The hands-on half of this path. Everything here is planned in SPEC.md and ships module by module (card order in the roadmap's build plan) — this page is the honest map of what exists today and what's next.
An in-browser workspace: build the DFD, walk STRIDE, mitigate, prioritize, check coverage against an expert model, export JSON + Markdown. Free, no account, saves to your browser.
| Case | Cloud | What it trains | |
|---|---|---|---|
| C1 | Food-delivery ordering API (API Gateway, Lambda, DynamoDB, S3, Cognito) | AWS | open → |
| C2 | Clinic appointment SaaS with patient records | Azure | CS10 |
| C3 | Card payments on EKS with a third-party payment provider | AWS | CS10 |
| C4 | Multi-tenant B2B SaaS | AWS | CS11 |
| C5 | RAG customer-support chatbot over internal docs | AWS + Azure | CS11 |
| C6 | A bank's private cloud: on-prem Kubernetes/OpenStack, HSM, hybrid link | Private + hybrid | CS11 |
| C7 | The CI/CD pipeline itself (GitHub Actions → AWS via OIDC) | AWS | CS11 |
| C8 | Cross-account data lake (S3, Glue, Athena, Lake Formation) | AWS | CS11 |
No cloud account needed — graded by tests, like the existing 10-security exercises.
| L1 | IAM policy puzzles | CS8 |
| L2 | CloudTrail investigation | CS8 |
| L3 | Reachability: security groups, NACLs, route tables | CS8 |
| L4 | KMS reasoning: who can decrypt? | CS9 |
| L5 | IaC misconfiguration hunt (Terraform + Bicep) | CS9 |
| L6 | Kubernetes RBAC & NetworkPolicy puzzles | CS9 |
| L7 | Detection-as-code (Sigma rules) | CS9 |
Run in your own sandbox account, each with a budget alarm, a teardown script and a cost meter.
| R1 | Secure baseline in Terraform (trail, GuardDuty, Config, SCPs) | CS12 |
| R2 | Attack and defend a CloudGoat scenario | CS12 |
| R3 | GitHub Actions → AWS via OIDC, fix an over-broad trust policy | CS13 |
| R4 | Azure: managed identity, Key Vault, private endpoint | CS13 |
| R5 | Harden a local kind/k3s cluster, then threat-model it | CS13 |
Public on GitHub, built for interviews — each with milestones and a "how to talk about this in an interview" page.
| PJ1 | Full threat model — a case or a real open-source app | CS14 |
| PJ2 | Secure landing zone (Terraform + policy-as-code + CI checks) | CS14 |
| PJ3 | Detection-as-code pipeline | CS14 |
| PJ4 | Incident response: tabletop, runbook, post-incident report | CS14 |
| PJ5 | Secure GenAI app (threat model + guardrails) | CS14 |
A security design round simulator, whiteboard drills, a deep-dive question bank, an incident scenario round, coding for security, behavioral STAR stories, and timed CCSK v5 / SCS-C03 mocks with a per-domain readiness dashboard.
CS15 (interview prep) · CS16 (mocks)