploitation
OWASP LLM LLM08:2026 Hidden Context Exposure AI System Prompt Leakage
OWASP LLM LLM09:2025 Misinformation AI Hallucination and Misinformation
OWASP LLM LLM09:2026 Vector and Embedding Weaknesses RAG Pipeline Exploitation
OWASP LLM LLM10:2025 Unbounded Consumption AI Denial-of-Service Attack
OWASP LLM LLM10:2026 Improper Output Handling Unsafe AI Output Handling

Which OWASP Agentic Top 10 Risks Does RansomLeak Cover?

Agentic risks are behavioural rather than syntactic: an agent holding the right permissions does the wrong thing. Each exercise puts the learner inside the loop where that decision gets made.

Identifier What it covers Exercises
OWASP ASI01:2026 Agent Goal Hijack AI Agent Goal Hijacking
OWASP ASI02:2026 Tool Misuse & Exploitation AI Agent Tool Exploitation
OWASP ASI03:2026 Identity & Privilege Abuse Agent Identity and Privilege Abuse
OWASP ASI04:2026 Agentic Supply Chain Vulnerabilities Agentic AI Supply Chain Attack
OWASP ASI05:2026 Unexpected Code Execution (RCE) AI Agent Code Injection
OWASP ASI06:2026 Memory & Context Poisoning AI Agent Memory Poisoning
OWASP ASI07:2026 Insecure Inter-Agent Communication Agent-to-Agent Communication Spoofing
OWASP ASI08:2026 Cascading Failures Multi-Agent Cascading Failure
OWASP ASI09:2026 Human-Agent Trust Exploitation Over-Trusting AI Agent Recommendations
OWASP ASI10:2026 Rogue Agents Rogue AI Agents

Which OWASP MCP Top 10 Risks Does RansomLeak Cover?

The Model Context Protocol course covers tool poisoning, token exposure and scope creep across a full agent toolchain. It is the newest list in the catalogue and maps one exercise to each risk.

Identifier What it covers Exercises
OWASP MCP MCP01:2025 Token Mismanagement & Secret Exposure Leaked MCP Tokens
OWASP MCP MCP02:2025 Privilege Escalation via Scope Creep Agent Scope Creep
OWASP MCP MCP03:2025 Tool Poisoning Poisoned Tool Descriptions
OWASP MCP MCP04:2025 Supply Chain & Dependency Tampering Typosquatted MCP Package
OWASP MCP MCP05:2025 Command Injection & Execution MCP Command Injection
OWASP MCP MCP06:2025 Intent Flow Subversion Hijacked Agent Intent
OWASP MCP MCP07:2025 Insufficient AuthN/AuthZ Unauthenticated MCP Server
OWASP MCP MCP08:2025 Lack of Audit & Telemetry Missing MCP Audit Trail
OWASP MCP MCP09:2025 Shadow MCP Servers Shadow MCP Servers
OWASP MCP MCP10:2025 Context Injection & Over-Sharing Cross-Tenant Context Leak

Which MITRE CWE Weaknesses Does RansomLeak Cover?

A CWE identifier pins an exercise to the exact weakness it teaches, which is what a secure development policy or a customer security questionnaire usually asks for. Coverage spans the application, API, cloud and repository tracks.

