Cloud Posture Lab
A CSPM report is a wall of findings. This is the part that actually matters: which ones do you fix first, and what does fixing them do to your risk? Walk a small cloud account, find the public bucket, the open SSH, the IAM wildcard and the internet-facing database, remediate them, and watch your posture score climb as the blast radius shrinks.
Goal
Remediate every critical and high finding in this account. Fix the public bucket and database, the admin wildcard, the open SSH/RDP, the MFA-less user, and turn on audit logging.
Posture score
0/100
Goal: clear every critical and high finding.
Findings
customer-exports: The bucket allows anonymous public access.
Blast radius: Anyone on the internet can list and download every object in the bucket.
deploy-bot: The identity can perform any action on any resource.
Blast radius: If these credentials leak, the entire account is taken over.
prod-postgres: The database instance has a public endpoint.
Blast radius: The production datastore is reachable from the internet.
web-sg: Port 22 is reachable from any address.
Blast radius: Direct brute-force and exploit surface for every host in the group.
bastion-sg: Port 22 is reachable from any address.
Blast radius: Direct brute-force and exploit surface for every host in the group.
bastion-sg: Port 3389 is reachable from any address.
Blast radius: Direct ransomware entry vector for every Windows host in the group.
jane.ops: A user with console access has no second factor.
Blast radius: A single phished or leaked password is full access.
org-trail: There is no account-wide audit trail.
Blast radius: No forensic record of API activity during a breach.
customer-exports: Server-side encryption is not enforced on the bucket.
prod-postgres: RDS storage encryption is not enabled.
customer-exports: S3 access logging is off, so reads/writes are not recorded.
app-cmk: Automatic annual rotation is off for this CMK.
Live now
team remediating togetherteam joiningβ¦
What this lab is
- A free cloud-misconfiguration lab: inspect a small cloud account, find the posture findings, and remediate them by flipping the offending setting.
- Covers the classics β public S3 buckets, 0.0.0.0/0 SSH/RDP, IAM *:* wildcards, public databases, missing MFA, disabled audit logging, unencrypted storage.
- Each finding carries a severity, a plain-language rationale, a CIS control reference, and β for criticals and highs β a blast-radius note.
- A live posture score (0β100) updates as you fix things; the goal is to clear every critical and high finding.
- Filter findings by severity and switch between a messy-account scenario and a crown-jewels scenario.
Frequently asked questions
What is the Cloud Posture Lab?
A free, in-browser exercise that drops you into a small simulated cloud account full of the misconfigurations a CSPM tool flags every day. You see each resource, the findings against it, and you remediate by toggling the offending setting β watching the finding clear and your posture score climb. It is the hands-on version of reading a Security Hub or Prowler report.
What checks does it run?
Public S3 buckets, buckets without default encryption or access logging, security groups exposing SSH (22) or RDP (3389) to 0.0.0.0/0, IAM identities without MFA, IAM policies granting Action:* on Resource:*, publicly accessible and unencrypted RDS databases, KMS keys without rotation, and accounts without CloudTrail. Each maps to a CIS AWS Foundations control.
How is the score calculated?
Each open finding subtracts a weight by severity (critical 40, high 20, medium 8, low 3) from 100, floored at 0. The explicit goal is zero critical and zero high findings β the bar a real account should clear before medium/low cleanup. Remediating a setting immediately re-scores.
Is this a real cloud account?
No. It is a teaching model of cloud posture management. Resources, names and settings are invented, and the checks are simplified to the decision that matters. Nothing here touches a real provider or account.