Cards Collection

Browse all game cards by type

🎁

Bonus

Bonus Card

Advance by 2 spaces

đŸ›Ąī¸

Firewall

Defense System

Blocks Malware attacks but vulnerable to Backdoor exploits

đŸĻ 

Malware

Attack System

Exploits Backdoor vulnerabilities but stopped by Firewall

đŸšĒ

Backdoor

Stealth Entry

Bypasses Firewall protection but vulnerable to Malware

đŸ›Ąī¸

Firewall

Defense System

Blocks Malware attacks but vulnerable to Backdoor exploits

đŸĻ 

Malware

Attack System

Exploits Backdoor vulnerabilities but stopped by Firewall

đŸšĒ

Backdoor

Stealth Entry

Bypasses Firewall protection but vulnerable to Malware

đŸ›Ąī¸

Firewall

Defense System

Blocks Malware attacks but vulnerable to Backdoor exploits

đŸĻ 

Malware

Attack System

Exploits Backdoor vulnerabilities but stopped by Firewall

đŸšĒ

Backdoor

Stealth Entry

Bypasses Firewall protection but vulnerable to Malware

💀

Malus

Malus Card

Choose someone to go backward by 2 spaces

🔍

OSINT Challenge #2

Security Breach Investigation

Discover how this PC was unlocked without permission

OSINT Challenge Image

This PC has been unlocked by someone without permission. But how?

🔍

OSINT Challenge #3

Resort Identification

Identify the resort from this island photo

OSINT Challenge Image

This is a photo of a resort located on an island. What is the name of the resort?

🔍

OSINT Challenge #4

Document Dating

Find the publication date of this journal

OSINT Challenge Image

Give the publication date of this journal.

🔍

OSINT Challenge #1

Workplace Investigation

Find the complete workplace information of this person

OSINT Challenge Image

Give the Name, the City and the Street of the working place of this person.

🔍

OSINT Challenge #5

Artist Attribution

Identify the creator of this statue

OSINT Challenge Image

Who is the creator of this statue?

📧

Post Office Package

Avoid the Trap

Is this email legitimate or phishing?

From:

noreply@postoffice-info.com

Subject:

Your package requires address confirmation

Message:

Click here to confirm your delivery address.

Link shown:

postoffice-verify.com/address

Is this email legitimate or phishing?

🔐

Google Security Alert

Avoid the Trap

Is this email legitimate or phishing?

From:

security@google.com

Subject:

Unusual login detected

Message:

Hello, an unusual login has been detected on your account from Chicago. If this wasn't you, verify your activity through your account.

Link shown:

accounts.google.com

Real link:

accounts-google.com.security-check.com/

Is this email legitimate or phishing?

📱

Telecom Invoice

Avoid the Trap

Is this email legitimate or phishing?

From:

billing@telecom.com

Subject:

Your invoice for November

Message:

Attached PDF, file name: invoice_2025.pdf. No external links.

Attachment:

📎 invoice_2025.pdf

Is this email legitimate or phishing?

👤

Facebook Verification

Avoid the Trap

Is this email legitimate or phishing?

From:

security@facebookmail.com

Subject:

Account temporarily restricted

Message:

Your Facebook account has been temporarily restricted due to a report. Please verify your identity.

Link shown:

facebook.com/verify

Real link:

facebook.com.verify-support.fr

Is this email legitimate or phishing?

đŸ’ŧ

Tax Authority Notice

Avoid the Trap

Is this email legitimate or phishing?

From:

contact@irs.gov

Subject:

Information about your latest notice

Message:

Redirect to the official irs.gov portal via secure link.

Link shown:

irs.gov

Is this email legitimate or phishing?

đŸ“Ļ

Amazon Security Team

Avoid the Trap

Is this email legitimate or phishing?

From:

account@amazon.com

Subject:

Suspicious activity detected

Message:

Suspicious activity has been detected on your Amazon account. To verify your orders, access your customer area.

Link shown:

amazon-checkorder.net

Is this email legitimate or phishing?

đŸ’ŗ

PayPal Receipt

Avoid the Trap

Is this email legitimate or phishing?

From:

support@paypal.com

Subject:

Transaction verified: PayPal receipt

Message:

You often receive this type of email after a real purchase.

Is this email legitimate or phishing?

📸

Instagram Warning

Avoid the Trap

Is this email legitimate or phishing?

From:

security@instagram.com

Subject:

Account will be deactivated soon

Message:

Hello, your Instagram account will soon be deactivated due to a violation of the rules. Call this number if you think this is an error.

