Nobody learns cloud security from a bullet list. You learn it the first time a misconfigured trust policy turns into someone else's access, and you trace back every place it could have been stopped. Cloud Siege is our attempt to give people that moment without the incident—as a six-round card duel where you can play the attacker.

The problem with security training

Most security learning is written from the defender's chair. You get a list of controls, a compliance checklist, and a diagram with a padlock on it. It tells you what to turn on. It rarely tells you what happens when you don't—or, more usefully, what happens when you turn on the wrong thing and feel covered.

Attackers don't work from a checklist. They work from a chain: get in, run something, get out with credentials, data, or privilege. Any single link is a chance to break it. That chain is the actual lesson, and it's very hard to teach with slides.

A control isn't good or bad. It's early or late, broad or exact, and cheap or expensive. You only feel that difference when someone is attacking you.

So we made it a game

Cloud Siege: The Control Plane Clash is a Red versus Blue card battle played on a cloud account map—Internet Edge, Federation Gateway, Application Workload, Data Boundary, and the Crown Store you're either protecting or trying to break. Six rounds. Crown Integrity starts at 10. Red wins by getting it to zero; Blue wins by keeping anything left standing.

Every attack has three windows

This is the part we care most about. In Cloud Siege, every Red unit exposes properties at three points: entry, execution, and exit. A stolen session enters as a credential, executes as an active session, and exits as egress. An SSRF enters at the edge, executes against instance metadata, and exits carrying temporary credentials.

Which means Blue always has three chances, not one. Miss the entry and you can still contain the execution. Miss both and an egress filter can still cut the impact down. That is defence in depth stated as a rule instead of a poster—and after a few matches you stop reading it as advice and start reading it as arithmetic.

Detection is not prevention

Blue's detection cards never stop anything. They make your next response cheaper, or give a nearby tower more capacity for the round. That's deliberate, and it's the lesson that costs people the most in real life: an alert is not a control. It's a discount on the control you still have to play.

Red gets to make that point too. Disable Logging and Log Tampering exist from day one, so the first time your detection round does nothing, you'll understand why attackers reach for the audit trail early.

Three ways in

An 84-card pool deals you a randomized, balanced 24-card loadout each match, so the same opening never plays out twice. Security Intel notes explain the real-world control behind each card as you use it, and the Security Gremlin turns up with tips—some of which are confidently wrong, on purpose. Spotting the bad advice is part of the training.

Who it's for

Engineers who keep meaning to read the IAM docs. Teams who want a security session that isn't another deck. Anyone learning cloud who wants a reason to remember why IMDSv2 matters, what a permission boundary is actually for, and why one very cheap public-access mistake can end a match.

It's free, it runs in the browser, and it's fully designed and developed by Mr.D. Twelve to eighteen minutes a match—about the length of the meeting you're skipping to play it.

Play Cloud Siege: The Control Plane Clash →