Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
The main features of bishopfox/iam-vulnerable are: Security Training Labs, Cloud Security, Vulnerability Assessment and IAM Auditing.
Open-source alternatives to bishopfox/iam-vulnerable include: bridgecrewio/cfngoat — Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project… rhinosecuritylabs/cloudgoat — CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool. bridgecrewio/cdkgoat — CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that… madhuakula/kubernetes-goat — Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of… andresriancho/nimbostratus — Tools for fingerprinting and exploiting Amazon cloud infrastructures. aliyun/aliyun-cli.
Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.