Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Free Security Awareness Training For Everyone

Interactive 3D cybersecurity simulations and employee security training exercises. No sign-up, no paywall. Start learning immediately.

200+
Free Exercises
3D
Interactive
100%
Handmade

What Security Awareness Exercises Are Available?

Master employee cybersecurity fundamentals with interactive 3D simulations and hands-on security exercises.

Frameworks

Showing 203 exercises

Callback Phishing

Handle a fake invoice designed to make you call.

  • ATT&CKT1566.004
  • CIS 14.2
Play Exercise

Phishing

Spot a phishing email before you click.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise

Vishing

Handle a realistic voice phishing call.

  • ATT&CKT1566.004
  • CIS 14.2
Play Exercise

Smishing

Detect fraud hiding in your text messages.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise

Double Barrel Phishing

Recognize the two-email trust trap.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise

Business Email Compromise

Stop a CEO impersonation wire fraud.

  • ATT&CKT1534
  • CIS 14.2
Play Exercise

Social Engineering

Recognize manipulation before you comply.

  • ATT&CKT1598
  • CIS 14.2
Play Exercise

Whaling With A Deepfake

Spot an AI-generated executive on a video call.

  • ATT&CKT1566.004
  • CIS 14.2
Play Exercise

Spear Phishing

Your public profile is their attack playbook.

  • ATT&CKT1566.001
  • CIS 14.2
Play Exercise

QR Code Phishing (Quishing)

That QR code skips every email filter you have.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise

WhatsApp Social Engineering

Your "boss" on WhatsApp isn't your boss.

  • ATT&CKT1566.003
  • CIS 14.2
Play Exercise

Tech Support Scams

That virus warning is the actual attack.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise

SEO Poisoning Awareness

Top search results aren't always trustworthy.

  • ATT&CKT1608.006
  • CIS 14.2
Play Exercise

Invoice & Payment Fraud

Catch a fraudulent vendor invoice using the 3-way match before it reaches the payment file.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise

Verification Procedures

Stop a vendor banking BEC by using your authoritative directory and an out-of-band callback.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise

Deepfake Audio Detection

Catch an AI-cloned executive voice on the phone before the wire goes out.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise

Calendar Invite Scams

Catch a spoofed calendar invite before the fake meeting page harvests your credentials.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise

Backup Best Practices

Build a backup plan that survives ransomware.

  • ATT&CKT1490
  • CIS 11
  • NIST CSFPR.DS
Play Exercise

Encryption & Lock Discipline

Practice the habits that protect unattended devices.

  • ATT&CKT1530
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

OS Updates & Patching Basics

See why skipping updates opens real attack paths.

  • ATT&CKT1190
  • CIS 7
  • NIST CSFID.RA
Play Exercise

Ransomware

Survive a ransomware attack in real time.

  • ATT&CKT1486
  • CIS 10
  • NIST CSFPR.PS
Play Exercise

USB Drop Attack

Think twice before plugging in that USB drive.

  • ATT&CKT1091
  • CIS 10
  • NIST CSFPR.PS
Play Exercise

Endpoint Patching & EDR Alerts

Know what your EDR alert means and what to do next.

  • ATT&CKT1068
  • CIS 7
  • NIST CSFID.RA
Play Exercise

File Extension Awareness

It looks like a PDF. It runs like malware.

  • ATT&CKT1036.007
  • CIS 10
  • NIST CSFPR.PS
Play Exercise

Safe Bluetooth Practices

Your headphones are broadcasting more than music.

  • ATT&CKT1011
  • CIS 14.8
Play Exercise

Mobile Device Security

One fake text. Eight hours of stolen access.

  • ATT&CKT1476
  • CIS 4
  • NIST CSFPR.PS
Play Exercise

IoT & Smart Device Security

Your smart camera scores 28 out of 100.

  • CWE-1392
  • ATT&CKT1078.001
  • CIS 4
  • NIST CSFPR.PS
Play Exercise

Mobile App Permissions

Name the feature each permission powers, or revoke it.

  • ATT&CKT1626
  • CIS 4
  • NIST CSFPR.PS
Play Exercise

Account Recovery Security

Defend account recovery from social engineering.

  • ATT&CKT1098.005
  • CIS 5
  • NIST CSFPR.AA
Play Exercise

Credential Stuffing Awareness

See how breached passwords fuel automated attacks.

