ARMO CTRL (Cloud Threat Readiness Lab) is a free tool that helps you test your cloud security tools by deploying a safe, controlled attack lab that mimics real attack behaviors end-to-end. Unlike other attack simulations, CTRL starts with a web exploit and then pivots deeper into your cloud environment to simulate how real attacks move.
CTRL runs curated attack scenarios against deliberately vulnerable sample services that model realistic flaws; for example, command injection, local file inclusion (LFI), server-side request forgery (SSRF), and SQL injection. The goal is not to “find a bug,” but to validate whether your cloud and container controls detect, alert, and prevent as designed.