Attachment:

📎 Phone: +1 555 123 4567

Is this email legitimate or phishing?

đŸ›ī¸

Online Store Order

Avoid the Trap

Is this email legitimate or phishing?

From:

shop@onlinestore.com

Subject:

Problem with your order

Message:

Link to onlinestore.com

Link shown:

onlinestore.com

Attachment:

📎 Order_STORE.pdf.exe

Is this email legitimate or phishing?

đŸĻ

Bank Security Alert

Avoid the Trap

Is this email legitimate or phishing?

From:

alerts@yourbank.com

Subject:

Unusual payment detected

Message:

Your bank has detected an unusual payment. No action required if you recognize the transaction. Otherwise, visit your customer area. No link provided.

Is this email legitimate or phishing?

📧

Post Office Package

Avoid the Trap

Is this email legitimate or phishing?

From:

noreply@postoffice-info.com

Subject:

Your package requires address confirmation

Message:

Click here to confirm your delivery address.

Link shown:

postoffice-verify.com/address

Is this email legitimate or phishing?

🔐

Google Security Alert

Avoid the Trap

Is this email legitimate or phishing?

From:

security@google.com

Subject:

Unusual login detected

Message:

Hello, an unusual login has been detected on your account from Chicago. If this wasn't you, verify your activity through your account.

Link shown:

accounts.google.com

Real link:

accounts-google.com.security-check.com/

Is this email legitimate or phishing?

📱

Telecom Invoice

Avoid the Trap

Is this email legitimate or phishing?

From:

billing@telecom.com

Subject:

Your invoice for November

Message:

Attached PDF, file name: invoice_2025.pdf. No external links.

Attachment:

📎 invoice_2025.pdf

Is this email legitimate or phishing?

👤

Facebook Verification

Avoid the Trap

Is this email legitimate or phishing?

From:

security@facebookmail.com

Subject:

Account temporarily restricted

Message:

Your Facebook account has been temporarily restricted due to a report. Please verify your identity.

Link shown:

facebook.com/verify

Real link:

facebook.com.verify-support.fr

Is this email legitimate or phishing?

đŸ’ŧ

Tax Authority Notice

Avoid the Trap

Is this email legitimate or phishing?

From:

contact@irs.gov

Subject:

Information about your latest notice

Message:

Redirect to the official irs.gov portal via secure link.

Link shown:

irs.gov

Is this email legitimate or phishing?

đŸ“Ļ

Amazon Security Team

Avoid the Trap

Is this email legitimate or phishing?

From:

account@amazon.com

Subject:

Suspicious activity detected

Message:

Suspicious activity has been detected on your Amazon account. To verify your orders, access your customer area.

Link shown:

amazon-checkorder.net

Is this email legitimate or phishing?

đŸ’ŗ

PayPal Receipt

Avoid the Trap

Is this email legitimate or phishing?

From:

support@paypal.com

Subject:

Transaction verified: PayPal receipt

Message:

You often receive this type of email after a real purchase.

Is this email legitimate or phishing?

📸

Instagram Warning

Avoid the Trap

Is this email legitimate or phishing?

From:

security@instagram.com

Subject:

Account will be deactivated soon

Message:

Hello, your Instagram account will soon be deactivated due to a violation of the rules. Call this number if you think this is an error.

Attachment:

📎 Phone: +1 555 123 4567

Is this email legitimate or phishing?

đŸ›ī¸

Online Store Order

Avoid the Trap

Is this email legitimate or phishing?

From:

shop@onlinestore.com

Subject:

Problem with your order

Message:

Link to onlinestore.com

Link shown:

onlinestore.com

Attachment:

📎 Order_STORE.pdf.exe

Is this email legitimate or phishing?

đŸĻ

Bank Security Alert

Avoid the Trap

Is this email legitimate or phishing?

From:

alerts@yourbank.com

Subject:

Unusual payment detected

Message:

Your bank has detected an unusual payment. No action required if you recognize the transaction. Otherwise, visit your customer area. No link provided.

Is this email legitimate or phishing?

📧

Telecom Invoice

Avoid the Trap - Easy

Is this email legitimate or phishing?

From:

billing@telecom.com

Subject:

Your invoice for November

Message:

Attached PDF, file name: invoice_2025.pdf. No external links.

Attachment:

📎 invoice_2025.pdf

Is this email legitimate or phishing?

