Interactive Cybersecurity Awareness
15 Free Attack Scenarios
Free cybersecurity training, no sign-up: 15 interactive modules to understand real attacks — ransomware, AiTM phishing, SQL injection, XSS, keyloggers, path traversal and more.
15 Free Cybersecurity Awareness Modules
Phishing
A fraudulent email step by step, a fake Microsoft page annotated with 6 red flags, and a simulated vishing call with automatic script playback.
SQL Injection
Step 2Authentication bypass via a SQL payload: watch the manipulated query live and apply the fix to block the attack.
Ransomware
Intrusion, spread, wave encryption and ransom note: follow every phase of a ransomware attack and its concrete impact.
XSS · Cross-Site Scripting
Step 1Script injection in a forum comment, real-time session cookie theft and account takeover, illustrated.
XXE · XML External Entity
A booby-trapped XML forces the server to read the internal .env file: database passwords, API secrets and tokens exposed in a single request.
Password spraying
Follow every password attempt in real time, then discover what the attacker sees after the breach: mailbox, HR data and credentials.
SSRF · Server Side Request Forgery
The attacker supplies an internal URL: the server contacts its own network and returns AWS credentials. Animated step-by-step flow.
Clickjacking
An invisible iframe overlays a legitimate button: one click confirms a €25,000 payment without the user noticing.
IDOR · Insecure Direct Object Reference
Step 5Changing an identifier in the URL to access another user's confidential data with no privilege escalation at all.
Keylogger
Step 6Three keystroke-capture variants — software, a rigged USB cable and a browser extension — with exfiltration to a C2 server.
Path Traversal
Step 4Reading sensitive files (.env, SSH keys, server configuration) via an uncontrolled path parameter in the URL.
Cleartext Traffic
Step 3Interactive Wireshark capture: Telnet, FTP and HTTP expose credentials and passwords in cleartext on the local network.
Juice Jacking
A compromised public USB station or a BadUSB cable: your charging phone can be fully exfiltrated in under 3 minutes, with no alert at all.
Password Reuse
Step 7One breached site is enough: stolen credentials are automatically tested via credential stuffing. With an interactive Have I Been Pwned check.
Session Hijacking · AiTM Phishing
Even with MFA enabled, an AiTM proxy steals the session cookie after validation. Step-by-step simulation, Twilio/Cloudflare case study and FIDO2 protection.
Frequently Asked Questions about Cybersecurity Awareness
- What is cybersecurity awareness?
- Cybersecurity awareness is a training program that teaches users to recognize and avoid common cyberattacks: phishing, ransomware, social engineering, weak passwords. ForenShield offers 15 free, interactive modules to understand real threats with no sign-up.
- How does a cyberattack simulation work?
- A cyberattack simulation reproduces the real steps of an attack (phishing, ransomware, SQL injection) in a safe environment. The goal is to make the mechanisms visible and understandable, for effective awareness with no real risk.
- Which attacks are covered in ForenShield's awareness modules?
- The 15 modules cover: phishing, AiTM phishing (MFA bypass), ransomware, SQL injection, XSS, SSRF, XXE, IDOR, path traversal, password spraying, password reuse, keyloggers, juice jacking, unencrypted network traffic and clickjacking.
- Is ForenShield's cybersecurity training free?
- Yes. ForenShield's 15 awareness modules are entirely free, with no sign-up and no ads. They're accessible directly from the browser and can be used to train teams in a company or for individual self-training.