  • ATT&CKT1110.004
  • CIS 14.3
Play Exercise

Joiner-Mover-Leaver Awareness

Manage access rights through role transitions.

  • ATT&CKT1078
  • CIS 5
  • NIST CSFPR.AA
Play Exercise

Least Privilege Awareness

Keep access to the minimum your job requires.

  • ATT&CKT1078
  • CIS 6
  • NIST CSFPR.AA
Play Exercise

MFA Setup & Best Practices

Set up multi-factor authentication the right way.

  • ATT&CKT1621
  • CIS 6
  • NIST CSFPR.AA
Play Exercise

MFA Fatigue Attack

Your phone buzzes for the thirtieth time. Then a Slack message says approve.

  • ATT&CKT1621
  • CIS 6
  • NIST CSFPR.AA
Play Exercise

Password Manager Habits

Build strong habits with your password manager.

  • ATT&CKT1555.005
  • CIS 14.3
Play Exercise

Privileged Access Basics

Learn why admin accounts need special handling.

  • ATT&CKT1078
  • CIS 6
  • NIST CSFPR.AA
Play Exercise

HTTPS & Website Security

Learn why the padlock icon is not proof of safety.

  • ATT&CKT1557
  • CIS 9
  • NIST CSFPR.PS
Play Exercise

Safe Browsing & Downloads

Spot malicious downloads before they run.

  • ATT&CKT1189
  • CIS 9
  • NIST CSFPR.PS
Play Exercise

Typosquatting Awareness

Catch the domain tricks attackers use against you.

  • ATT&CKT1583.001
  • CIS 9
  • NIST CSFPR.PS
Play Exercise

Browser Autofill Risks

Hidden fields silently steal your autofilled data.

  • ATT&CKT1555.003
  • CIS 9
  • NIST CSFPR.PS
Play Exercise

Browser Extension Safety

That helpful extension might be stealing everything.

  • ATT&CKT1176
  • CIS 9
  • NIST CSFPR.PS
Play Exercise

Browser Notification Abuse

That CAPTCHA was a trap for push spam.

  • ATT&CKT1204.001
  • CIS 9
  • NIST CSFPR.PS
Play Exercise

General Incident Reporting

Know when and how to report a security incident.

  • CIS 14.6
  • NIST CSFRS.MA
Play Exercise

Reporting Culture

Build a team that reports without fear.

  • CIS 14.6
  • NIST CSFRS.MA
Play Exercise

Cloud Sharing Controls

Audit who can see your shared files right now.

  • CWE-732
  • ATT&CKT1530
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Guest Access Management

Control what external users can reach and for how long.

  • ATT&CKT1078
  • CIS 5
  • NIST CSFPR.AA
Play Exercise

Secure Messaging Practices

Stop sensitive data from leaking through chat apps.

  • ATT&CKT1552.008
  • CIS 14.4
Play Exercise

Social Media Policy

Learn what not to post on corporate accounts.

  • CIS 14.1
Play Exercise

Social Media Oversharing

See how attackers exploit your public profiles.

  • ATT&CKT1589
  • CIS 14.5
Play Exercise

Third-Party App OAuth Risks

Check what you gave permission to access.

  • ATT&CKT1528
  • CIS 15
  • NIST CSFGV.SC
Play Exercise

Secure Online Meetings

Spot the drop-in attendee, remove them, lock the meeting, file the report.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise

Audit Mindset Basics

Think like an auditor to find compliance gaps.

  • CIS 14.2
Play Exercise

Audit Portal Training

Navigate GRC portals and submit audit evidence.

  • CIS 14.6
Play Exercise

Employee Security Responsibilities

Know your personal security duties at work.

  • CIS 14.1
Play Exercise

ISMS Policy Awareness

Connect ISO 27001 policies to your daily work.

  • CIS 14.1
Play Exercise

Internet & Email Acceptable Use

Stay within corporate internet and email policies.

  • CIS 14.1
Play Exercise

Data Classification Basics

Label data correctly by sensitivity level.

  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Identity Theft Prevention

Spot identity theft tactics targeting employees.

  • ATT&CKT1566.004
  • CIS 14.2
Play Exercise

Secure Sharing Practices

Share files safely without creating security gaps.

  • CWE-732
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Leakage

Stop sensitive data from leaving your org.

  • CWE-200
  • CIS 14.5
Play Exercise

Log Sensitivity Awareness

Production logs hold things you would never email out.