📧

Amazon Security

Avoid the Trap - Easy

Is this email legitimate or phishing?

From:

account@amazon.com

Subject:

Suspicious activity detected

Message:

Suspicious activity has been detected on your Amazon account. To verify your orders, access your customer area.

Link shown:

amazon-checkorder.net

Is this email legitimate or phishing?

📧

PayPal Receipt

Avoid the Trap - Easy

Is this email legitimate or phishing?

From:

support@paypal.com

Subject:

Transaction verified: PayPal receipt

Message:

You often receive this type of email after a real purchase.

Is this email legitimate or phishing?

📧

Post Office Package

Avoid the Trap - Medium

Is this email legitimate or phishing?

From:

noreply@postoffice-info.com

Subject:

Your package requires address confirmation

Message:

Click here to confirm your delivery address.

Link shown:

postoffice-verify.com/address

Is this email legitimate or phishing?

📧

Tax Authority

Avoid the Trap - Medium

Is this email legitimate or phishing?

From:

contact@irs.gov

Subject:

Information about your latest notice

Message:

Redirect to the official irs.gov portal via secure link.

Link shown:

irs.gov

Is this email legitimate or phishing?

📧

Instagram Warning

Avoid the Trap - Medium

Is this email legitimate or phishing?

From:

security@instagram.com

Subject:

Account will be deactivated soon

Message:

Hello, your Instagram account will soon be deactivated due to a violation of the rules. Call this number if you think this is an error.

Attachment:

📎 Phone: +1 555 123 4567

Is this email legitimate or phishing?

📧

Bank Alert

Avoid the Trap - Medium

Is this email legitimate or phishing?

From:

alerts@yourbank.com

Subject:

Unusual payment detected

Message:

Your bank has detected an unusual payment. No action required if you recognize the transaction. Otherwise, visit your customer area. No link provided.

Is this email legitimate or phishing?

📧

Google Security Alert

Avoid the Trap - Hard

Is this email legitimate or phishing?

From:

security@google.com

Subject:

Unusual login detected

Message:

Hello, an unusual login has been detected on your account from Chicago. If this wasn't you, verify your activity through your account.

Link shown:

accounts.google.com

Real link:

accounts-google.com.security-check.com/

Is this email legitimate or phishing?

📧

Facebook Verification

Avoid the Trap - Hard

Is this email legitimate or phishing?

From:

security@facebookmail.com

Subject:

Account temporarily restricted

Message:

Your Facebook account has been temporarily restricted due to a report. Please verify your identity.

Link shown:

facebook.com/verify

Real link:

facebook.com.verify-support.fr

Is this email legitimate or phishing?

📧

Online Store Order

Avoid the Trap - Hard

Is this email legitimate or phishing?

From:

shop@onlinestore.com

Subject:

Problem with your order

Message:

Link to onlinestore.com

Link shown:

onlinestore.com

Attachment:

📎 Order_STORE.pdf.exe

Is this email legitimate or phishing?

❓

Password Security

Technical Quiz

Answer the cybersecurity question

Which password is the most secure?

  • A. 123456
  • B. azerty
  • C. Soleil2025!
  • D. motdepasse
❓

HTTPS Security

Technical Quiz

Answer the cybersecurity question

What does the 🔒 icon in the address bar mean?

  • A. The site is fast
  • B. The site uses HTTPS
  • C. The site is official
  • D. The site has no ads
❓

Email Fraud Detection

Technical Quiz

Answer the cybersecurity question

Which element can indicate a fraudulent email?

  • A. An unknown address
  • B. An elegant font
  • C. A legitimate attachment
  • D. A complete signature
❓

Metadata in Files

Technical Quiz

Answer the cybersecurity question

What type of file can contain metadata revealing a location?

  • A. .pdf
  • B. .jpg
  • C. .zip
  • D. .csv
❓

Ransomware Definition

Technical Quiz

Answer the cybersecurity question

What is a ransomware?

  • A. A virus that spams
  • B. A virus that encrypts files
  • C. A virus that shows ads
  • D. A virus that steals passwords
❓

Firewall Purpose

Technical Quiz

Answer the cybersecurity question

What is the purpose of a firewall?

  • A. Delete viruses
  • B. Block or allow network traffic
  • C. Speed up internet connection
  • D. Backup data
❓

Phone Number Privacy

Technical Quiz

Answer the cybersecurity question

What is the main risk of posting your phone number publicly?

