Awareness Library
Interactive security awareness games for every threat vector and role. Free to play, no account required.
Timeline Detective
Investigate employee access histories over time. Review role changes, permission grants, and certifications — then flag the moments where privilege creep, orphaned access, or missing reviews created governance risks.
Inbox Triage
You're the access reviewer. A stream of access requests and security alerts hits your queue — approve, deny, or escalate each one. Not every request is suspicious, but the ones you rubber-stamp could expose the entire organization.
Org Audit
Review department access dashboards and spot employees with governance risks — orphaned accounts from departed staff, excessive permissions that violate least privilege, and segregation of duties conflicts that no one caught. Submit your findings before the audit deadline.
Shadow AI
Navigate real workplace scenarios where colleagues want to use AI tools with company data. Make the call — some uses are safe, some need safeguards, and some should never happen. Learn where the lines are between productivity and data exposure.
Deepfake Detective
Analyze voice messages, video calls, emails, and text messages to determine what's real and what's AI-generated. Train your eye and ear to catch the subtle signals that separate authentic communications from deepfake attacks.
Prompt Injection
Examine AI chatbot interactions and spot the attacks. From obvious jailbreaks to hidden instructions in documents, learn how attackers manipulate AI systems — and how to defend against the #1 vulnerability in AI applications.
Terminal Roulette
A command is staged in a live terminal with a countdown. Read the context — hostname, directory, command history — and decide: execute, abort, or flag for review before the timer runs out. Not every command is dangerous, but the ones that are can take down production in seconds.
AI Supply Chain
Evaluate AI models, MCP servers, plugins, datasets, and agents before integrating them into your stack. Spot trojanized models, poisoned datasets, and backdoored tools hiding behind legitimate-looking registries.
Extension Roulette
Swipe through VS Code marketplace listings under time pressure. Install, reject, or inspect each extension — spot the malicious ones hiding behind fake reviews, cloned names, and suspicious permissions before time runs out.
BEC: The Compromise
Navigate a realistic business email compromise scenario. Identify social engineering red flags, make critical decisions under pressure, and learn how attackers manipulate trust to authorize fraudulent transactions.
Coming Soon
Phish or Legit?
Analyze emails, links, and landing pages to determine what's real and what's a phish. Train your eye to catch the subtle differences that separate legitimate communications from credential-harvesting attacks.
Ransomware Response
Lead your organization's response to an active ransomware incident. Make time-critical decisions about containment, communication, and recovery while balancing operational impact against security priorities.
The Insider Threat
Investigate suspicious employee behavior patterns across access logs, communications, and data transfers. Distinguish between legitimate activity and indicators of insider compromise or data exfiltration.