Identifier What it covers Exercises
CWE-22 Improper Limitation of a Pathname to a Restricted Directory Directory Traversal
CWE-74 Improper Neutralization of Special Elements in Output ('Injection') Injection
CWE-78 Improper Neutralization of Special Elements used in an OS Command Command Injection, MCP Command Injection
CWE-79 Improper Neutralization of Input During Web Page Generation DOM XSS, Reflected XSS, Stored XSS
CWE-89 Improper Neutralization of Special Elements used in an SQL Command SQL Injection, Unsafe AI Output Handling
CWE-94 Improper Control of Generation of Code ('Code Injection') AI Agent Code Injection
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor Data Leakage, Sensitive Data Exposure Through AI, AI System Prompt Leakage, Cross-Tenant Context Leak, Secure Document Disposal, Unattended Printouts, Excessive Data Exposure, Printer Admin Security
CWE-204 Observable Response Discrepancy User Enumeration
CWE-208 Observable Timing Discrepancy User Enumeration
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer Metadata Awareness
CWE-213 Exposure of Sensitive Information Due to Incompatible Policies Excessive Data Exposure
CWE-215 Insertion of Sensitive Information Into Debugging Code Leftover Debug Code
CWE-223 Omission of Security-relevant Information Audit Logging Gaps, Insufficient Logging & Monitoring, Missing MCP Audit Trail
CWE-250 Execution with Unnecessary Privileges AI Agent Tool Exploitation, Over-Permissioned AI Agent, Privileged Containers, Serverless Over-Privilege, Agent Identity and Privilege Abuse, Agent Scope Creep, Over-Permissive IAM
CWE-269 Improper Privilege Management Agent Identity and Privilege Abuse, Agent Scope Creep, Over-Permissive IAM, Vertical Privilege Escalation, Multi-Account Boundaries, Privileged Containers
CWE-284 Improper Access Control Cloud Network Exposure, Exposed Docker Daemon, Unauthenticated MCP Server
CWE-285 Improper Authorization Branch Protection Bypass, Broken Function Level Authorization
CWE-287 Improper Authentication Broken User Authentication
CWE-306 Missing Authentication for Critical Function Container Registry Exposure, Exposed Docker Daemon, Unauthenticated MCP Server, Container Network Exposure
CWE-307 Improper Restriction of Excessive Authentication Attempts Broken User Authentication
CWE-324 Use of a Key Past its Expiration Date Long-Lived Access Keys
CWE-330 Use of Insufficiently Random Values Weak Randomness
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Weak Randomness
CWE-345 Insufficient Verification of Data Authenticity Agent-to-Agent Communication Spoofing, Commit Author Spoofing, Malicious Base Images, Malicious Pull Requests, Typosquatted MCP Package, Poisoned Tool Descriptions, Vertical Privilege Escalation
CWE-347 Improper Verification of Cryptographic Signature Agent-to-Agent Communication Spoofing, Commit Author Spoofing
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data AI Agent Memory Poisoning
CWE-352 Cross-Site Request Forgery (CSRF) Cross-Site Request Forgery
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor Sensitive Data Exposure Through AI
CWE-384 Session Fixation Session Fixation
CWE-400 Uncontrolled Resource Consumption Unrestricted Resource Consumption
CWE-425 Direct Request ('Forced Browsing') Forced Browsing
CWE-488 Exposure of Data Element to Wrong Session Cross-Tenant Context Leak
CWE-489 Active Debug Code Leftover Debug Code
CWE-494 Download of Code Without Integrity Check Malicious Base Images, Malicious Pull Requests, Typosquatted MCP Package, Agentic AI Supply Chain Attack
CWE-522 Insufficiently Protected Credentials Clean Desk Basics, Collaboration Tool Hygiene, Leaked Access Tokens, Leaked MCP Tokens, Committed Secret Files, Instance Metadata Abuse, Long-Lived Access Keys, Secrets in Git History, Secrets in Image Layers, Serverless Over-Privilege
