Bench: labs, cases & projects

The hands-on half of this path. Everything here is planned in SPEC.md and ships module by module (card order in the roadmap's build plan) — this page is the honest map of what exists today and what's next.

The Threat Model Studio

An in-browser workspace: build the DFD, walk STRIDE, mitigate, prioritize, check coverage against an expert model, export JSON + Markdown. Free, no account, saves to your browser.

CaseCloudWhat it trains
C1Food-delivery ordering API (API Gateway, Lambda, DynamoDB, S3, Cognito)AWSopen →
C2Clinic appointment SaaS with patient recordsAzureCS10
C3Card payments on EKS with a third-party payment providerAWSCS10
C4Multi-tenant B2B SaaSAWSCS11
C5RAG customer-support chatbot over internal docsAWS + AzureCS11
C6A bank's private cloud: on-prem Kubernetes/OpenStack, HSM, hybrid linkPrivate + hybridCS11
C7The CI/CD pipeline itself (GitHub Actions → AWS via OIDC)AWSCS11
C8Cross-account data lake (S3, Glue, Athena, Lake Formation)AWSCS11

Browser labs

No cloud account needed — graded by tests, like the existing 10-security exercises.

L1IAM policy puzzlesCS8
L2CloudTrail investigationCS8
L3Reachability: security groups, NACLs, route tablesCS8
L4KMS reasoning: who can decrypt?CS9
L5IaC misconfiguration hunt (Terraform + Bicep)CS9
L6Kubernetes RBAC & NetworkPolicy puzzlesCS9
L7Detection-as-code (Sigma rules)CS9

Real-cloud labs

Run in your own sandbox account, each with a budget alarm, a teardown script and a cost meter.

R1Secure baseline in Terraform (trail, GuardDuty, Config, SCPs)CS12
R2Attack and defend a CloudGoat scenarioCS12
R3GitHub Actions → AWS via OIDC, fix an over-broad trust policyCS13
R4Azure: managed identity, Key Vault, private endpointCS13
R5Harden a local kind/k3s cluster, then threat-model itCS13

Portfolio projects

Public on GitHub, built for interviews — each with milestones and a "how to talk about this in an interview" page.

PJ1Full threat model — a case or a real open-source appCS14
PJ2Secure landing zone (Terraform + policy-as-code + CI checks)CS14
PJ3Detection-as-code pipelineCS14
PJ4Incident response: tabletop, runbook, post-incident reportCS14
PJ5Secure GenAI app (threat model + guardrails)CS14

Interview prep & mocks

A security design round simulator, whiteboard drills, a deep-dive question bank, an incident scenario round, coding for security, behavioral STAR stories, and timed CCSK v5 / SCS-C03 mocks with a per-domain readiness dashboard.

CS15 (interview prep) · CS16 (mocks)