  • CWE-532
  • CIS 8
  • NIST CSFPR.PS
Play Exercise

Metadata Awareness

A black rectangle over text does not remove the text.

  • CWE-212
  • CIS 14.4
Play Exercise

Safe GenAI Usage

Use generative AI without leaking sensitive client data.

  • OWASP LLMLLM02:2025
  • EU AI ActArt. 4
  • CIS 14.4
Play Exercise

Insider Threat (Intentional)

Recognize the warning signs of a malicious insider.

  • ATT&CKT1052
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Shadow IT Awareness

Find out what happens when teams use unapproved apps.

  • CIS 2
  • NIST CSFID.AM
Play Exercise

Image-Based Attacks (Stegosploit)

That image file might be carrying more than pixels.

  • ATT&CKT1027.003
  • CIS 10
  • NIST CSFPR.PS
Play Exercise

Insider Threat (Accidental)

One wrong attachment. Forty-seven salaries exposed.

  • CIS 14.5
Play Exercise

Collaboration Tool Hygiene

One shortcut in Slack. Credentials everywhere.

  • CWE-522
  • ATT&CKT1552.008
  • CIS 14.4
Play Exercise

VPN Usage & Safety

Configure and use your VPN without leaving gaps.

  • ATT&CKT1133
  • CIS 12
  • NIST CSFPR.IR
Play Exercise

Home Router Security

Find out who else is on your home network.

  • CWE-1392
  • ATT&CKT1078.001
  • CIS 12
  • NIST CSFPR.IR
Play Exercise

Personal Data Essentials

Recognize personal data before you handle it.

  • GDPRArt. 4
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Principles and Legal Bases

Pick the lawful basis before the work starts.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Everyday Privacy Duties

The three reflexes that keep a small problem small.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Employee Data Collection

Send the staff form twice: once wrong, once lawfully.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Marketing Consent Management

Build compliant opt-in flows that regulators accept.

  • GDPRArt. 7
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Breach Response

Triage a breach and meet the 72-hour notification clock.

  • GDPRArt. 33
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Privacy by Design Review

Evaluate a product feature through a privacy-first lens.

  • GDPRArt. 25
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Legitimate DSAR Processing

Process a data subject access request end to end.

  • GDPRArt. 15
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

PII Document Redaction

Redact personal data from documents before disclosure.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Fraudulent DSAR Detection

Spot fake data access requests used for social engineering.

  • GDPRArt. 12
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Third-Party Data Processor Vetting

Evaluate a vendor's data processing controls before signing.

  • GDPRArt. 28
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Security Incident Response

Coordinate security and privacy teams during a live breach.

  • GDPRArt. 32
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Cross-Border Data Transfers

Navigate transfer mechanisms for data leaving the EEA.

  • GDPRArt. 44
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Protection Impact Assessment

Run a DPIA for a high-risk data processing activity.

  • GDPRArt. 35
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Mapping and Records of Processing

Build an Article 30 processing register from scratch.

  • GDPRArt. 30
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Cookie Consent Management

Fix a cookie banner a regulator has already flagged.

  • GDPRArt. 7
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Data Retention Compliance

Decide what to delete, retain, hold, or anonymize.

  • GDPRArt. 5
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Breach Response Tabletop

Take the privacy seat on a live ransomware bridge.

  • GDPRArt. 33
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

AI Literacy Essentials

Earn the AI literacy required by Article 4 before touching company AI tools.

  • EU AI ActArt. 4
Play Exercise

AI Risk Classification

Sort real AI deployments into the four EU AI Act risk tiers.

  • EU AI ActArt. 6
Play Exercise

Prohibited AI Practices

Stop banned AI deployments before they go live.

  • EU AI ActArt. 5
Play Exercise

High-Risk AI: Deployer Obligations

Block a high-risk AI launch with compliance gaps in any of seven areas.

  • EU AI ActArt. 8
Play Exercise

Provider vs. Deployer: Who's Responsible?

A compliant vendor product does not make your deployment compliant.

  • EU AI ActArt. 16
Play Exercise

AI Transparency and Disclosure

Label AI chatbots and synthetic media correctly under Article 50.

  • EU AI ActArt. 50
Play Exercise

Meaningful Human Oversight

Override an AI loan recommendation when the evidence does not match.

  • EU AI ActArt. 14
Play Exercise

AI Data Governance

Block AI training that uses a leaky, biased, or oversharing dataset.

