
Exposed .git Folder: Scanning the Web for Secrets
A public web server at Larkspur Logistics was deployed straight from a git checkout, leaving its .git directory exposed to the Internet. Following the EMERALDWHALE playbook, an attacker pulled /.git/config, stole the GitHub token baked into the clone URL, cloned the private repository, and found a hard-coded AWS key inside that handed them the cloud account. Walk the access, GitHub, and CloudTrail logs step by step to trace one misconfiguration into a full credential-theft chain.
Launches in 5 days
Tuesday, July 28, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
What you'll investigate
7 objectives unlock when this operation goes live.
Be first when it launches
Create your free account now. The moment this operation goes live on Jul 28, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free