Cheat sheets - For the game master's eyes only

This page is to help the game master with running the Azure Cloud Castle game.

Game rules

Prerequisites:

  • A OWASP Cornucopia card deck. Both Website App Edition and Ecommerce Edition can be used.
  • A dice. Any dice will do.
  • A computer
  • A list of qr codes that takes the player to the page presenting the characters of the game.

As a game master, you start by showing a list of qr codes to each of the players, the player scans the qr code which takes them to a character page. This is much faster and funnier then having the players read through the whole list of characters and may also make it more enjoyable in case you have played the game before.

Deal out all the OWASP Cornucopia cards.

Once everyone has a character, get them to present themselves. This way, everyone knows about each others abilities, skills and spells.

You select "Azure Cloud Castle" from the games meny and start to read the plot of the game. If you have a projector, you can open the game in two windows. Project one window to the participants in order to display the images to them and use a separate window to read the plot. Alternatively, you can tell each of the participants to follow the story on their own laptop and tell them what to do.

After reading the plot, the players are presented with 1-4 choices. They can "cast a spell", "use a weapon", "throw the dice" or "use a card". All options are not always available. The players are not told which option is the best. You, as a game master, keep track on whether the choices the player make are valid or not.

Free yourself from the story and improvise if the players come up with interesting solutions and choices. Just make sure to lead them back to the story so that you don't diverge too far from the storyline.

Once you have played the game a couple of times, you can also play the game infront of an audience. If so, dress up as your favorite character for the event.

Rolling the dice

For simplicity you can use any type of dice. Say you use a dice with six edges (1-6). When the player throw the dice, if they get 1-3, then that would be a "low roll" and if they get 4-6, then that would be a "high roll". If you play with a dice with more edges just divide the possible edges that the dice can land on into low and high in a similar fashion. The game master can decide what a "high roll" and what a "low roll" is meant to be. Just make sure that you clarify this before starting the game.

Easter eggs:

Encourge the players to click on the links in the text. They contain easter eggs related to cybersecurity.

The game chapters

This is the complete list of link to pages that you are taken two given the choices presented at a specific chapter in the game.

Provided by Johan Sydseter

OWASP® Dungeons & Daemons

OWASP Dungeons & Daemons is originally created by Johan Sydseter. It is open source and can be downloaded free of charge from the OWASP website. It is is free to use. It is licensed under the Creative Commons Attribution-ShareAlike 4.0 International, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. OWASP does not endorse or recommend commercial products or services. OWASP Dungeons & Daemons is licensed under the Creative Commons Attribution-ShareAlike 4.0 International license and is © 2024 OWASP Foundation.