  • GDPRArt. 5
  • EU AI ActArt. 10
Play Exercise

AI and Data Protection

Run a healthcare AI through both EU AI Act and GDPR at once.

  • GDPRArt. 22
  • EU AI ActArt. 26
Play Exercise

Bias and Discrimination in AI

Investigate proxy variables hiding inside a resume-screening model.

  • EU AI ActArt. 10
Play Exercise

Fundamental Rights Impact Assessment

Run a FRIA before a social housing AI ever assigns a benefit decision.

  • GDPRArt. 35
  • EU AI ActArt. 27
Play Exercise

AI Incident Reporting

Report a discriminatory AI rejection pattern under Article 62.

  • EU AI ActArt. 62
  • CIS 17
  • NIST CSFRS.MA
Play Exercise

AI Governance in Your Organization

Build an AI registry and shut down shadow AI in your company.

  • EU AI ActArt. 4
Play Exercise

General-Purpose AI Model Obligations

Map GPAI provider and downstream deployer duties for systemic-risk models.

  • EU AI ActArt. 53
Play Exercise

Using AI Tools Responsibly at Work

Make compliant AI choices through a normal working day.

  • EU AI ActArt. 4
  • CIS 14.4
Play Exercise

EU AI Act Penalties and Enforcement

Map the three-tier penalty structure to real enforcement scenarios.

  • EU AI ActArt. 99
Play Exercise
Soon

Privacy Breach Through Application Vulnerabilities

An error message and one URL id are enough to read other people's records.

Coming Soon
Soon

Internal Data Leakage to Unauthorized Parties

Customer records reach an outside vendor because a share link was too broad.

Coming Soon
Soon

Handling a Personal Data Breach

The clock starts at detection, not when you understand the leak.

Coming Soon
Soon

Consent Dark Patterns and Bundled Permissions

One checkbox for five purposes is not consent to any of them.

Coming Soon
Soon

Opaque Privacy Policies and Hidden Data Practices

The policy discloses everything and explains nothing.

Coming Soon
Soon

Personal Data Deletion Failures

The account is gone. The backup, the analytics profile, and the CRM are not.

Coming Soon
Soon

Outdated and Inaccurate Personal Data

A stale record stops being untidy once it decides someone's credit.

Coming Soon
Soon

Session Hijacking Through Missing Expiration

The last person to use this workstation is still logged in.

Coming Soon
Soon

Blocked Data Subject Access Requests

One person's data, one month, and no system that agrees who they are.

Coming Soon
Soon

Excessive Personal Data Collection

Every field you collect just in case is a field you have to protect.

Coming Soon

Clawdbot (Moltbot) Prompt Injection

Stop a hidden prompt from hijacking your AI assistant mid-task.

  • OWASP LLMLLM01:2026
  • CWE-1427
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Sensitive Data Exposure Through AI

See what happens when confidential data enters a consumer AI tool.

  • OWASP LLMLLM02:2026
  • CWE-200
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI Supply Chain Attack

Deploy an AI plugin that hides a backdoor in plain sight.

  • OWASP LLMLLM04:2026
  • CWE-1104
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI Training Data Poisoning

Watch poisoned documents corrupt your AI's answers in real time.

  • OWASP LLMLLM05:2026
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Unsafe AI Output Handling

Exploit an AI whose outputs flow unchecked into live systems.

  • OWASP LLMLLM10:2026
  • CWE-1426
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Over-Permissioned AI Agent

Manipulate an AI assistant into misusing its own permissions.

  • OWASP LLMLLM03:2026
  • CWE-250
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI System Prompt Leakage

Extract hidden instructions from a customer-facing AI chatbot.

  • OWASP LLMLLM08:2026
  • CWE-200
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

RAG Pipeline Exploitation

Exploit a RAG pipeline to access documents beyond your clearance.

  • OWASP LLMLLM09:2026
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI Hallucination and Misinformation

Catch fabricated statistics and fake citations in an AI report.

  • OWASP LLMLLM07:2026
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI Denial-of-Service Attack

Launch a denial-of-wallet attack against an unprotected AI API.

  • OWASP LLMLLM06:2026
  • CWE-770
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI Agent Goal Hijacking

Spot the moment an AI agent's goal is quietly rewritten.

  • OWASPASI01:2026
  • CWE-1427
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI Agent Tool Exploitation

Catch the fraudulent items an agent's tools slip into your queue.

