3 مستودعات
Virtualization environments intentionally configured with security weaknesses for research and testing.
Distinct from Virtual Machine Deployment: Focuses on the intentional vulnerability of the infrastructure rather than generic deployment of virtual machines.
Explore 3 awesome GitHub repositories matching devops & infrastructure · Vulnerable Infrastructure. Refine with filters or upvote what's useful.
GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including
Sets up networks of virtual machines with known weaknesses for security research and penetration testing practice.
Metasploitable3 هو موفر أجهزة افتراضية (VM) مؤتمت مصمم لبناء ونشر صور نظام التشغيل مع نقاط ضعف أمنية متعمدة. يعمل كمختبر لاختبار الاختراق من خلال إنشاء أهداف أجهزة افتراضية ضعيفة تُستخدم للتدريب الأمني، وتطوير الاستغلال، والتحقق من أدوات الأمان. يستخدم النظام نصوص تكوين برمجية لحقن الثغرات في بيئات Windows وLinux. يتضمن ذلك نشر تطبيقات وخدمات غير آمنة، مثل خوادم الويب وقواعد البيانات، وتطبيق أذونات نظام مهيأة بشكل خاطئ لمحاكاة عيوب البرمجيات في العالم الحقيقي. يدير المشروع عملية توفير البيئة من خلال أدوات التنسيق وإدارة التكوين. تسمح هذه الأدوات بإنشاء سيناريوهات أمنية قابلة للتكرار عبر منصات افتراضية مختلفة من خلال الجمع بين الصور الأساسية والنصوص البرمجية التي تقدم ثغرات محددة.
Provisions virtualization environments that are intentionally configured with security weaknesses.
هذا المشروع عبارة عن منصة لالتقاط العلم (CTF) وبيئة تدريب على الأمن السيبراني. يوفر إطار عمل لنشر تحديات الأمان وتتبع تقدم المشاركين من خلال لوحة صدارة تسجيل النقاط في الوقت الفعلي. تعمل المنصة كنظام لوحة صدارة وإدارة لمسابقات الأمان، حيث تستضيف بنية تحتية ضعيفة عمداً لممارسة الهندسة العكسية وتقنيات استغلال البرمجيات. وتدير اكتشاف السلاسل السرية داخل هذه الألغاز لتحديد تصنيفات الفرق. يغطي النظام إدارة مسابقات الأمن السيبراني، ونشر تحديات الأمان، والتدريب على أبحاث الثغرات الأمنية. ويستخدم نظام تتبع لمراقبة إجمالي النقاط بناءً على عدد تحديات الأمان التي تم حلها.
Provides intentionally vulnerable infrastructure configured with security weaknesses for research and competition testing.