Live-fire investigation workshop
Investigate a real breach. Then find it before it happens.
Two scenarios, one shared incident — Acme Rentals. An AI agent, armed with the open-source Anthropic Cybersecurity Skills library, does the actual investigation while you drive and check its work.
/casky-workshops
TollBooth
A web server leaked AWS credentials through SSRF. Find how, trace what the attacker stole, and map the full attack chain to MITRE ATT&CK. ~20 min.
Scenario 2 · Proactive auditOpenDoor
Same account, before the breach. Audit the AWS configs, find the three misconfigurations, and work out which one the attacker actually used. ~20 min.
Which path do I run?
Both scenarios can be driven two different ways. Pick whichever matches today's room setup — your facilitator will tell you which, but here's the difference:
| Section 1 — Kali + Claude Code | Section 2 — Casky Box | |
|---|---|---|
| Skill selection | 10 hand-picked skills, symlinked per laptop | Auto-classified from all 817 skills, per investigation |
| Agent runtime | Claude Code installed per laptop | One shared casky-runner container |
| Verification | verify.sh — 9 raw tshark/jq checks on the data | [VERIFIED] transcript per step — did the agent actually run the assigned skill's script |
| Output | Cheat-sheet answer pages | Structured plan → findings → CISO-style consolidated report |
| Reset between attendees | ./reset.sh (<10s) | Each investigation run is already fresh |
Full setup for both is on the Setup page — do that first, before opening either scenario page.
The printed cheat sheet
Everyone should have (or can grab) the original color-coded cheat sheet — teal instruction pages, orange checkpoints, red answer pages. This wiki mirrors it exactly, with the answers collapsed so you can attempt each phase before checking.
Authorized & lawful use only. All data in both scenarios is synthetic and self-contained — no live systems are touched. Built on the open-source Anthropic Cybersecurity Skills library (Apache-2.0); not affiliated with Anthropic PBC. Source data trimmed from BHUSA-Anthropic-CyberSecurity-Skills.