  • OWASPASI02:2026
  • CWE-250
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Agent Identity and Privilege Abuse

Find the agent that has been quietly widening its own access.

  • OWASPASI03:2026
  • CWE-269
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Agentic AI Supply Chain Attack

A backdoored MCP server mirrors every query your agents make.

  • OWASPASI04:2026
  • CWE-1104
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI Agent Code Injection

Read the AI's pull request before you approve the reverse shell.

  • OWASPASI05:2026
  • CWE-94
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

AI Agent Memory Poisoning

One poisoned memory entry keeps steering the agent for weeks.

  • OWASPASI06:2026
  • CWE-1427
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Agent-to-Agent Communication Spoofing

Forge one message on an unauthenticated agent bus and it obeys.

  • OWASPASI07:2026
  • CWE-345
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Multi-Agent Cascading Failure

One bad record, five agents, and a filed regulatory report.

  • OWASPASI08:2026
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Over-Trusting AI Agent Recommendations

Weeks of accurate approvals are the setup, not the reassurance.

  • OWASPASI09:2026
  • CWE-1426
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Rogue AI Agents

Healthy metrics, clean output, one agent acting on its own.

  • OWASPASI10:2026
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Poisoned Tool Descriptions

Agents read tool descriptions as instructions, not as docs.

  • OWASP MCPMCP03:2025
  • CWE-1427
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

MCP Command Injection

A semicolon in a tool argument becomes a shell command.

  • OWASP MCPMCP05:2025
  • CWE-78
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Hijacked Agent Intent

Text an agent reads is not a command it should obey.

  • OWASP MCPMCP06:2025
  • CWE-1427
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Shadow MCP Servers

Your client's server list is not what is actually listening.

  • OWASP MCPMCP09:2025
  • CWE-1059
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Typosquatted MCP Package

Installing an MCP server runs its code before you read it.

  • OWASP MCPMCP04:2025
  • CWE-494
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Missing MCP Audit Trail

Logging turned on today cannot recover yesterday.

  • OWASP MCPMCP08:2025
  • CWE-778
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Unauthenticated MCP Server

Approving a server is not the same as authenticating it.

  • OWASP MCPMCP07:2025
  • CWE-306
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Agent Scope Creep

An agent reaches as far as its token, not its brief.

  • OWASP MCPMCP02:2025
  • CWE-269
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Leaked MCP Tokens

A token in your MCP config is a token your assistant reads.

  • OWASP MCPMCP01:2025
  • CWE-522
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Cross-Tenant Context Leak

When one agent serves many customers, its context is data.

  • OWASP MCPMCP10:2025
  • CWE-200
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

OneNote Email Attack

Trace a real BEC scam built on weeks of inbox surveillance.

  • ATT&CKT1566.001
  • CIS 14.2
Play Exercise

MGM Resorts Breach

Relive the 10-minute helpdesk call that cost $100M.

  • ATT&CKT1566.004
  • CIS 14.2
Play Exercise

Clickjacking

Steal a click on a bank approval button.

  • OWASPA02:2025
  • CWE-1021
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Command Injection

Chain a second command onto a server-side tool.

  • OWASPA05:2025
  • CWE-78
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Components with Known Vulnerabilities

Get code execution through an outdated library.

  • OWASPA03:2025
  • CWE-1104
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Cross-Site Request Forgery

Move money from a page the victim never trusted.

  • OWASPA01:2025
  • CWE-352
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Directory Traversal

Read system files through a download link.

  • OWASPA01:2025
  • CWE-22
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

DOM XSS

Trigger XSS the server never sees.

  • OWASPA05:2025
  • CWE-79
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Forced Browsing

Pull an employee PII export from an unlinked route.

  • OWASPA01:2025
  • CWE-425
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Horizontal Privilege Escalation

Change one digit and read another customer.

  • OWASPA01:2025
  • CWE-639
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Host Header Injection

Redirect a password-reset email to a lookalike domain.

  • OWASPA02:2025
  • CWE-644
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Insecure URL Redirect

Hide a phishing page behind a real login.

  • OWASPA01:2025
  • CWE-601
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Leftover Debug Code

Pull production secrets from a forgotten debug route.

  • OWASPA02:2025
  • CWE-489
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

PII in URL

Lift personal data straight out of a link.

  • OWASPA04:2025
  • CWE-598
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Reflected XSS

Craft a malicious URL that runs the moment it opens.