CWE-527 Exposure of Version-Control Repository to an Unauthorized Sphere Exposed .git Directory
CWE-532 Insertion of Sensitive Information into Log File CI/CD Secret Exposure, Log Sensitivity Awareness, PII in URL, Token Exposure in URL
CWE-540 Inclusion of Sensitive Information in Source Code Committed Secret Files, Secrets in Git History, Secrets in Image Layers, CI/CD Secret Exposure, AI System Prompt Leakage, Leaked MCP Tokens
CWE-548 Exposure of Information Through Directory Listing Exposed .git Directory
CWE-598 Use of GET Request Method With Sensitive Query Strings PII in URL, Token Exposure in URL
CWE-601 URL Redirection to Untrusted Site ('Open Redirect') Insecure URL Redirect
CWE-611 Improper Restriction of XML External Entity Reference XXE Injection
CWE-613 Insufficient Session Expiration Session Fixation
CWE-639 Authorization Bypass Through User-Controlled Key Broken Object Level Authorization, Horizontal Privilege Escalation
CWE-640 Weak Password Recovery Mechanism for Forgotten Password Host Header Injection
CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax Host Header Injection
CWE-668 Exposure of Resource to Wrong Sphere Cloud Network Exposure, Container Network Exposure, Cloud Sharing Controls, Public Storage Buckets, Secure Sharing Practices
CWE-672 Operation on a Resource after Expiration or Release Subdomain Takeover
CWE-732 Incorrect Permission Assignment for Critical Resource Cloud Sharing Controls, Public Storage Buckets, Secure Sharing Practices, Container Registry Exposure
CWE-770 Allocation of Resources Without Limits or Throttling AI Denial-of-Service Attack, Unrestricted Resource Consumption
CWE-778 Insufficient Logging Audit Logging Gaps, Insufficient Logging & Monitoring, Missing MCP Audit Trail
CWE-798 Use of Hard-coded Credentials Long-Lived Access Keys, Leaked Access Tokens
CWE-807 Reliance on Untrusted Inputs in a Security Decision AI Agent Goal Hijacking, Over-Trusting AI Agent Recommendations, Clawdbot (Moltbot) Prompt Injection, Hijacked Agent Intent
CWE-862 Missing Authorization Branch Protection Bypass, Broken Function Level Authorization, Broken Object Level Authorization, Forced Browsing, Horizontal Privilege Escalation
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes Mass Assignment
CWE-918 Server-Side Request Forgery (SSRF) Instance Metadata Abuse, Server-Side Request Forgery, XXE Injection
CWE-942 Permissive Cross-domain Policy with Untrusted Domains Security Misconfiguration
CWE-1021 Improper Restriction of Rendered UI Layers or Frames Clickjacking
CWE-1059 Insufficient Technical Documentation Improper Inventory Management, Shadow MCP Servers
CWE-1104 Use of Unmaintained Third Party Components Agentic AI Supply Chain Attack, Components with Known Vulnerabilities, AI Supply Chain Attack, Vulnerable Base Images
CWE-1188 Initialization of a Resource with an Insecure Default Minimal Container Images, Multi-Account Boundaries, Security Misconfiguration
CWE-1275 Sensitive Cookie with Improper SameSite Attribute Cross-Site Request Forgery
CWE-1392 Use of Default Credentials Home Router Security, IoT & Smart Device Security, Printer Admin Security
CWE-1395 Dependency on Vulnerable Third-Party Component Components with Known Vulnerabilities, AI Supply Chain Attack, Vulnerable Base Images
CWE-1426 Improper Validation of Generative AI Output Over-Trusting AI Agent Recommendations, Unsafe AI Output Handling
CWE-1427 Improper Neutralization of Input Used for LLM Prompting AI Agent Goal Hijacking, AI Agent Memory Poisoning, Clawdbot (Moltbot) Prompt Injection, Prompt Injection in Documents, Hijacked Agent Intent, Poisoned Tool Descriptions, AI Agent Payment Fraud, AI Agent Code Injection

