Computer & Information Sciences
Cyber Security Challenges
Real cyber-security challenges on Ewance — assess risk, harden systems, and respond to threats the way a working security professional does. Solve them to build a portfolio of verified, recruiter-checkable proof you can do the work — not just describe it.
Recommended challenges
- ResearchSeniorNew
Audit a Custom Cryptographic Protocol
Read the 22-page protocol spec, the Go reference implementation (around 4,000 lines), and the test vectors. Run a structured review covering: primitive choices (which cipher, MA…
- Applied Cryptography
- Cryptographic Audit
- Protocol Analysis
Applied Cryptography - AnalysisIntermediateNew
Run a Red-Team Exercise on a Cloud-Native Microservices Platform
Receive a scoped engagement letter (in-scope: 6 microservices and their CI/CD pipelines; out-of-scope: customer-data exfiltration beyond proof-of-access), the architecture diagr…
- Red Teaming
- Kubernetes Security
- Lateral Movement
Computer Systems Security - CodeSeniorNew
Tune an Intrusion-Detection Rule Pack for Manufacturing PLCs
Work entirely from the five provided materials. Using the packet captures (M1) and the labeled event manifest (M2), characterize normal Modbus/TCP and Ethernet/IP behavior for t…
- Intrusion Detection
- Ics Security
- Suricata
Open coursework - CodeSeniorNew
Build a Kernel-Module Sandbox for an Untrusted Code Service
Receive the current Docker-based sandbox configuration, post-incident reports for both escapes, and the runtime requirements for Python and C++ (compilers, package availability,…
- Sandboxing
- Seccomp Bpf
- Gvisor
Computer Systems Security Practice your coursework on real scenarios.
Every challenge is shaped from real-world context — not generic exercises. The work mirrors what your degree prepares you for.
Why Ewance
- DesignIntermediateNew
Detect and Defend a Government Portal Against Application-Layer DDoS
Working only from the provided incident log sample, architecture overview, and prior-incident case file, design a layered defense and prove it holds up under simulation. Build s…
- Ddos Defense
- Detection Engineering
- Waf
Open coursework - AnalysisIntermediateNew
Clear a Fortune-100 Privacy Review for an HR-Tech Vendor
Using the product fact-sheet, the stakeholder interview notes, the buyer's 14-concern brief, and the official texts of the General Data Protection Regulation and the EU Artifici…
- Compliance
- Privacy Regulation
- GDPR
Open coursework - CodeIntermediateNew
Static Analysis SAST Rollout on a Fintech Codebase
Run baseline scans with Semgrep + SonarQube + Snyk Code across all 18 services. Triage the initial findings (likely 800-1,500 raw alerts) into true-positive / false-positive / i…
- Sast
- Semgrep
- Sonarqube
Open coursework - DesignIntermediateNew
Author a SOC 2-Ready Incident Response Playbook for Kestrel Pay
Using the Kestrel Pay company dossier and the current pinned-message 'playbook' (both provided), author a four-phase playbook — Prepare, Detect & Analyze, Contain/Eradicate/Reco…
- Incident Response
- NIST Sp 800 61
- Security Governance
Open coursework - Browse challenges
Explore role
Product Manager
Ship product that solves real user problems. Combine user research, prototyping, and stakeholder alignment to turn ambiguous briefs into measurable wins — the role at the centre of modern software teams.
- AnalysisIntermediateNew
Privacy-by-Design Review for a Smart-City Data Platform
Map the new module's end-to-end data flow (sensors -> ingestion -> analytics -> dashboards -> exports). Run a Privacy Impact Assessment against OECD privacy principles + per-ten…
- Privacy By Design
- Privacy Regulation
- Compliance
Information Security Management and Governance - AnalysisBeginnerNew
GDPR Article 25 Privacy-By-Design Review for a HealthTech API
Review the API specification (OpenAPI 3, provided, 42 endpoints). For each endpoint: identify data categories handled (special-category health data, identifiers, traffic data), …
- GDPR
- Privacy By Design
- API Design
Privacy-Enhancing Technologies - DesignIntermediateNew
Design a Secure-by-Default IoT Device Provisioning Flow
Design end-to-end provisioning: factory bootstrap (per-device key pair burned at manufacture), installer flow (BLE-driven activation, Wi-Fi handoff), cloud-side enrollment (mTLS…
- Iot Security
- Secure Provisioning
- Mutual Tls
Cyber-Physical and Cybercrime Topics - AnalysisSeniorNew
Forensic Reconstruction of an Anonymized Energy-Grid Incident
Treat this as a case file and work timeline-first. From the incident intake record (intake-file), establish the known facts and the 19-minute window. Reconcile the remote-termin…
- Digital Forensics
- Incident Response
- Ics Security
Open coursework Build a verifiable portfolio.
Submissions become evidence. Reviewers with shipping experience score against a rubric; the result becomes a credential anyone can verify.