  • A. Battery drain
  • B. Spam + targeted attacks
  • C. Account deletion
  • D. Carrier blocking
❓

Wi-Fi Encryption

Technical Quiz

Answer the cybersecurity question

Which protocol encrypts communications on a secure Wi-Fi network?

  • A. WEP
  • B. WPA2
  • C. FTP
  • D. ARP
❓

SQL Injection

Technical Quiz

Answer the cybersecurity question

What type of attack exploits a vulnerability in web forms?

  • A. DDoS
  • B. Man-in-the-middle
  • C. SQL Injection
  • D. Sniffing
❓

Password Cracking

Technical Quiz

Answer the cybersecurity question

Which method tests password strength without knowing it?

  • A. Social engineering
  • B. Heuristic analysis
  • C. Bruteforce
  • D. Network reconnaissance
🔤

RIWLFEAL

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

RIWLFEAL

💡 Hint: Network security device

🔤

NYRPCTIEON

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

NYRPCTIEON

💡 Hint: Data protection method

🔤

SWASROPD

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

SWASROPD

💡 Hint: Authentication credential

🔤

HACEKR

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

HACEKR

💡 Hint: Cyber intruder

🔤

MLAAREW

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

MLAAREW

💡 Hint: Malicious software

🔤

GIHSNIHP

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

GIHSNIHP

💡 Hint: Email scam technique

🔤

KAOBRCDO

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

KAOBRCDO

💡 Hint: Hidden access point

🔤

UISVR

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

UISVR

💡 Hint: Self-replicating malware

🔤

NOARSWEM

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

NOARSWEM

💡 Hint: Encrypts files for money

🔤

VPN

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

VPN

💡 Hint: Virtual Private Network (already unscrambled - explain what it stands for!)

🔤

RIWLFEAL

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

RIWLFEAL

💡 Hint: Network security device

🔤

NYRPCTIEON

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

NYRPCTIEON

💡 Hint: Data protection method

🔤

SWASROPD

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

SWASROPD

💡 Hint: Authentication credential

🔤

HACEKR

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

HACEKR

💡 Hint: Cyber intruder

🔤

MLAAREW

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

MLAAREW

💡 Hint: Malicious software

🔤

GIHSNIHP

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

GIHSNIHP

💡 Hint: Email scam technique

🔤

KAOBRCDO

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

KAOBRCDO

💡 Hint: Hidden access point

🔤

UISVR

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

UISVR

💡 Hint: Self-replicating malware

🔤

NOARSWEM

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

NOARSWEM

💡 Hint: Encrypts files for money

🔤

VPN

Group Challenge

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

VPN

💡 Hint: Virtual Private Network (already unscrambled - explain what it stands for!)

🔤

SWASROPD

Group Challenge - Easy

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

SWASROPD

💡 Hint: Authentication credential

🔤

HACEKR

Group Challenge - Easy

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

HACEKR

💡 Hint: Cyber intruder

🔤

UISVR

Group Challenge - Easy

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

UISVR

💡 Hint: Self-replicating malware

🔤

RIWLFEAL

Group Challenge - Medium

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

RIWLFEAL

💡 Hint: Network security device

🔤

MLAAREW

Group Challenge - Medium

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

MLAAREW

💡 Hint: Malicious software

🔤

VPN

Group Challenge - Medium

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

VPN

💡 Hint: Virtual Private Network (already unscrambled - explain what it stands for!)

🔤

NYRPCTIEON

Group Challenge - Hard

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

NYRPCTIEON

💡 Hint: Data protection method

🔤

GIHSNIHP

Group Challenge - Hard

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

GIHSNIHP

💡 Hint: Email scam technique

🔤

KAOBRCDO

Group Challenge - Hard

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

KAOBRCDO

💡 Hint: Hidden access point

🔤

NOARSWEM

Group Challenge - Hard

First to unscramble this cyber term moves up, last player moves down

Scrambled Word:

NOARSWEM

💡 Hint: Encrypts files for money

đŸ”Ĩ

Expert Phishing Detection

Special Challenge - Expert

Advanced phishing detection - analyze carefully!

Difficulty: Hard

From:

noreply-update@microsoft.com

Subject:

Mandatory update of terms of service

Real link:

https://account.microsoft.com.security-policy.net

❓ Is this legitimate or dangerous?

đŸ”Ĩ

Password Strength Expert

Special Challenge - Expert

Which password is truly the strongest?

Difficulty: Hard

Which is really the strongest password?

