Challenge Category

Cloud Security CTF Challenges

Misconfigurations, IAM abuse & cloud attack paths.

Round duration

12 hours

Format

Jeopardy-style CTF

Team size

1–3 members

Cloud security challenges are unusual among CTF categories because a meaningful share of them are not exploitable in the classic sense — they are misconfigurations. A bucket that permits anonymous listing, a role with far more permissions than its function needs, a metadata service reachable from a function you can influence. The attacker does not break in; they use what was left open.

That reframes how you approach the category. Instead of looking for a bug in an application, you are reading a trust boundary and asking what it permits. The IAM policy is the vulnerability. The attach-role configuration is the vulnerability. The lesson is one security teams pay for expensively in production, which is exactly why it is worth practising here.

Expect challenges built around realistic mistakes — an over-permissive trust policy, a hardcoded key in a repository, a public snapshot, or a server-side request that reaches the metadata endpoint. All of these appear regularly in real cloud incidents.

What you’ll actually face

Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.

Storage misconfiguration

Buckets and containers exposed to anonymous list or read, overly permissive object ACLs, and backup archives left readable.

IAM & privilege abuse

Over-broad role policies, trust relationships that accept unexpected principals, and privilege escalation chains through role assumption.

Metadata services

Instance and function metadata endpoints abused to steal temporary credentials — the same technique behind real-world cloud compromises.

Exposed secrets

API keys, access keys and connection strings leaked in environment variables, logs, source control or error messages.

Containers & orchestration

Dockerfiles and manifests with excessive capabilities, host mounts, privileged mode or missing security context.

Network exposure

Open security groups, public load balancers and management interfaces reachable from the public internet.

Tools you’ll reach for

  • AWS CLI
  • Azure CLI
  • trufflehog / gitleaks
  • ScoutSuite / cloudmapper
  • kube-bench
  • Terraform
  • ffuf / nuclei
  • CyberChef

How to prepare

None of this is required to enter — it is simply the shortest path to scoring points in this discipline.

  1. Get a free-tier account on one major cloud and build something small. Reading a real IAM policy only makes sense once you have written one.

  2. Study the four most common real-world cloud compromises: exposed credentials, permissive storage, SSRF to metadata, and over-privileged CI/CD.

  3. Learn the AWS shared-responsibility boundary properly — it explains most of what these challenges are testing.

  4. Practise secret scanning with `gitleaks` or `trufflehog` against public repositories to see what leaks look like in the wild.

  5. Read a `Dockerfile` and a Kubernetes manifest with a security eye. Insecure defaults are everywhere and worth recognising instantly.

Quick facts

Everything about Ghost Protocol CTF 2.0 at a glance.

Online qualifier
17 October 2026 · 12 hours · remote
Grand finale
24 October 2026 · 12 hours · on-ground
Format
Jeopardy-style CTF
Team size
1–3 members (solo entry allowed)
Registration fee
Free per team
Prize pool
Up to ₹51,000
Challenge categories
10 disciplines
Eligibility
Any student in an undergraduate or postgraduate programme, any stream
Venue
NIET Greater Noida
Organised by
Cyber Invaders · NIET Greater Noida

Ready to prove it on the scoreboard?

Cloud Security is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.