purplebutter
10 Games Available

Awareness Library

Interactive security awareness games for every threat vector and role. Free to play, no account required.

Access Governance·Investigation

Timeline Detective

Investigate employee access histories over time. Review role changes, permission grants, and certifications — then flag the moments where privilege creep, orphaned access, or missing reviews created governance risks.

15 min
IT/Security, Managers
Access Governance·Simulation

Inbox Triage

You're the access reviewer. A stream of access requests and security alerts hits your queue — approve, deny, or escalate each one. Not every request is suspicious, but the ones you rubber-stamp could expose the entire organization.

10 min
IT/Security, Managers
Access Governance·Investigation

Org Audit

Review department access dashboards and spot employees with governance risks — orphaned accounts from departed staff, excessive permissions that violate least privilege, and segregation of duties conflicts that no one caught. Submit your findings before the audit deadline.

15 min
IT/Security, Managers
AI Security·Simulation

Shadow AI

Navigate real workplace scenarios where colleagues want to use AI tools with company data. Make the call — some uses are safe, some need safeguards, and some should never happen. Learn where the lines are between productivity and data exposure.

15 min
All Employees
AI Security·Quiz

Deepfake Detective

Analyze voice messages, video calls, emails, and text messages to determine what's real and what's AI-generated. Train your eye and ear to catch the subtle signals that separate authentic communications from deepfake attacks.

10 min
All Employees
AI Security·Card Game

Prompt Injection

Examine AI chatbot interactions and spot the attacks. From obvious jailbreaks to hidden instructions in documents, learn how attackers manipulate AI systems — and how to defend against the #1 vulnerability in AI applications.

10 min
Developers, IT/Security
Operations·Terminal Sim

Terminal Roulette

A command is staged in a live terminal with a countdown. Read the context — hostname, directory, command history — and decide: execute, abort, or flag for review before the timer runs out. Not every command is dangerous, but the ones that are can take down production in seconds.

10 min
IT/Security, Developers
AI Security·Card Game

AI Supply Chain

Evaluate AI models, MCP servers, plugins, datasets, and agents before integrating them into your stack. Spot trojanized models, poisoned datasets, and backdoored tools hiding behind legitimate-looking registries.

10 min
Developers
IDE Security·Card Game

Extension Roulette

Swipe through VS Code marketplace listings under time pressure. Install, reject, or inspect each extension — spot the malicious ones hiding behind fake reviews, cloned names, and suspicious permissions before time runs out.

10 min
Developers
Social Engineering·Simulation

BEC: The Compromise

Navigate a realistic business email compromise scenario. Identify social engineering red flags, make critical decisions under pressure, and learn how attackers manipulate trust to authorize fraudulent transactions.

15 min
All Employees

Coming Soon

P
Coming Soon
Phishing·Quiz

Phish or Legit?

Analyze emails, links, and landing pages to determine what's real and what's a phish. Train your eye to catch the subtle differences that separate legitimate communications from credential-harvesting attacks.

10 min
All Employees
R
Coming Soon
Ransomware·Simulation

Ransomware Response

Lead your organization's response to an active ransomware incident. Make time-critical decisions about containment, communication, and recovery while balancing operational impact against security priorities.

20 min
IT/Security
T
Coming Soon
Insider Threat·Simulation

The Insider Threat

Investigate suspicious employee behavior patterns across access logs, communications, and data transfers. Distinguish between legitimate activity and indicators of insider compromise or data exfiltration.

15 min
IT/Security, Managers