Guides

Breach at the Beach: Ultimate Entra ID CTF

July 14, 2026 12:13 · 12 min read
Breach at the Beach: Ultimate Entra ID CTF

Breach at the Beach: Play the Ultimate Entra ID CTF

Cybersecurity can be likened to the ocean, with a sense of calm on the surface but unknown threats lurking underwater. Varonis Threat Labs researchers Doron Kapah and Mark Vaitsman aimed to create an Entra ID training experience that gives security practitioners firsthand knowledge of data exfiltration in Entra ID.

Thus, Breach at the Beach was born. The game follows Pixel, Varonis' threat-detecting cat, as she investigates a breach in Entra ID. Players trace the threat actor's steps to uncover what sensitive data the attacker is after, hoping to stop them before it's too late.

Why Entra ID?

Entra ID is not just an identity provider; it's the control plane for the entire enterprise, connecting users, applications, permissions, automation, and AI-powered workflows. The rise of non-human identities, such as AI agents and service principals, has changed what a compromise in Entra ID can look like.

In today's AI era, a lot of identities are non-human identities. If there is a compromise in Entra, a threat actor can pivot themselves into a non-human identity, and it can quickly turn into a stealthy and scalable data exfiltration attempt.

Doron Kapah, Security Researcher at Varonis, highlights that non-human identities are rapidly outgrowing human identities, expanding the attack surface and creating major challenges for monitoring and detection.

Breach at the Beach: The Ultimate Entra ID CTF

Breach at the Beach is a free, online capture-the-flag (CTF) challenge that teaches players about modern attacks in Entra ID. The game is designed to give defenders a hands-on experience, showing what modern attacks look like and how to detect threats without AI assistance.

Players learn to recognize when legitimate functionalities are being weaponized, how to eliminate noise in raw Entra logs, and how to create their own clarity in complex environments. The CTF experience helps players feel the impact of a breach, rather than just understanding it conceptually.

Lessons Learned

Mark Vaitsman, Security Research Team Leader at Varonis, emphasizes the importance of hands-on learning, stating, You understand nothing if you are not hands-on the keyboard, clicking around, and seeing how it works. Reading is not enough.

Built for All Cybersecurity Professionals

Breach at the Beach is designed for all cybersecurity professionals, including red teamers, blue teamers, CISOs, threat intelligence roles, and more. The game provides a chance to learn about Entra ID, AI, and auditing visibility gaps, helping to identify any gaps that may be missing.

Completing the CTF awards players with 1 CPE credit and a themed badge. Once all four stages are complete, players receive a certificate of completion to share on LinkedIn. Breach at the Beach is available to play online at https://breachatthebeach.com.

Doron and Mark will be attending Black Hat USA and DEF CON 34, where they will elaborate on how the CTF was built and help players through the exercise in person. Find the details for those events at the Varonis booth (#2948) at Black Hat USA and in the Cloud Village at DEF CON 34.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free