Lab Catalog

Hands-on environments you can spin up on demand. Browse freely; sign in when you want to start one.

Admission Policy as Code thumbnail 60m
Lab

Admission Policy as Code

Express your security standards as admission policies, test them against manifests that should pass and manifests that should not, and roll them out in audit mode before they start blocking deployments.

Richard Augenti Intermediate Policy as Code Kubernetes
Answering a Zero-Day with an SBOM thumbnail 45m
Lab

Answering a Zero-Day with an SBOM

Generate SBOMs for a set of build artifacts and use them to answer, in minutes rather than days, which deployed services contain a newly disclosed vulnerable component.

Richard Augenti Intermediate Supply Chain Security DevSecOps
Catching Infrastructure Misconfiguration Before Apply thumbnail 45m
Lab

Catching Infrastructure Misconfiguration Before Apply

Scan Terraform for the misconfigurations that become public buckets and open security groups, fix them, and wire the scan into the plan stage where it blocks a merge.

Richard Augenti Beginner Cloud Security Infrastructure as Code
Container Escape and the Controls That Stop It thumbnail 60m
Lab

Container Escape and the Controls That Stop It

Break out of a deliberately misconfigured container to reach the host, then apply the runtime and admission controls that make the same escape fail.

Richard Augenti Advanced Containers Kubernetes
Custom SAST Rules That Catch What Defaults Miss thumbnail 60m
Lab

Custom SAST Rules That Catch What Defaults Miss

Write, test and tune your own static analysis rules against a vulnerable codebase, then judge them on false positives as well as on what they catch.

Richard Augenti Intermediate Application Security DevSecOps
Cutting Cloud IAM Down to Least Privilege thumbnail 60m
Lab

Cutting Cloud IAM Down to Least Privilege

Find the over-permissioned roles in a cloud account, use access data to derive the permissions actually in use, and tighten the policies without breaking the workloads.

Richard Augenti Intermediate Cloud Security Identity and Access
DAST Against an Ephemeral Environment thumbnail 60m
Lab

DAST Against an Ephemeral Environment

Stand up a per-merge-request environment, run an authenticated dynamic scan against the running application, and turn the results into a pipeline gate that does not flake.

Richard Augenti Intermediate Application Security CI/CD
Detection as Code with Grafana thumbnail 60m
Lab

Detection as Code with Grafana

Define alert rules and dashboards as version-controlled code, test them against replayed attack telemetry, and ship them through a pipeline like any other artifact.

Richard Augenti Intermediate Detection Engineering Observability
DevSecOps Incident Response Game Day thumbnail 90m
Lab

DevSecOps Incident Response Game Day

Run a live compromise of a pipeline and cluster end to end: detect it, contain it, evict the attacker, and produce the timeline and control changes that come out of it.

Richard Augenti Advanced Incident Response DevSecOps
Exfiltrating Secrets from a CI Pipeline thumbnail 60m
Lab

Exfiltrating Secrets from a CI Pipeline

Run a malicious merge request that steals the pipeline's deploy token, then scope the secret to protected refs so an untrusted pipeline receives nothing while real deploys still work.

Techworth Labs Advanced CI/CD Secrets Management
Gating Builds on Vulnerable Dependencies thumbnail 45m
Lab

Gating Builds on Vulnerable Dependencies

Add a dependency scan that fails a build on exploitable CVEs, then work through the upgrades, exceptions and expiry dates that keep the gate from being quietly switched off.

Richard Augenti Beginner Supply Chain Security DevSecOps
Hardening a Container Image thumbnail 45m
Lab

Hardening a Container Image

Take a bloated application image that runs as root and rebuild it as a minimal, non-root, reproducible image, measuring the vulnerability count at every step.

Richard Augenti Beginner Containers DevSecOps
Kubernetes RBAC Privilege Escalation thumbnail 60m
Lab

Kubernetes RBAC Privilege Escalation

Escalate from a limited service account to cluster-admin through over-granted RBAC verbs, then rewrite the roles and prove the same path is closed.

Richard Augenti Advanced Identity and Access Kubernetes
Leaked Credential, End to End thumbnail 60m
Lab

Leaked Credential, End to End

A developer committed AWS credentials to the `payments-api` repository four commits ago, and the file is still tracked on the team's Git server. Detect the exposure with gitleaks, revoke the credential, purge it from every commit with `git filter-repo`, and discover that the remote is still dirty the moment that separates fixing your copy from fixing the exposure. You will finish by adding a pre-commit hook and a CI gate, then proving they work by trying to reintroduce a credential.

Richard Augenti Intermediate Secrets Management DevSecOps
Risk-Based Vulnerability Prioritization thumbnail 45m
Lab

Risk-Based Vulnerability Prioritization

Reduce thousands of raw scanner findings to the handful that matter, using exploitability, reachability and real exposure rather than CVSS score alone.

Richard Augenti Beginner Vulnerability Management DevSecOps
Runtime Secrets Management thumbnail 60m
Lab

Runtime Secrets Management

Move hardcoded application secrets into a managed secret store issuing short-lived dynamic credentials, and confirm that a stolen credential expires before it is useful.

Richard Augenti Intermediate Secrets Management DevSecOps
Runtime Threat Detection with Falco thumbnail 60m
Lab

Runtime Threat Detection with Falco

Attack a running workload, watch the default Falco rules miss part of it, then write and tune custom rules that catch the behaviour without burying you in noise.

Richard Augenti Intermediate Runtime Security Kubernetes
Shift-Left Security Scanning with Trivy thumbnail 45m
Lab

Shift-Left Security Scanning with Trivy

Find hardcoded credentials, vulnerable dependencies and insecure infrastructure code in a real repository before any of it reaches production.

Richard Augenti Intermediate Security DevSecOps
Signing and Verifying Build Artifacts thumbnail 60m
Lab

Signing and Verifying Build Artifacts

Sign container images and provenance attestations in the pipeline, then enforce verification at deploy time so an unsigned or tampered artifact cannot run.

Richard Augenti Intermediate Supply Chain Security DevSecOps
Testing API Authorization thumbnail 60m
Lab

Testing API Authorization

Exploit broken object-level and function-level authorization in a running API, fix the checks, and add the automated tests that keep the fixes honest.

Richard Augenti Intermediate API Security Application Security
Workload Identity and Mutual TLS thumbnail 60m
Lab

Workload Identity and Mutual TLS

Give each service a cryptographic identity, enforce mTLS between them, and confirm that an unidentified workload on the same network is refused rather than trusted.

Richard Augenti Advanced Zero Trust Kubernetes