  • OWASPA05:2025
  • CWE-79
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Server-Side Request Forgery

Make the server fetch its own cloud credentials.

  • OWASPA01:2025
  • CWE-918
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Session Fixation

Plant a session id and inherit the victim login.

  • OWASPA07:2025
  • CWE-384
  • ATT&CKT1539
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

SQL Injection

Dump a database through one unguarded lookup form.

  • OWASPA05:2025
  • CWE-89
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Stored XSS

Plant a script in a comment and watch it fire.

  • OWASPA05:2025
  • CWE-79
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Token Exposure in URL

Replay a session token harvested from a referrer log.

  • OWASPA07:2025
  • CWE-598
  • ATT&CKT1539
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

User Enumeration

Harvest a verified customer list from a login form.

  • OWASPA07:2025
  • CWE-204
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Vertical Privilege Escalation

Forge a role claim and become an administrator.

  • OWASPA01:2025
  • CWE-269
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Weak Randomness

Predict a password-reset token and take the account.

  • OWASPA04:2025
  • CWE-330
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

XXE Injection

Read the password file through an XML upload.

  • OWASPA02:2025
  • CWE-611
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Broken Function Level Authorization

Call staff-only endpoints from a read-only account.

  • OWASP APIAPI5:2023
  • CWE-285
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Broken Object Level Authorization

Swap an id and read another rider.

  • OWASP APIAPI1:2023
  • CWE-639
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Broken User Authentication

Brute-force a six-digit login code.

  • OWASP APIAPI2:2023
  • CWE-287
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Excessive Data Exposure

Read the fields the UI never shows.

  • OWASP APIAPI3:2019
  • CWE-213
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Improper Inventory Management

Read records through a retired API version.

  • OWASP APIAPI9:2023
  • CWE-1059
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Injection

Turn a search box into a full database read.

  • OWASP APIAPI8:2019
  • CWE-74
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Insufficient Logging & Monitoring

Look up a customer and leave no trace.

  • OWASP APIAPI10:2019
  • CWE-778
  • CIS 8
  • NIST CSFPR.PS
Play Exercise

Mass Assignment

Mint a loyalty balance with two extra keys.

  • OWASP APIAPI6:2019
  • CWE-915
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Security Misconfiguration

Read a signed-in account from any website.

  • OWASP APIAPI8:2023
  • CWE-942
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Unrestricted Resource Consumption

Scrape a catalog with one oversized request.

  • OWASP APIAPI4:2023
  • CWE-770
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Secrets in Git History

Recover a live API key from the commit that removed it.

  • CWE-540
  • ATT&CKT1552.001
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Exposed .git Directory

Rebuild an entire codebase from one public URL.

  • CWE-527
  • ATT&CKT1213.003
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Committed Secret Files

Clone a public repo and read its committed .env.

  • CWE-540
  • ATT&CKT1552.001
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Commit Author Spoofing

Land a backdoor wearing a maintainer’s name.

  • CWE-345
  • ATT&CKT1036
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Branch Protection Bypass

Force-push over main and skip review and CI.

  • CWE-285
  • ATT&CKT1195.002
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Leaked Access Tokens

Clone private repos with a token from a public gist.

  • CWE-522
  • ATT&CKT1552.001
  • CIS 5
  • NIST CSFPR.AA
Play Exercise

Malicious Pull Requests

Catch a backdoor hidden inside a friendly test fix.

  • CWE-494
  • ATT&CKT1195.002
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

CI/CD Secret Exposure

Lift a deploy key straight out of a public build log.

  • CWE-532
  • ATT&CKT1552.001
  • CIS 16
  • NIST CSFPR.PS
Play Exercise

Public Storage Buckets

List a bucket with no credentials and take the customer export.

  • CWE-732
  • ATT&CKT1530
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Over-Permissive IAM

Escalate a boring build credential into a full administrator.

  • CWE-269
  • ATT&CKT1098.003
  • CIS 6
  • NIST CSFPR.AA
Play Exercise

Long-Lived Access Keys

Replay a key that leaked months ago and still authenticates.

  • CWE-798
  • ATT&CKT1552.001
  • CIS 5
  • NIST CSFPR.AA
Play Exercise

Instance Metadata Abuse

Turn a URL-fetching feature into cloud credential theft.

  • CWE-918
  • ATT&CKT1552.005
  • CIS 4
  • NIST CSFPR.PS
Play Exercise

Cloud Network Exposure

Connect straight to a production database with no application in the path.