  • A. &T4p9Lm!2
  • B. GreenButterflyHitsAWallIn2025
  • C. N!k0lA5-R00
  • D. %zF3-@Lp
đŸ”Ĩ

Social Engineering Attack

Special Challenge - Expert

Real enterprise threat scenario

Difficulty: Hard

A "technician" calls you: "We need to reset your MFA due to an issue. I'll send you a code, read it to me to validate."

📋 The call seems internal (company number displayed)

❓ Is this legitimate?

đŸ”Ĩ

Mixed Content Security

Special Challenge - Expert

Technical web security analysis

Difficulty: Hard

A website uses HTTPS, but loads an external script via HTTP.

📋 Main page: https:// | External script: http://

❓ Is this secure?

đŸ”Ĩ

Evil Twin WiFi

Special Challenge - Expert

Network security threat detection

Difficulty: Hard

Employee connects to "Company-Secure" (WPA2, normally no captive portal).

📋 Phone suddenly opens a login page like a captive portal

❓ Bug or security risk?

đŸ”Ĩ

Modern Malware Behavior

Special Challenge - Expert

Identify advanced malware characteristics

Difficulty: Hard

Which behavior indicates modern stealthy malware?

  • A. PC overheating
  • B. Screen flickering
  • C. No visible symptoms
  • D. Pop-ups appearing
đŸ”Ĩ

Technical Email Phishing

Special Challenge - Expert

Very tricky phishing detection

Difficulty: Hard

From:

support@paypal.com

Subject:

Security verification required

Link displayed:

https://paypal.com/security

Real link:

https://paypal.com.security-check.info

❓ Is this legitimate?

đŸ”Ĩ

MFA Authentication Logic

Special Challenge - Expert

Advanced authentication reasoning

Difficulty: Hard

A company replaces passwords with a 6-digit PIN + MFA application.

📋 Old: Long password only | New: Short PIN + MFA app

❓ Does this reduce security?

đŸ”Ĩ

RDP Network Exposure

Special Challenge - Expert

Server security assessment

Difficulty: Hard

A Windows server exposes port 3389 (RDP) on the Internet.

📋 Security measures: Long password, MFA enabled, Active firewall

❓ Is this sufficient?

đŸ”Ĩ

SSL Certificate Trust

Special Challenge - Expert

Expert certificate analysis

Difficulty: Hard

Banking site in HTTPS with valid certificate.

📋 Padlock OK, Valid certificate, Issuer: Let's Encrypt, No browser alert

❓ Is this sufficient proof the site is authentic?

đŸ”Ĩ

Expert Phishing Detection

Special Challenge - Expert

Advanced phishing detection - analyze carefully!

Difficulty: Hard

From:

noreply-update@microsoft.com

Subject:

Mandatory update of terms of service

Real link:

https://account.microsoft.com.security-policy.net

❓ Is this legitimate or dangerous?

đŸ”Ĩ

Password Strength Expert

Special Challenge - Expert

Which password is truly the strongest?

Difficulty: Hard

Which is really the strongest password?

  • A. &T4p9Lm!2
  • B. GreenButterflyHitsAWallIn2025
  • C. N!k0lA5-R00
  • D. %zF3-@Lp
đŸ”Ĩ

Social Engineering Attack

Special Challenge - Expert

Real enterprise threat scenario

Difficulty: Hard

A "technician" calls you: "We need to reset your MFA due to an issue. I'll send you a code, read it to me to validate."

📋 The call seems internal (company number displayed)

❓ Is this legitimate?

đŸ”Ĩ

Mixed Content Security

Special Challenge - Expert

Technical web security analysis

Difficulty: Hard

A website uses HTTPS, but loads an external script via HTTP.

📋 Main page: https:// | External script: http://

❓ Is this secure?

đŸ”Ĩ

Evil Twin WiFi

Special Challenge - Expert

Network security threat detection

Difficulty: Hard

Employee connects to "Company-Secure" (WPA2, normally no captive portal).

📋 Phone suddenly opens a login page like a captive portal

❓ Bug or security risk?

đŸ”Ĩ

Modern Malware Behavior

Special Challenge - Expert

Identify advanced malware characteristics

Difficulty: Hard

Which behavior indicates modern stealthy malware?

  • A. PC overheating
  • B. Screen flickering
  • C. No visible symptoms
  • D. Pop-ups appearing
đŸ”Ĩ

Technical Email Phishing

Special Challenge - Expert

Very tricky phishing detection

Difficulty: Hard

From:

support@paypal.com

Subject:

Security verification required

Link displayed:

https://paypal.com/security

Real link:

https://paypal.com.security-check.info

❓ Is this legitimate?

