awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to bridgecrewio/cfngoat

Projects sharing features with Cfngoat

30 open-source projects similar to bridgecrewio/cfngoat, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • madhuakula/kubernetes-goatmadhuakula avatar

    madhuakula/kubernetes-goat

    5,686View on GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    View on GitHub↗5,686
  • bishopfox/iam-vulnerableBishopFox avatar

    BishopFox/iam-vulnerable

    574View on GitHub↗

    Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

    HCL
    View on GitHub↗574
  • rhinosecuritylabs/cloudgoatRhinoSecurityLabs avatar

    RhinoSecurityLabs/cloudgoat

    3,639View on GitHub↗

    CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

    Python
    View on GitHub↗3,639
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    View on GitHub↗12,530

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • bridgecrewio/cdkgoatbridgecrewio avatar

    bridgecrewio/cdkgoat

    48View on GitHub↗

    CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    Python
    View on GitHub↗48
  • bridgecrewio/terragoatbridgecrewio avatar

    bridgecrewio/terragoat

    1,289View on GitHub↗

    TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    HCLaws-securityazure-securitycloud-security
    View on GitHub↗1,289
  • appsecco/breaking-and-pwning-apps-and-servers-aws-azure-trainingappsecco avatar

    appsecco/breaking-and-pwning-apps-and-servers-aws-azure-training

    952View on GitHub↗

    Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!

    CSS
    View on GitHub↗952
  • andresriancho/nimbostratusandresriancho avatar

    andresriancho/nimbostratus

    509View on GitHub↗

    Tools for fingerprinting and exploiting Amazon cloud infrastructures

    Python
    View on GitHub↗509
  • aliyun/aliyun-cliA

    aliyun/aliyun-cli

    0View on GitHub↗
    View on GitHub↗0
  • awslabs/aws-security-benchmarkawslabs avatar

    awslabs/aws-security-benchmark

    620View on GitHub↗

    Open source demos, concept and guidance related to the AWS CIS Foundation framework.

    Python
    View on GitHub↗620
  • azure/stormspotterAzure avatar

    Azure/Stormspotter

    1,706View on GitHub↗

    Stormspotter creates an “attack graph” of the resources in an Azure subscription. It enables red teams and pentesters to visualize the attack surface and pivot opportunities within a tenant, and supercharges your defenders to quickly orient and prioritize incident response work.

    Python
    View on GitHub↗1,706
  • azuread/azure-ad-incident-response-powershell-moduleA

    AzureAD/Azure-AD-Incident-Response-PowerShell-Module

    0View on GitHub↗
    View on GitHub↗0
  • b3nac/injuredandroidB3nac avatar

    B3nac/InjuredAndroid

    751View on GitHub↗

    A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

    Kotlin
    View on GitHub↗751
  • cloud-sniper/cloud-sniperC

    cloud-sniper/cloud-sniper

    0View on GitHub↗
    View on GitHub↗0
  • aws-cloudformation/cloudformation-guardaws-cloudformation avatar

    aws-cloudformation/cloudformation-guard

    1,384View on GitHub↗

    Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

    Rust
    View on GitHub↗1,384
  • andresriancho/enumerate-iamandresriancho avatar

    andresriancho/enumerate-iam

    1,242View on GitHub↗

    Enumerate the permissions associated with AWS credential set

    Python
    View on GitHub↗1,242
  • bloodhoundad/azurehoundB

    BloodHoundAD/AzureHound

    0View on GitHub↗
    View on GitHub↗0
  • aquasecurity/kube-hunteraquasecurity avatar

    aquasecurity/kube-hunter

    5,064View on GitHub↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Python
    View on GitHub↗5,064
  • bkimminich/juice-shopB

    bkimminich/juice-shop

    0View on GitHub↗
    View on GitHub↗0
  • carlospolop/purplepandaC

    carlospolop/PurplePanda

    0View on GitHub↗
    View on GitHub↗0
  • carnal0wnage/weirdaalcarnal0wnage avatar

    carnal0wnage/weirdAAL

    844View on GitHub↗

    WeirdAAL (AWS Attack Library)

    Python
    View on GitHub↗844
  • cdk-team/cdkcdk-team avatar

    cdk-team/CDK

    4,692View on GitHub↗

    CDK is a specialized toolset for container security auditing, container escape exploitation, and cloud infrastructure pentesting. It provides a collection of scripts and tools designed to identify and exploit vulnerabilities in container runtimes to break out of isolated environments and execute commands on the underlying host operating system. The project features a dedicated Docker runtime exploit suite for abusing the Docker API, procfs, and cgroups to gain unauthorized host-level access. It includes specific techniques for bypassing isolation via LXCFS, user namespace exploitation, and ho

    Go
    View on GitHub↗4,692
  • chaitin/veinmind-toolschaitin avatar

    chaitin/veinmind-tools

    1,649View on GitHub↗

    问脉已接入 openai, 可以使用 openai 对扫描的结果进行人性化分析,让您更加清晰的了解本次扫描发现了哪些风险。

    Go
    View on GitHub↗1,649
  • chromium/badssl.comchromium avatar

    chromium/badssl.com

    3,026View on GitHub↗

    Visit badssl.com for a list of test subdomains, including:

    HTML
    View on GitHub↗3,026
  • chuckfw/owaspbwachuckfw avatar

    chuckfw/owaspbwa

    310View on GitHub↗

    OWASP Broken Web Applications Project

    PHP
    View on GitHub↗310
  • cider-security-research/cicd-goatcider-security-research avatar

    cider-security-research/cicd-goat

    2,274View on GitHub↗

    A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

    Python
    View on GitHub↗2,274
  • cisagov/sparrowcisagov avatar

    cisagov/Sparrow

    1,430View on GitHub↗

    Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.

    PowerShell
    View on GitHub↗1,430
  • cisagov/untitledgoosetoolcisagov avatar

    cisagov/untitledgoosetool

    956View on GitHub↗

    Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to run a full investigation against a customer’s Azure Active Directory (AzureAD), Azure, and M365 environments.

    Python
    View on GitHub↗956
  • bishopfox/smogcloudB

    BishopFox/smogcloud

    0View on GitHub↗
    View on GitHub↗0
  • aquasecurity/kube-benchaquasecurity avatar

    aquasecurity/kube-bench

    8,078View on GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    View on GitHub↗8,078