Which MITRE ATT&CK Techniques Does RansomLeak Cover?

ATT&CK maps training to attacker behaviour rather than to code defects, so a detection team can line up awareness coverage against the techniques it already tracks. Sub-techniques are listed separately where the catalogue teaches them separately.

Identifier What it covers Exercises
ATT&CK T1005 Data from Local System Printer Admin Security
ATT&CK T1011 Exfiltration Over Other Network Medium Safe Bluetooth Practices
ATT&CK T1027.003 Obfuscated Files or Information: Steganography Image-Based Attacks (Stegosploit)
ATT&CK T1036 Masquerading Commit Author Spoofing, Typosquatting Awareness
ATT&CK T1036.007 Masquerading: Double File Extension File Extension Awareness
ATT&CK T1046 Network Service Discovery Cloud Network Exposure, Container Network Exposure, Printer Admin Security
ATT&CK T1052 Exfiltration Over Physical Medium Insider Threat (Intentional)
ATT&CK T1068 Exploitation for Privilege Escalation Endpoint Patching & EDR Alerts
ATT&CK T1078 Valid Accounts Guest Access Management, Joiner-Mover-Leaver Awareness, Least Privilege Awareness, Privileged Access Basics, Insider Threat (Intentional), Leaked Access Tokens, MGM Resorts Breach
ATT&CK T1078.001 Valid Accounts: Default Accounts Home Router Security, IoT & Smart Device Security, Printer Admin Security
ATT&CK T1078.004 Valid Accounts: Cloud Accounts Multi-Account Boundaries, Long-Lived Access Keys, Serverless Over-Privilege
ATT&CK T1091 Replication Through Removable Media USB Drop Attack
ATT&CK T1098.003 Account Manipulation: Additional Cloud Roles Over-Permissive IAM
ATT&CK T1098.005 Account Manipulation: Device Registration Account Recovery Security
ATT&CK T1110.004 Brute Force: Credential Stuffing Credential Stuffing Awareness
ATT&CK T1111 Multi-Factor Authentication Interception AI Support Chatbot Scam, AI Voice Phishing Calls
ATT&CK T1114 Email Collection OneNote Email Attack
ATT&CK T1133 External Remote Services VPN Usage & Safety, Cloud Network Exposure, Exposed Docker Daemon
ATT&CK T1176 Browser Extensions Browser Extension Safety
ATT&CK T1189 Drive-by Compromise Safe Browsing & Downloads
ATT&CK T1190 Exploit Public-Facing Application OS Updates & Patching Basics, Vulnerable Base Images
ATT&CK T1195.002 Supply Chain Compromise: Compromise Software Supply Chain Branch Protection Bypass, Malicious Base Images, Malicious Pull Requests
ATT&CK T1199 Trusted Relationship Multi-Account Boundaries
ATT&CK T1200 Hardware Additions USB Drop Attack
ATT&CK T1204.001 User Execution: Malicious Link Browser Notification Abuse
ATT&CK T1204.002 User Execution: Malicious File OneNote Email Attack, Safe Browsing & Downloads
ATT&CK T1210 Exploitation of Remote Services Container Network Exposure
ATT&CK T1213.003 Data from Information Repositories: Code Repositories Exposed .git Directory, Secrets in Git History
ATT&CK T1476 Deliver Malicious App via Other Means (Mobile) Mobile Device Security
ATT&CK T1486 Data Encrypted for Impact Ransomware, MGM Resorts Breach
ATT&CK T1490 Inhibit System Recovery Backup Best Practices
ATT&CK T1496 Resource Hijacking Audit Logging Gaps
ATT&CK T1525 Implant Internal Image Container Registry Exposure
ATT&CK T1528 Steal Application Access Token Third-Party App OAuth Risks
ATT&CK T1530 Data from Cloud Storage Cloud Sharing Controls, Encryption & Lock Discipline, Public Storage Buckets
ATT&CK T1534 Internal Spearphishing Business Email Compromise
ATT&CK T1539 Steal Web Session Cookie Session Fixation, Token Exposure in URL
ATT&CK T1548 Abuse Elevation Control Mechanism Over-Permissive IAM
ATT&CK T1550.001 Use Alternate Authentication Material: Application Access Token Third-Party App OAuth Risks
ATT&CK T1552 Unsecured Credentials Serverless Over-Privilege
ATT&CK T1552.001 Unsecured Credentials: Credentials In Files CI/CD Secret Exposure, Committed Secret Files, Leaked Access Tokens, Long-Lived Access Keys, Secrets in Git History, Secrets in Image Layers
ATT&CK T1552.005 Unsecured Credentials: Cloud Instance Metadata API Instance Metadata Abuse
ATT&CK T1552.008 Unsecured Credentials: Chat Messages Collaboration Tool Hygiene, Secure Messaging Practices
ATT&CK T1555.003 Credentials from Password Stores: Credentials from Web Browsers Browser Autofill Risks
ATT&CK T1555.005 Credentials from Password Stores: Password Managers Password Manager Habits
ATT&CK T1556 Modify Authentication Process Account Recovery Security
ATT&CK T1557 Adversary-in-the-Middle HTTPS & Website Security
ATT&CK T1562.008 Impair Defenses: Disable or Modify Cloud Logs Audit Logging Gaps
ATT&CK T1566.001 Phishing: Spearphishing Attachment Prompt Injection in Documents, OneNote Email Attack, Spear Phishing
ATT&CK T1566.002 Phishing: Spearphishing Link AI Support Chatbot Scam, AI-Written Phishing, Calendar Invite Scams, Double Barrel Phishing, Phishing, QR Code Phishing (Quishing), Smishing
ATT&CK T1566.003 Phishing: Spearphishing via Service WhatsApp Social Engineering, AI-Written Phishing, Cloned Voice Payment Fraud
ATT&CK T1566.004 Phishing: Spearphishing Voice Callback Phishing, Identity Theft Prevention, MGM Resorts Breach, AI Voice Phishing Calls, Vishing, Whaling With A Deepfake
ATT&CK T1583.001 Acquire Infrastructure: Domains Typosquatting Awareness
ATT&CK T1584.001 Compromise Infrastructure: Domains Subdomain Takeover
ATT&CK T1585 Establish Accounts Voice Clone Impersonation
ATT&CK T1585.001 Establish Accounts: Social Media Accounts Deepfake Hiring Fraud
ATT&CK T1589 Gather Victim Identity Information Social Media Oversharing
ATT&CK T1591 Gather Victim Org Information Social Media Oversharing
ATT&CK T1598 Phishing for Information Social Engineering, AI Support Chatbot Scam, AI Voice Phishing Calls
ATT&CK T1598.003 Phishing for Information: Spearphishing Link AI-Written Phishing
ATT&CK T1608.006 Stage Capabilities: SEO Poisoning SEO Poisoning Awareness
ATT&CK T1610 Deploy Container Exposed Docker Daemon
ATT&CK T1611 Escape to Host Privileged Containers
ATT&CK T1621 Multi-Factor Authentication Request Generation MFA Fatigue Attack, MFA Setup & Best Practices
ATT&CK T1626 Abuse Elevation Control Mechanism (Mobile) Mobile App Permissions
ATT&CK T1656 Impersonation Deepfake Audio Detection, Deepfake Hiring Fraud, Invoice & Payment Fraud, Secure Online Meetings, Voice Clone Impersonation, Tech Support Scams, Verification Procedures, Cloned Voice Payment Fraud, Business Email Compromise, Identity Theft Prevention, and 2 more
ATT&CK T1657 Financial Theft AI Agent Payment Fraud

