awesome-repositories.com
Blog
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Orange-Cyberdefense avatar

Orange-Cyberdefense/GOAD

0
View on GitHub↗
7,464 Stars·1,030 Forks·PowerShell·gpl-3.0·4 Aufrufe

GOAD

GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors.

The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including vulnerable Active Directory environments, Exchange servers, and SCCM setups, while allowing for custom lab extensions and tiered inventory overrides to adapt the environment to specific provider settings.

Broad capabilities include the provisioning of blue team monitoring stacks with EDR solutions and centralized logging for security event analysis. It also provides network access utilities such as SSH jumpboxes and SOCKS proxies to route attack traffic into isolated segments, and simulates specific security challenges like database impersonation and access control list manipulation.

Features

  • Vulnerable Lab Environments - Provisions a pre-configured network of Windows virtual machines with intentional Active Directory misconfigurations.
  • Simulation Recipes - Provides a collection of infrastructure recipes for simulating misconfigured Active Directory environments.
  • Red Team and Offensive Security - Creates intentional security misconfigurations and attack scenarios for training professionals in offensive security.
  • Security Labs and Practice - Provides automated deployment of complex virtual networks and target machines for hands-on security training.
  • Vulnerable Training Environments - Provisions targeted networks with intentional vulnerabilities to practice privilege escalation and lateral movement.
  • Virtual Machine Provisioning - Automates the creation and configuration of Windows virtual machines across various hypervisors and cloud platforms.
  • Ansible Modules - Uses Ansible modules and playbooks to orchestrate the deployment of vulnerable virtual machine networks.
  • Vulnerable Infrastructure - Sets up networks of virtual machines with known weaknesses for security research and penetration testing practice.
  • Automated Provisioning - Automates the deployment of pre-configured networks of Windows virtual machines using Ansible playbooks.
  • Active Directory Attacks - Provides vulnerable Windows environments specifically designed to practice Active Directory attack vectors.
  • Blue Team and Defensive Security - Deploys EDR and log aggregation stacks to simulate blue team detection and response operations.
  • Endpoint Security - Configures workstations with restrictions like blocked LSASS stealing to emulate a hardened endpoint environment.
  • Infrastructure Provisioning Recipes - Defines infrastructure requirements as modular recipes combining virtual machine specifications with sequential configuration tasks.
  • Provider Abstractions - Decouples infrastructure logic from specific hypervisors and cloud platforms using a common set of configuration templates.
  • Deployment Configuration - Allows tailoring the environment by configuring the virtualization provider, IP range, and deployment method.
  • Extensible Provider Frameworks - Allows integrating new virtualization or cloud platforms via provider classes and configuration templates.
  • Multi-Cloud Orchestrators - Orchestrates the deployment of security testing environments across various cloud platforms and local hypervisors.
  • Tiered Configuration Inventories - Organizes network and host variables in a hierarchy to allow provider-specific overrides of global settings.
  • Email Server Simulations - Allows adding resource-heavy Windows machines to simulate vulnerable Exchange email servers.
  • Lab Scaling Options - Provisions pre-configured networks of Windows virtual machines in varying sizes to simulate diverse AD environments.
  • Lab Topology Definitions - Enables specifying virtual machine groups and networking variables to build custom vulnerable network topologies.
  • Lightweight Lab Profiles - Provisions a minimal Active Directory environment with a reduced memory footprint.
  • SCCM Simulation Labs - Provisions a network including a domain controller and SQL server to practice attacks against SCCM.
  • Service Exploitation Labs - Provides virtual machines running MSSQL and IIS to practice impersonation and trusted link attacks.
  • Targeted Attack Scenarios - Sets up specialized environments, including configuration management systems, to practice specific exploitation techniques.
  • Functional Network Topologies - Builds complex network topologies by grouping virtual machines into functional roles like domain controllers and workstations.
  • Access Control Lists - Allows testing privilege escalation and permission abuse by modifying misconfigured user and group access rights.
  • EDR Deployments - Installs a security monitoring server and deploys agents to all domain computers to detect and respond to threats.
  • Simulated Vulnerabilities - Provisions users and groups with specific ACL vulnerabilities to practice privilege escalation.
  • Centralized Logging Systems - Provisions a centralized Kibana instance to collect and visualize security events occurring across the network.
  • Lab Environments - Provides optional installation playbooks to add specialized services and security tools to the lab environment.
  • Lab Instance Automation - Automates the creation of dedicated folders containing the recipes, configuration files, and keys needed to launch a network.
  • Security Event Monitoring - Integrates EDR and log aggregation tools to visualize security alerts and analyze system logs during attacks.
  • Vulnerable Environments - Lab environment for practicing Active Directory attacks.
  • Security Lab Environments - Automated lab environment for testing Active Directory attacks.
  • Vulnerable Systems and Mobile - Vulnerable Active Directory lab for practicing attack techniques.
  • Vulnerability Labs - Active Directory lab environment for practicing attack techniques.

Star-Verlauf

Star-Verlauf für orange-cyberdefense/goadStar-Verlauf für orange-cyberdefense/goad

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Open-Source-Alternativen zu GOAD

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit GOAD.
  • digininja/dvwaAvatar von digininja

    digininja/DVWA

    13,229Auf GitHub ansehen↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    Auf GitHub ansehen↗13,229
  • rapid7/metasploitable3Avatar von rapid7

    rapid7/metasploitable3

    5,592Auf GitHub ansehen↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    Auf GitHub ansehen↗5,592
  • stamparm/maltrailAvatar von stamparm

    stamparm/maltrail

    8,498Auf GitHub ansehen↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    Auf GitHub ansehen↗8,498
  • madhuakula/kubernetes-goatAvatar von madhuakula

    madhuakula/kubernetes-goat

    5,686Auf GitHub ansehen↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    Auf GitHub ansehen↗5,686
Alle 30 Alternativen zu GOAD anzeigen→

Häufig gestellte Fragen

Was macht orange-cyberdefense/goad?

GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors.

Was sind die Hauptfunktionen von orange-cyberdefense/goad?

Die Hauptfunktionen von orange-cyberdefense/goad sind: Vulnerable Lab Environments, Simulation Recipes, Red Team and Offensive Security, Security Labs and Practice, Vulnerable Training Environments, Virtual Machine Provisioning, Ansible Modules, Vulnerable Infrastructure.

Welche Open-Source-Alternativen gibt es zu orange-cyberdefense/goad?

Open-Source-Alternativen zu orange-cyberdefense/goad sind unter anderem: rapid7/metasploitable3 — Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with… digininja/dvwa — DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws.… stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… madhuakula/kubernetes-goat — Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of… fireeye/flare-vm — Flare-VM is a collection of scripts and an orchestrator designed to automate the installation and configuration of a… hmaverickadams/beginner-network-pentesting — This is a hands-on lab environment for learning network penetration testing techniques, centered on setting up and…