awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Intentionally Vulnerable Cloud Environments

Ranking updated Jun 30, 2026

For an intentionally vulnerable cloud environment for practice, the strongest matches are orange-cyberdefense/goad (GOAD deploys intentionally vulnerable Windows networks for Active Directory), splunk/attack_range (Attack Range is a cybersecurity breach simulation framework that) and rhinosecuritylabs/cloudgoat (CloudGoat is a purpose-built tool for deploying intentionally vulnerable). Each is ranked by relevance to your query, popularity and recent activity.

Discover open-source cloud platforms designed for practicing penetration testing and identifying common security misconfigurations.

Intentionally Vulnerable Cloud Environments

Find the best repos with AI.We'll search the best matching repositories with AI.
  • orange-cyberdefense/goadOrange-Cyberdefense avatar

    Orange-Cyberdefense/GOAD

    7,464View on GitHub↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    GOAD deploys intentionally vulnerable Windows networks for Active Directory penetration testing across multiple cloud platforms and hypervisors, providing automated provisioning and realistic AD attack scenarios, though it focuses on AD rather than broader cloud services like web, IAM, or multi-cloud services beyond IaaS.

    PowerShellTargeted Attack ScenariosMulti-Cloud Orchestrators
    View on GitHub↗7,464
  • splunk/attack_rangesplunk avatar

    splunk/attack_range

    2,507View on GitHub↗

    Attack Range is a cybersecurity breach simulation framework designed to orchestrate the lifecycle of security labs and execute controlled attack scenarios. It functions as a security simulation infrastructure orchestrator, enabling the deployment of instrumented cloud and local environments to validate defensive capabilities and generate security telemetry. The platform distinguishes itself through configuration-driven automation and infrastructure-as-code orchestration, which allow for the repeatable provisioning of vulnerable environments. It manages the entire simulation lifecycle, from th

    Attack Range is a cybersecurity breach simulation framework that provisions vulnerable cloud and local environments for practicing attack and detection scenarios, squarely fitting the cloud security lab category, though it lacks explicit multi-cloud support and guided walkthroughs, making it a narrower match for hands-on cloud hacking practice.

    PythonInfrastructure as Code
    View on GitHub↗2,507
  • rhinosecuritylabs/cloudgoatRhinoSecurityLabs avatar

    RhinoSecurityLabs/cloudgoat

    3,639View on GitHub↗

    CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

    CloudGoat is a purpose-built tool for deploying intentionally vulnerable AWS environments, making it a solid cloud security lab for AWS practice, though it does not extend to Azure or GCP as needed for full multi-cloud coverage.

    PythonCloud SecurityCloud Security Training and LabsSecurity Training Labs
    View on GitHub↗3,639

Related searches

  • a vulnerable web application for security training
  • a platform for practicing cybersecurity CTF challenges
  • an automated security scanner for web applications
  • a path to becoming a cloud engineer
  • a vulnerability management platform
  • a learning path into security engineering
  • an open source penetration testing framework
  • an automated security auditing tool for AWS