Cloud Security CTF Challenges
Misconfigurations, IAM abuse & cloud attack paths.
Round duration
12 hours
Format
Jeopardy-style CTF
Team size
1–3 members
Cloud security challenges are unusual among CTF categories because a meaningful share of them are not exploitable in the classic sense — they are misconfigurations. A bucket that permits anonymous listing, a role with far more permissions than its function needs, a metadata service reachable from a function you can influence. The attacker does not break in; they use what was left open.
That reframes how you approach the category. Instead of looking for a bug in an application, you are reading a trust boundary and asking what it permits. The IAM policy is the vulnerability. The attach-role configuration is the vulnerability. The lesson is one security teams pay for expensively in production, which is exactly why it is worth practising here.
Expect challenges built around realistic mistakes — an over-permissive trust policy, a hardcoded key in a repository, a public snapshot, or a server-side request that reaches the metadata endpoint. All of these appear regularly in real cloud incidents.
What you’ll actually face
Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.
Storage misconfiguration
Buckets and containers exposed to anonymous list or read, overly permissive object ACLs, and backup archives left readable.
IAM & privilege abuse
Over-broad role policies, trust relationships that accept unexpected principals, and privilege escalation chains through role assumption.
Metadata services
Instance and function metadata endpoints abused to steal temporary credentials — the same technique behind real-world cloud compromises.
Exposed secrets
API keys, access keys and connection strings leaked in environment variables, logs, source control or error messages.
Containers & orchestration
Dockerfiles and manifests with excessive capabilities, host mounts, privileged mode or missing security context.
Network exposure
Open security groups, public load balancers and management interfaces reachable from the public internet.
Tools you’ll reach for
- AWS CLI
- Azure CLI
- trufflehog / gitleaks
- ScoutSuite / cloudmapper
- kube-bench
- Terraform
- ffuf / nuclei
- CyberChef
How to prepare
None of this is required to enter — it is simply the shortest path to scoring points in this discipline.
Get a free-tier account on one major cloud and build something small. Reading a real IAM policy only makes sense once you have written one.
Study the four most common real-world cloud compromises: exposed credentials, permissive storage, SSRF to metadata, and over-privileged CI/CD.
Learn the AWS shared-responsibility boundary properly — it explains most of what these challenges are testing.
Practise secret scanning with `gitleaks` or `trufflehog` against public repositories to see what leaks look like in the wild.
Read a `Dockerfile` and a Kubernetes manifest with a security eye. Insecure defaults are everywhere and worth recognising instantly.
Quick facts
Everything about Ghost Protocol CTF 2.0 at a glance.
- Online qualifier
- 17 October 2026 · 12 hours · remote
- Grand finale
- 24 October 2026 · 12 hours · on-ground
- Format
- Jeopardy-style CTF
- Team size
- 1–3 members (solo entry allowed)
- Registration fee
- Free per team
- Prize pool
- Up to ₹51,000
- Challenge categories
- 10 disciplines
- Eligibility
- Any student in an undergraduate or postgraduate programme, any stream
- Venue
- NIET Greater Noida
- Organised by
- Cyber Invaders · NIET Greater Noida
Adjacent disciplines
Competitors in CTF teams tend to specialise — here is where the skills overlap.
Ready to prove it on the scoreboard?
Cloud Security is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.