Cybersecurity practitioners are often warned about the dangers lurking beneath the surface. But what happens when that threat turns out to be real? Varonis Threat Labs researchers Doron Kapah and Mark Vaitsman have faced this reality firsthand, dealing with data exfiltration in cloud-native environments. Their experience inspired them to create Breach at the Beach, a unique Entra ID training experience that simulates a breach in identity management.
Varonis’ threat-detecting cat, Pixel, is on a beach vacation when she discovers a breach in Entra ID and switches to investigator mode. Players take on the role of investigators, tracing the steps of a threat actor through Pixel’s systems to uncover what sensitive data they’re after. The goal is to stop them before it’s too late.
But why Entra ID? This identity provider isn’t just a simple authentication system; it’s the control plane for an entire enterprise, connecting users, applications, and permissions. With the rise of non-human identities – AI agents, service principals, automated workflows – a compromise in Entra ID can look very different from traditional attacks.
“A lot of identities are non-human identities,” says Mark Vaitsman, Security Research Team Leader at Varonis. “If there is a compromise in Entra, a threat actor can pivot themselves into a non-human identity, and it can quickly turn into a stealthy and scalable data exfiltration attempt.” This scenario reflects real cases that Doron and Mark have encountered firsthand, making each challenge a lesson grounded in what defenders are up against today.
Organizations face a difficult balance between adopting AI quickly and keeping security infrastructure up-to-date. Non-human identities are rapidly outgrowing human ones, expanding the attack surface as a result. Threat actors can gain and scale access while creating major challenges for monitoring and detection. “We’re caught between the pressure to adopt AI and our ability to keep pace with it,” says Doron.
Breach at the Beach is an online CTF (capture the flag) experience designed to teach players how modern attacks work in Entra ID. It’s free, available now, and can be played by anyone looking to learn about data exfiltration. By completing Breach at the Beach, players will gain hands-on experience with real-world challenges.
The creators deliberately avoided AI assistance, instead focusing on teaching players to recognize legitimate functionality being weaponized and how to detect threats without relying on machine learning. The goal is not just to solve challenges quickly but to absorb the lessons embedded in the experience.
Hands-on learning gives defenders real-world practice, says Mark Vaitsman. “You understand nothing if you’re not hands-on the keyboard, clicking around, and seeing how it works. Reading is not enough.” CTF experiences like Breach at the Beach help players feel the impact of a breach, not just understanding it conceptually.
If you’re on a red team, blue team, or simply looking to gain CPE credits, this is your chance to learn by doing. So grab your beach towel and get ready to investigate Pixel’s systems – before it’s too late!
Source: Bleeping Computer — 2026-07-13