How Does RansomLeak Map to CIS Critical Security Controls?

Control 14 is the security awareness safeguard, but the catalogue supports many of the others too. Broad controls list the ten most on-point exercises here, and the identifier links through to the full set in the library.

Identifier What it covers Exercises
CIS 2 Inventory and Control of Software Assets Malicious Base Images, Minimal Container Images, Shadow IT Awareness, Browser Extension Safety, Container Registry Exposure, Subdomain Takeover, Shadow AI Tools, Vulnerable Base Images
CIS 3 Data Protection Cloud Sharing Controls, Committed Secret Files, Data Classification Basics, Encryption & Lock Discipline, Breach Response Tabletop, Cookie Consent Management, Cross-Border Data Transfers, Data Breach Response, Data Mapping and Records of Processing, Data Protection Impact Assessment, and 20 more
CIS 4 Secure Configuration of Enterprise Assets and Software Exposed Docker Daemon, Instance Metadata Abuse, IoT & Smart Device Security, Mobile App Permissions, Mobile Device Security, Printer Admin Security, Privileged Containers, Exposed .git Directory, Minimal Container Images
CIS 5 Account Management Account Recovery Security, Guest Access Management, Joiner-Mover-Leaver Awareness, Leaked Access Tokens, Long-Lived Access Keys, Printer Admin Security
CIS 6 Access Control Management Container Registry Exposure, Least Privilege Awareness, MFA Fatigue Attack, MFA Setup & Best Practices, Multi-Account Boundaries, Over-Permissive IAM, Privileged Access Basics, Serverless Over-Privilege, Deepfake Hiring Fraud, Exposed Docker Daemon, and 4 more
CIS 7 Continuous Vulnerability Management Endpoint Patching & EDR Alerts, OS Updates & Patching Basics, Vulnerable Base Images, Components with Known Vulnerabilities
CIS 8 Audit Log Management Audit Logging Gaps, Insufficient Logging & Monitoring, Log Sensitivity Awareness, CI/CD Secret Exposure
CIS 9 Email and Web Browser Protections Browser Autofill Risks, Browser Extension Safety, Browser Notification Abuse, HTTPS & Website Security, Safe Browsing & Downloads, Typosquatting Awareness
CIS 10 Malware Defenses File Extension Awareness, Image-Based Attacks (Stegosploit), Ransomware, USB Drop Attack, Safe Browsing & Downloads
CIS 11 Data Recovery Backup Best Practices, Ransomware
CIS 12 Network Infrastructure Management Cloud Network Exposure, Container Network Exposure, Home Router Security, Subdomain Takeover, VPN Usage & Safety
CIS 14.1 Establish and Maintain a Security Awareness Program Employee Security Responsibilities, Internet & Email Acceptable Use, ISMS Policy Awareness, Social Media Policy, Shadow IT Awareness
CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks AI Support Chatbot Scam, AI-Written Phishing, Audit Mindset Basics, Business Email Compromise, Calendar Invite Scams, Callback Phishing, Deepfake Audio Detection, Deepfake Hiring Fraud, Double Barrel Phishing, Prompt Injection in Documents, and 25 more
CIS 14.3 Train Workforce Members on Authentication Best Practices Credential Stuffing Awareness, Password Manager Habits, Account Recovery Security, AI Support Chatbot Scam, MFA Fatigue Attack, MFA Setup & Best Practices, AI Voice Phishing Calls
CIS 14.4 Train Workforce on Data Handling Best Practices Clean Desk Basics, Collaboration Tool Hygiene, Metadata Awareness, Using AI Tools Responsibly at Work, Unreviewed AI Output, Safe GenAI Usage, Secure Messaging Practices, Shadow AI Tools, Cloud Sharing Controls, Data Classification Basics, and 4 more
CIS 14.5 Train Workforce Members on Causes of Unintentional Data Exposure Data Leakage, Insider Threat (Accidental), Social Media Oversharing, Clean Desk Basics, Insider Threat (Intentional), Metadata Awareness, Secure Document Disposal, Social Media Policy, Unattended Printouts, Unapproved AI Notetakers
CIS 14.6 Train Workforce Members on Recognizing and Reporting Security Incidents Audit Portal Training, General Incident Reporting, Reporting Culture, AI Incident Reporting, Prompt Injection in Documents
CIS 14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates Endpoint Patching & EDR Alerts, OS Updates & Patching Basics
CIS 14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks Safe Bluetooth Practices, Home Router Security, HTTPS & Website Security, IoT & Smart Device Security, VPN Usage & Safety
CIS 15 Service Provider Management Third-Party App OAuth Risks
CIS 16 Application Software Security Multi-Agent Cascading Failure, AI Agent Code Injection, AI Agent Goal Hijacking, Agent Identity and Privilege Abuse, Agent-to-Agent Communication Spoofing, AI Agent Memory Poisoning, Rogue AI Agents, Agentic AI Supply Chain Attack, AI Agent Tool Exploitation, Over-Trusting AI Agent Recommendations, and 62 more
CIS 17 Incident Response Management AI Incident Reporting, General Incident Reporting, Reporting Culture