  • CWE-668
  • ATT&CKT1046
  • CIS 12
  • NIST CSFPR.IR
Play Exercise

Subdomain Takeover

Serve your own login page from a domain the company really owns.

  • CWE-672
  • ATT&CKT1584.001
  • CIS 12
  • NIST CSFPR.IR
Play Exercise

Audit Logging Gaps

Investigate an incident where the trail covered one region and the intruder deleted the rest.

  • CWE-778
  • ATT&CKT1562.008
  • CIS 8
  • NIST CSFPR.PS
Play Exercise

Serverless Over-Privilege

Drive a public function URL into an account-wide role.

  • CWE-250
  • ATT&CKT1552
  • CIS 6
  • NIST CSFPR.AA
Play Exercise

Multi-Account Boundaries

Walk a sandbox credential into production, then put a ceiling above the account.

  • CWE-1188
  • ATT&CKT1078.004
  • CIS 6
  • NIST CSFPR.AA
Play Exercise

Secrets in Image Layers

Read a live token out of a layer the build tried to clean up.

  • CWE-540
  • ATT&CKT1552.001
  • CIS 3
  • NIST CSFPR.DS
Play Exercise

Privileged Containers

Turn a shell in a container into root on the host.

  • CWE-250
  • ATT&CKT1611
  • CIS 4
  • NIST CSFPR.PS
Play Exercise

Exposed Docker Daemon

Take a production host through an unauthenticated Docker API.

  • CWE-306
  • ATT&CKT1610
  • CIS 4
  • NIST CSFPR.PS
Play Exercise

Vulnerable Base Images

Exploit a CVE in the OS layer nobody audits.

  • CWE-1104
  • ATT&CKT1190
  • CIS 7
  • NIST CSFID.RA
Play Exercise

Malicious Base Images

Trace a cryptominer back to one line in a Dockerfile.

  • CWE-494
  • ATT&CKT1195.002
  • CIS 2
  • NIST CSFID.AM
Play Exercise

Container Registry Exposure

Pull a private image, then replace the tag they deploy.

  • CWE-306
  • ATT&CKT1525
  • CIS 6
  • NIST CSFPR.AA
Play Exercise

Container Network Exposure

A port mapping puts a production database on the internet.

  • CWE-668
  • ATT&CKT1046
  • CIS 12
  • NIST CSFPR.IR
Play Exercise

Minimal Container Images

Cut a 412MB runtime down to what actually has to ship.

  • CWE-1188
  • CIS 2
  • NIST CSFID.AM
Play Exercise
Coming Soon

Free Exercise Builder

Create your own interactive cyber hygiene exercises. Build custom email security simulations, credential theft scenarios, and threat awareness training. All for free.

Drag & Drop No coding required
SCORM Export Works with any LMS
Forever Free Open for everyone

Frequently asked questions

Are these exercises really free?

Yes. Every exercise in our free library is fully playable with no sign-up, no email required, and no paywall. You get the same interactive 3D simulations used by enterprise customers.

The free library covers core attack types including phishing, ransomware, social engineering, vishing, smishing, and business email compromise. Enterprise features like analytics dashboards, SSO, and SCORM export require a paid plan.

Who are these free exercises for?

Anyone who wants to improve their cybersecurity awareness. Individuals building personal security skills, students studying cybersecurity, small business owners training their teams, and IT administrators evaluating our platform before purchasing.

No sign-up is required. Each exercise takes 5 to 10 minutes and covers topics from basic phishing detection to AI prompt injection and deepfake whaling.

How long does each exercise take?

Most exercises take 5 to 10 minutes. Each one uses an interactive 3D simulation where you face a realistic cybersecurity scenario and make decisions at key points.

Wrong choices trigger immediate corrective feedback explaining what went wrong and why. According to National Training Laboratories research, practice-by-doing achieves 75% knowledge retention compared to 5% for lectures.

What topics do the exercises cover?

Over 200 exercises across four active categories, with Application Security, API Security, and Cloud Security launching soon. Security Awareness covers phishing, ransomware, social engineering, vishing, smishing, business email compromise, deepfake whaling, and USB drop attacks.

AI & LLM Security covers prompt injection, AI-powered phishing, deepfake voice cloning, plus the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications. Privacy & Compliance exercises address GDPR, data subject access requests, breach notification, cross-border transfers, and the OWASP Top 10 Privacy Risks. New exercises are added monthly.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.