Skip to main content
Exposed .git Folder: Scanning the Web for Secrets operation cover
COMING SOONBeginner

Exposed .git Folder: Scanning the Web for Secrets

A public web server at Larkspur Logistics was deployed straight from a git checkout, leaving its .git directory exposed to the Internet. Following the EMERALDWHALE playbook, an attacker pulled /.git/config, stole the GitHub token baked into the clone URL, cloned the private repository, and found a hard-coded AWS key inside that handed them the cloud account. Walk the access, GitHub, and CloudTrail logs step by step to trace one misconfiguration into a full credential-theft chain.

25m
7 tasks
25 points
Free

Launches in 5 days

Jul 28, 2026

Tuesday, July 28, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

SIEMFirewall

What you'll investigate

7 objectives unlock when this operation goes live.

1Brief: a folder that should never have shipped
2Spot the dotfile that should have 404'd
3Whose key did the config give away
4Trace who used the stolen token
5Find the cloud key hidden in the source
6Name the rogue account left behind
7Map the credential theft to MITRE ATT&CK

Be first when it launches

Create your free account now. The moment this operation goes live on Jul 28, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free