Frequently asked questions

Which compliance frameworks does RansomLeak training cover?

RansomLeak training maps to thirteen major frameworks: SOC 2, ISO 27001, ISO 27701, NIST CSF 2.0, GDPR, the EU AI Act, CCPA / CPRA, HIPAA, HITRUST CSF, PCI DSS, NIS2, DORA, and CMMC Level 1. Each framework has specific requirement areas linked to relevant courses and exercises.

Eight security taxonomies sit alongside them: the OWASP Top 10 lists for web, API, LLM, agentic and MCP applications, plus MITRE CWE, MITRE ATT&CK and the CIS Critical Security Controls.

This page is the cross-reference matrix for scope comparison. For framework deep dives (audit failure modes, named enforcement actions, control-by-control coverage), see the compliance framework guides.

Does RansomLeak map exercises to OWASP, CWE, and MITRE ATT&CK?

Yes. Every exercise carries the OWASP, CWE, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act identifiers it maps to. Those identifiers show on the exercise card in the catalogue as well as in the coverage tables on this page.

The tables are generated from the same data the catalogue uses, so they track content releases instead of being maintained by hand. You can also filter the library by identifier, for example CWE-89 or T1566.

Can RansomLeak generate audit-ready compliance reports?

Yes. The platform exports compliance reports in PDF, CSV, and Excel formats that document training completion by employee, department, and framework requirement. Reports include timestamps, scores, and evidence of participation.

Auditors can verify that specific controls have been addressed through structured training records without manual data collection.

How often should compliance training be refreshed?

Most frameworks require at least annual training, but best practice is quarterly or monthly updates. SOC 2 and ISO 27001 auditors expect to see ongoing awareness activities, not just a single annual session.

RansomLeak ships new content monthly, so you can assign fresh exercises on a regular cadence without repeating the same material.

Does RansomLeak support SCORM for compliance LMS tracking?

Yes. Every exercise exports as a SCORM 1.2 or SCORM 2004 package that runs inside your existing LMS. Completion data, scores, and time spent flow directly into your LMS reporting system.

Visit our SCORM integration page for details on supported platforms and deployment steps.

Can training be customized for specific compliance requirements?

Yes. Our content team builds custom exercises tailored to your regulatory environment. Healthcare organizations can get HIPAA-specific scenarios. Financial institutions can focus on PCI DSS and DORA requirements.

Custom content follows the same interactive 3D format and integrates with the standard compliance reporting tools.

What evidence does RansomLeak provide for auditors?

RansomLeak generates detailed training records that include employee name, department, exercise completed, date, time spent, score, and the specific compliance control addressed. These records are exportable and retention policies keep historical data available for multi-year audits.

For organizations using SCORM, the LMS maintains its own independent audit trail alongside RansomLeak records.

Map Your Training to Compliance

Talk to our team about building a compliance-aligned training program. Read the CISO buyer's guide for evaluation criteria, or explore the full exercise catalogue.