đŸ”Ĩ

MFA Authentication Logic

Special Challenge - Expert

Advanced authentication reasoning

Difficulty: Hard

A company replaces passwords with a 6-digit PIN + MFA application.

📋 Old: Long password only | New: Short PIN + MFA app

❓ Does this reduce security?

đŸ”Ĩ

RDP Network Exposure

Special Challenge - Expert

Server security assessment

Difficulty: Hard

A Windows server exposes port 3389 (RDP) on the Internet.

📋 Security measures: Long password, MFA enabled, Active firewall

❓ Is this sufficient?

đŸ”Ĩ

SSL Certificate Trust

Special Challenge - Expert

Expert certificate analysis

Difficulty: Hard

Banking site in HTTPS with valid certificate.

📋 Padlock OK, Valid certificate, Issuer: Let's Encrypt, No browser alert

❓ Is this sufficient proof the site is authentic?

đŸ”Ĩ

Expert Phishing Detection

Special Challenge - Expert

Advanced phishing detection - analyze carefully!

Difficulty: Hard

From:

noreply-update@microsoft.com

Subject:

Mandatory update of terms of service

Real link:

https://account.microsoft.com.security-policy.net

❓ Is this legitimate or dangerous?

đŸ”Ĩ

Password Strength Expert

Special Challenge - Expert

Which password is truly the strongest?

Difficulty: Hard

Which is really the strongest password?

  • A. &T4p9Lm!2
  • B. GreenButterflyHitsAWallIn2025
  • C. N!k0lA5-R00
  • D. %zF3-@Lp
đŸ”Ĩ

Social Engineering Attack

Special Challenge - Expert

Real enterprise threat scenario

Difficulty: Hard

A "technician" calls you: "We need to reset your MFA due to an issue. I'll send you a code, read it to me to validate."

📋 The call seems internal (company number displayed)

❓ Is this legitimate?

đŸ”Ĩ

Mixed Content Security

Special Challenge - Expert

Technical web security analysis

Difficulty: Hard

A website uses HTTPS, but loads an external script via HTTP.

📋 Main page: https:// | External script: http://

❓ Is this secure?

đŸ”Ĩ

Evil Twin WiFi

Special Challenge - Expert

Network security threat detection

Difficulty: Hard

Employee connects to "Company-Secure" (WPA2, normally no captive portal).

📋 Phone suddenly opens a login page like a captive portal

❓ Bug or security risk?

đŸ”Ĩ

Modern Malware Behavior

Special Challenge - Expert

Identify advanced malware characteristics

Difficulty: Hard

Which behavior indicates modern stealthy malware?

  • A. PC overheating
  • B. Screen flickering
  • C. No visible symptoms
  • D. Pop-ups appearing
đŸ”Ĩ

Technical Email Phishing

Special Challenge - Expert

Very tricky phishing detection

Difficulty: Hard

From:

support@paypal.com

Subject:

Security verification required

Link displayed:

https://paypal.com/security

Real link:

https://paypal.com.security-check.info

❓ Is this legitimate?

đŸ”Ĩ

MFA Authentication Logic

Special Challenge - Expert

Advanced authentication reasoning

Difficulty: Hard

A company replaces passwords with a 6-digit PIN + MFA application.

📋 Old: Long password only | New: Short PIN + MFA app

❓ Does this reduce security?

đŸ”Ĩ

RDP Network Exposure

Special Challenge - Expert

Server security assessment

Difficulty: Hard

A Windows server exposes port 3389 (RDP) on the Internet.

📋 Security measures: Long password, MFA enabled, Active firewall

❓ Is this sufficient?

đŸ”Ĩ

SSL Certificate Trust

Special Challenge - Expert

Expert certificate analysis

Difficulty: Hard

Banking site in HTTPS with valid certificate.

📋 Padlock OK, Valid certificate, Issuer: Let's Encrypt, No browser alert

❓ Is this sufficient proof the site is authentic?

} else { answerDiv.classList.add('hidden'); button.textContent = 'Show Answer'; button.classList.remove('bg-gray-600', 'hover:bg-gray-700', 'dark:bg-gray-500', 'dark:hover:bg-gray-600'); button.classList.add('bg-blue-600', 'hover:bg-blue-700', 'dark:bg-blue-500', 'dark:hover:bg-blue-600'); } }