A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure
The main features of nccgroup/sadcloud are: Security Training Labs.
Open-source alternatives to nccgroup/sadcloud include: madhuakula/kubernetes-goat — Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of… bridgecrewio/cdkgoat — CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that… bridgecrewio/cfngoat — Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project… bridgecrewio/terragoat — TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project… disruptops/incidentresponsegenerator — Updated incident response generator for training classes. bishopfox/iam-vulnerable — Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.
CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.