The planned scenario

A hosting provider combines its own operational surface with the applications it hosts for customers. This scenario makes that distinction visible through a provider portal, hosted storefront, support, administration, a legacy application facade, and service status. The private model includes a provider API and backup storage context.

The breadth of public routes suits an inventory and responsibility exercise. A customer site, support attachment, and administrative page may share an entry point while representing different owners and access expectations. Identify those differences and test the boundaries configured for the exercise.

Public surfaces

These reference routes describe possible entry points in the scenario model. They are not live customer services or a guarantee of the routes in a particular product release. Use your configured exercise inventory as the authoritative scope.

Public routes declared in the Hosting Provider catalog
RouteSurfaceContext
/provider-portalMain customer and provider account portal.
/shophosted-shopHosted customer storefront simulation.
/supportsupport-deskSupport tickets, uploads, and customer context.
/adminadmin-consoleProvider administrative surface.
/legacylegacy-appLegacy customer application facade.
/statusstatus-apiPublic status and health API simulation.

Private systems

These service names and segments describe the internal context of Hosting Provider. They help define exercise boundaries and interpret the generated records.

internal-api

Private provider API in app subnets. Catalog segment: private application.

backup-store

Private backup and artifact storage path. Catalog segment: private data.

Configure your exercise

Choose a question for the assignment and define the evidence participants should collect.

  • Which routes represent the provider itself, and which represent hosted customer activity?
  • Where could support or backup context reveal a relationship between otherwise separate tenants?
  • How should the administrative and legacy surfaces be inventoried alongside the normal customer portal?

What to hand in

Produce an ownership aware surface inventory and observed exposure record. Distinguish tenant context, provider administration, backup artifacts, and development artifacts instead of reporting them as one undifferentiated application.

Records and evidence

Tenants and hosted sites define the customer population. Support tickets, backups, status events, and development artifacts add operational context. Use the selected tier and run outputs to establish the artifact inventory before reviewing provider and tenant boundaries.

  • tenants
  • support-tickets
  • hosted-sites
  • backups
  • status-events
  • dev-artifacts

Preserve the scenario and product version, the record or observation, and its source with each finding. Distinguish what a participant observed from what the reviewer inferred. Use synthetic data and your defined evidence-retention rules.

Public self-service at launch

Managed Verse is planned for 1 January 2027. Users will create an account, choose a scenario and configure their own authorized exercise boundaries. Vulnverse will host and operate the platform and cloud; users will not need to provision or maintain an exercise cloud.

Managed Verse is planned to replace all previous services. All new inquiries are paused during the transition. Read Managed Verse →.