Aller au contenu
Live demo · Interactive modules

Interactive Cybersecurity Awareness
15 Free Attack Scenarios

Free cybersecurity training, no sign-up: 15 interactive modules to understand real attacks — ransomware, AiTM phishing, SQL injection, XSS, keyloggers, path traversal and more.

15 modules

15 Free Cybersecurity Awareness Modules

Phishing

A fraudulent email step by step, a fake Microsoft page annotated with 6 red flags, and a simulated vishing call with automatic script playback.

SQL Injection

Step 2

Authentication bypass via a SQL payload: watch the manipulated query live and apply the fix to block the attack.

Ransomware

Intrusion, spread, wave encryption and ransom note: follow every phase of a ransomware attack and its concrete impact.

XSS · Cross-Site Scripting

Step 1

Script injection in a forum comment, real-time session cookie theft and account takeover, illustrated.

XXE · XML External Entity

A booby-trapped XML forces the server to read the internal .env file: database passwords, API secrets and tokens exposed in a single request.

Password spraying

Follow every password attempt in real time, then discover what the attacker sees after the breach: mailbox, HR data and credentials.

SSRF · Server Side Request Forgery

The attacker supplies an internal URL: the server contacts its own network and returns AWS credentials. Animated step-by-step flow.

Clickjacking

An invisible iframe overlays a legitimate button: one click confirms a €25,000 payment without the user noticing.

IDOR · Insecure Direct Object Reference

Step 5

Changing an identifier in the URL to access another user's confidential data with no privilege escalation at all.

Keylogger

Step 6

Three keystroke-capture variants — software, a rigged USB cable and a browser extension — with exfiltration to a C2 server.

Path Traversal

Step 4

Reading sensitive files (.env, SSH keys, server configuration) via an uncontrolled path parameter in the URL.

Cleartext Traffic

Step 3

Interactive Wireshark capture: Telnet, FTP and HTTP expose credentials and passwords in cleartext on the local network.

Juice Jacking

A compromised public USB station or a BadUSB cable: your charging phone can be fully exfiltrated in under 3 minutes, with no alert at all.

Password Reuse

Step 7

One breached site is enough: stolen credentials are automatically tested via credential stuffing. With an interactive Have I Been Pwned check.

Session Hijacking · AiTM Phishing

Even with MFA enabled, an AiTM proxy steals the session cookie after validation. Step-by-step simulation, Twilio/Cloudflare case study and FIDO2 protection.

Frequently Asked Questions about Cybersecurity Awareness

What is cybersecurity awareness?
Cybersecurity awareness is a training program that teaches users to recognize and avoid common cyberattacks: phishing, ransomware, social engineering, weak passwords. ForenShield offers 15 free, interactive modules to understand real threats with no sign-up.
How does a cyberattack simulation work?
A cyberattack simulation reproduces the real steps of an attack (phishing, ransomware, SQL injection) in a safe environment. The goal is to make the mechanisms visible and understandable, for effective awareness with no real risk.
Which attacks are covered in ForenShield's awareness modules?
The 15 modules cover: phishing, AiTM phishing (MFA bypass), ransomware, SQL injection, XSS, SSRF, XXE, IDOR, path traversal, password spraying, password reuse, keyloggers, juice jacking, unencrypted network traffic and clickjacking.
Is ForenShield's cybersecurity training free?
Yes. ForenShield's 15 awareness modules are entirely free, with no sign-up and no ads. They're accessible directly from the browser and can be used to train teams in a company or for individual self-training.