Why Ewance
- CodeIntermediateNew
Harden a Linux Container Runtime Against Privilege Escalation
Receive the pen-test report (with attack chain), the current cluster config (EKS 1.29, default Amazon Linux 2023 worker nodes), and 3 representative workload classes (web API, a…
- Os Security
- Linux Hardening
- Apparmor
Open coursework - DesignIntermediateNew
Threat-Model and Hardening Proposal for a Whistleblower Intake
Using the current-stack dossier and the CTO mandate brief, build a threat model of the existing intake using the LINDDUN privacy-threat framework (linkability, identifiability, …
- Anonymous Communication
- Threat Modeling
- Tor
Open coursework - AnalysisBeginnerNew
Exploit and Remediate Eight Web Flaws on a FinTech Practice Range
Using the eight challenge specifications in the provided challenge specification brief and the representative Rails module in the provided vulnerable application source bundle (…
- Web Security
- OWASP Top 10
- Penetration Testing
Open coursework - ResearchBeginnerNew
Ransomware Underwriting Brief for a Zurich Cyber Insurer
Using the underwriting mandate brief, the initial-access listing sample, the Ransomware.live tracker, and the public CISA cybersecurity advisories provided, produce a quarterly …
- Threat Intelligence
- Cybercrime Economy
- Ransomware
Open coursework - AnalysisIntermediateNew
Build a Risk Register for a Cross-Border Healthcare Provider
Run 8 structured interviews (CISO, IT director, clinical-systems lead, DPO, 4 clinic managers) to surface the top risk candidates. Map each risk against NIST SP 800-30 (threat s…
- Risk Management
- NIST Sp 800 30
- Security Governance
Open coursework - CodeSeniorNew
Implement Threshold Signatures for a Multi-Sig Custody Service
Read the FROST IETF draft (draft-irtf-cfrg-frost) and the underlying Schnorr signature scheme on the secp256k1 curve. Implement the FROST distributed key generation (DKG) and 3-…
- Applied Cryptography
- Threshold Signatures
- Rust
Open coursework - DesignIntermediateNew
Passive Intrusion Detection for an Auto Supplier's Plant Network
Using the provided plant network diagram, design a passive (listen-only) sensor architecture that pairs Zeek and Suricata at the office-to-factory boundary plus three production…
- Intrusion Detection
- Ot Security
- Zeek
Open coursework - AnalysisIntermediateNew
Privacy Posture Review of a Fintech's Internal Service Mesh
Work only from the four supplied materials: the anonymized service inventory, the sample east-west traffic flow records, the current mesh policy export, and the public Istio sec…
- Network Privacy
- Mtls
- Service Mesh
Open coursework - DesignSeniorNew
Design an End-to-End Encrypted Messaging Protocol for Clinicians
Using the Vireo current-architecture case file and the Signal protocol specifications listed in provided materials, design an end-to-end encrypted messaging protocol that covers…
- Applied Cryptography
- Protocol Design
- Rust
Open coursework - CodeIntermediateNew
Secure the Software Supply Chain of an Open-Source SDK
Audit the current state: dependency tree, publish process, GitHub Actions workflows, signing posture. Generate an SBOM (CycloneDX format) using Syft. Run OpenSSF Scorecard and t…
- Supply Chain Security
- Slsa
- Sbom
Open coursework - CodeIntermediateNew
Implement Federated Learning for a Government Statistics Office
Use Flower as the FL framework. Simulate 8 municipalities each with a partition of a synthetic wage dataset (provided, 1M rows, EU-Labour-Force-Survey schema). Train a gradient-…
- Federated Learning
- Differential Privacy
- Python Programming
Privacy-Enhancing Technologies - AnalysisIntermediateNew
Secure-by-Design Review of a Microservices Auth Subsystem
Read the 18-page proposed auth-service design (Next.js BFF, FastAPI auth-service, Postgres for sessions + refresh, Redis for short-lived tokens, integration with Auth0 for OIDC)…
- Secure Design
- OWASP Asvs
- Oauth2
Software Security
How it works
From brief to credential, in six steps.
Step 01
Browse challenges aligned to your studies.
Step 02
Accept the one that fits your goals.
Step 03
Work through it with AI Copilot guidance.
Step 04
Submit for structured evaluation.
Step 05
Earn a verified credential.
Step 06
Add it to LinkedIn with one click.
Industry teams behind a decade of practitioner briefs
Hiring from this pool?
Sponsor a challenge and meet candidates through actual work.
Industry teams can shape briefs around the skills they hire for, then evaluate students on rubric-scored deliverables — not resumes.



















































































