Skip to content
πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
Free lab

Cloud Posture Lab

A CSPM report is a wall of findings. This is the part that actually matters: which ones do you fix first, and what does fixing them do to your risk? Walk a small cloud account, find the public bucket, the open SSH, the IAM wildcard and the internet-facing database, remediate them, and watch your posture score climb as the blast radius shrinks.

Goal

Remediate every critical and high finding in this account. Fix the public bucket and database, the admin wildcard, the open SSH/RDP, the MFA-less user, and turn on audit logging.

customer-exportsS3 bucket3 finding(s)
web-sgSecurity group1 finding(s)
bastion-sgSecurity group2 finding(s)
deploy-botIAM identity1 finding(s)
jane.opsIAM identity1 finding(s)
prod-postgresRDS database2 finding(s)
app-cmkKMS key1 finding(s)
org-trailCloudTrail1 finding(s)

Posture score

0/100

Goal: clear every critical and high finding.

Findings

Public S3 bucketCIS AWS 2.1.5

customer-exports: The bucket allows anonymous public access.

Blast radius: Anyone on the internet can list and download every object in the bucket.

IAM policy grants *:*CIS AWS 1.16

deploy-bot: The identity can perform any action on any resource.

Blast radius: If these credentials leak, the entire account is taken over.

Publicly accessible databaseCIS AWS 2.3.3

prod-postgres: The database instance has a public endpoint.

Blast radius: The production datastore is reachable from the internet.

SSH open to 0.0.0.0/0CIS AWS 5.2

web-sg: Port 22 is reachable from any address.

Blast radius: Direct brute-force and exploit surface for every host in the group.

SSH open to 0.0.0.0/0CIS AWS 5.2

bastion-sg: Port 22 is reachable from any address.

Blast radius: Direct brute-force and exploit surface for every host in the group.

RDP open to 0.0.0.0/0CIS AWS 5.3

bastion-sg: Port 3389 is reachable from any address.

Blast radius: Direct ransomware entry vector for every Windows host in the group.

Console user without MFACIS AWS 1.10

jane.ops: A user with console access has no second factor.

Blast radius: A single phished or leaked password is full access.

Audit logging disabledCIS AWS 3.1

org-trail: There is no account-wide audit trail.

Blast radius: No forensic record of API activity during a breach.

Bucket not encrypted at restCIS AWS 2.1.1

customer-exports: Server-side encryption is not enforced on the bucket.

Database not encrypted at restCIS AWS 2.3.1

prod-postgres: RDS storage encryption is not enabled.

Access logging disabledCIS AWS 2.1.3

customer-exports: S3 access logging is off, so reads/writes are not recorded.

Key rotation disabledCIS AWS 3.8

app-cmk: Automatic annual rotation is off for this CMK.

Live now

team remediating together
cloudsec-mei1 fixes
platform-raj0 fixes
scanner-aiattacker

team joining…

TL;DR

What this lab is

  • A free cloud-misconfiguration lab: inspect a small cloud account, find the posture findings, and remediate them by flipping the offending setting.
  • Covers the classics β€” public S3 buckets, 0.0.0.0/0 SSH/RDP, IAM *:* wildcards, public databases, missing MFA, disabled audit logging, unencrypted storage.
  • Each finding carries a severity, a plain-language rationale, a CIS control reference, and β€” for criticals and highs β€” a blast-radius note.
  • A live posture score (0–100) updates as you fix things; the goal is to clear every critical and high finding.
  • Filter findings by severity and switch between a messy-account scenario and a crown-jewels scenario.

Frequently asked questions

What is the Cloud Posture Lab?

A free, in-browser exercise that drops you into a small simulated cloud account full of the misconfigurations a CSPM tool flags every day. You see each resource, the findings against it, and you remediate by toggling the offending setting β€” watching the finding clear and your posture score climb. It is the hands-on version of reading a Security Hub or Prowler report.

What checks does it run?

Public S3 buckets, buckets without default encryption or access logging, security groups exposing SSH (22) or RDP (3389) to 0.0.0.0/0, IAM identities without MFA, IAM policies granting Action:* on Resource:*, publicly accessible and unencrypted RDS databases, KMS keys without rotation, and accounts without CloudTrail. Each maps to a CIS AWS Foundations control.

How is the score calculated?

Each open finding subtracts a weight by severity (critical 40, high 20, medium 8, low 3) from 100, floored at 0. The explicit goal is zero critical and zero high findings β€” the bar a real account should clear before medium/low cleanup. Remediating a setting immediately re-scores.

Is this a real cloud account?

No. It is a teaching model of cloud posture management. Resources, names and settings are invented, and the checks are simplified to the decision that matters. Nothing here touches a real provider or account.

Cloud Posture Lab β€” Free Cloud Misconfiguration Trainer Β· PlayCISO