For entorno en la nube intencionalmente vulnerable para prácticas, the strongest matches are orange-cyberdefense/goad (GOAD deploys intentionally vulnerable Windows networks for Active Directory), splunk/attack_range (Attack Range is a cybersecurity breach simulation framework that) and rhinosecuritylabs/cloudgoat (CloudGoat is a purpose-built tool for deploying intentionally vulnerable). Each is ranked by relevance to your query, popularity and recent activity.
Descubre plataformas en la nube de código abierto diseñadas para practicar pruebas de penetración e identificar configuraciones de seguridad erróneas comunes.
GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including
GOAD deploys intentionally vulnerable Windows networks for Active Directory penetration testing across multiple cloud platforms and hypervisors, providing automated provisioning and realistic AD attack scenarios, though it focuses on AD rather than broader cloud services like web, IAM, or multi-cloud services beyond IaaS.
Attack Range is a cybersecurity breach simulation framework designed to orchestrate the lifecycle of security labs and execute controlled attack scenarios. It functions as a security simulation infrastructure orchestrator, enabling the deployment of instrumented cloud and local environments to validate defensive capabilities and generate security telemetry. The platform distinguishes itself through configuration-driven automation and infrastructure-as-code orchestration, which allow for the repeatable provisioning of vulnerable environments. It manages the entire simulation lifecycle, from th
Attack Range is a cybersecurity breach simulation framework that provisions vulnerable cloud and local environments for practicing attack and detection scenarios, squarely fitting the cloud security lab category, though it lacks explicit multi-cloud support and guided walkthroughs, making it a narrower match for hands-on cloud hacking practice.
CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
CloudGoat is a purpose-built tool for deploying intentionally vulnerable AWS environments, making it a solid cloud security lab for AWS practice, though it does not extend to Azure or GCP as needed for full multi-cloud coverage.