awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to rhinosecuritylabs/cloudgoat

Open-source alternatives to Cloudgoat

30 open-source projects similar to rhinosecuritylabs/cloudgoat, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Cloudgoat alternative.

  • audi-1/sqli-labsAudi-1 avatar

    Audi-1/sqli-labs

    5,791View on GitHub↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    View on GitHub↗5,791
  • koadt/oss-oopssec-storekOaDT avatar

    kOaDT/oss-oopssec-store

    22View on GitHub↗

    Security training for the apps you actually ship. Open your browser and start hacking.

    TypeScript
    View on GitHub↗22
  • madhuakula/kubernetes-goatmadhuakula avatar

    madhuakula/kubernetes-goat

    5,686View on GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    View on GitHub↗5,686
  • bridgecrewio/cdkgoatbridgecrewio avatar

    bridgecrewio/cdkgoat

    48View on GitHub↗

    CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    Python
    View on GitHub↗48

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • tegal1337/0l4bstegal1337 avatar

    tegal1337/0l4bs

    341View on GitHub↗

    Cross-site scripting labs for web application security enthusiasts

    PHP
    View on GitHub↗341
  • bridgecrewio/cfngoatbridgecrewio avatar

    bridgecrewio/cfngoat

    97View on GitHub↗

    Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    View on GitHub↗97
  • jerryhoff/webgoat.netjerryhoff avatar

    jerryhoff/WebGoat.NET

    252View on GitHub↗

    OWASP WebGoat.NET

    C#
    View on GitHub↗252
  • iknowjason/awesome-cloudsec-labsiknowjason avatar

    iknowjason/Awesome-CloudSec-Labs

    2,109View on GitHub↗

    Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

    View on GitHub↗2,109
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    View on GitHub↗12,530
  • m6a-uds/dvcam6a-UdS avatar

    m6a-UdS/dvca

    211View on GitHub↗

    Damn Vulnerable Cloud Application

    CSS
    View on GitHub↗211
  • owasp/serverless-goatOWASP avatar

    OWASP/Serverless-Goat

    329View on GitHub↗

    OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

    Python
    View on GitHub↗329
  • webgoat/webgoatWebGoat avatar

    WebGoat/WebGoat

    9,160View on GitHub↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    JavaScript
    View on GitHub↗9,160
  • rapid7/hackazonrapid7 avatar

    rapid7/hackazon

    1,035View on GitHub↗

    A modern vulnerable web app

    HTML
    View on GitHub↗1,035
  • commjoen/wrongsecretsC

    commjoen/wrongsecrets

    0View on GitHub↗
    View on GitHub↗0
  • adamdoupe/wackopickoadamdoupe avatar

    adamdoupe/WackoPicko

    350View on GitHub↗

    WackoPicko is a vulnerable web application used to test web application vulnerability scanners.

    PHP
    View on GitHub↗350
  • ine-labs/awsgoatine-labs avatar

    ine-labs/AWSGoat

    2,025View on GitHub↗

    AWSGoat : A Damn Vulnerable AWS Infrastructure

    PHP
    View on GitHub↗2,025
  • appsecco/breaking-and-pwning-apps-and-servers-aws-azure-trainingappsecco avatar

    appsecco/breaking-and-pwning-apps-and-servers-aws-azure-training

    952View on GitHub↗

    Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!

    CSS
    View on GitHub↗952
  • bishopfox/iam-vulnerableBishopFox avatar

    BishopFox/iam-vulnerable

    574View on GitHub↗

    Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

    HCL
    View on GitHub↗574
  • momenbasel/htb-writeupsmomenbasel avatar

    momenbasel/htb-writeups

    123View on GitHub↗

    The most comprehensive Hack The Box writeup collection - 500+ machines, 400+ challenges, interactive knowledge graph, skill trees, attack path diagrams, ProLabs, Sherlocks, OSCP/CPTS/CRTO prep. Browse: momenbasel.github.io/htb-writeups

    HTML
    View on GitHub↗123
  • antonio-morales/fuzzing101antonio-morales avatar

    antonio-morales/Fuzzing101

    3,796View on GitHub↗

    Fuzzing101 is an educational resource providing a structured curriculum and containerized security labs for learning software fuzzing and vulnerability research. It functions as a training course that guides users through the process of identifying security flaws using systematic input manipulation and memory corruption analysis. The project distinguishes itself by providing isolated environments that ensure consistent build dependencies for practicing software instrumentation and crash triaging. It includes a practical tutorial on using evolutionary fuzzing engines and instrumentation tools

    View on GitHub↗3,796
  • awslabs/aws-security-benchmarkawslabs avatar

    awslabs/aws-security-benchmark

    620View on GitHub↗

    Open source demos, concept and guidance related to the AWS CIS Foundation framework.

    Python
    View on GitHub↗620
  • aws-cloudformation/cloudformation-guardaws-cloudformation avatar

    aws-cloudformation/cloudformation-guard

    1,384View on GitHub↗

    Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

    Rust
    View on GitHub↗1,384
  • andresriancho/nimbostratusandresriancho avatar

    andresriancho/nimbostratus

    509View on GitHub↗

    Tools for fingerprinting and exploiting Amazon cloud infrastructures

    Python
    View on GitHub↗509
  • carlospolop/purplepandaC

    carlospolop/PurplePanda

    0View on GitHub↗
    View on GitHub↗0
  • c0ny1/vulstudyc0ny1 avatar

    c0ny1/vulstudy

    2,443View on GitHub↗

    使用docker快速搭建各大漏洞靶场,目前可以一键搭建17个靶场。

    Shelldocker-image-buildervulnerability
    View on GitHub↗2,443
  • c0ny1/upload-labsc0ny1 avatar

    c0ny1/upload-labs

    4,157View on GitHub↗

    upload-labs is a file upload vulnerability lab and penetration testing sandbox. It consists of a collection of intentionally vulnerable web applications designed for practicing the discovery and exploitation of file upload security flaws. The project serves as a web security training ground and cybersecurity education lab. It provides a simulated environment for learning how to bypass upload restrictions and achieve remote code execution on servers through controlled laboratory exercises. The system includes capabilities for vulnerability research simulation and penetration testing practice.

    PHP
    View on GitHub↗4,157
  • carnal0wnage/weirdaalcarnal0wnage avatar

    carnal0wnage/weirdAAL

    844View on GitHub↗

    WeirdAAL (AWS Attack Library)

    Python
    View on GitHub↗844
  • cdk-team/cdkcdk-team avatar

    cdk-team/CDK

    4,692View on GitHub↗

    CDK is a specialized toolset for container security auditing, container escape exploitation, and cloud infrastructure pentesting. It provides a collection of scripts and tools designed to identify and exploit vulnerabilities in container runtimes to break out of isolated environments and execute commands on the underlying host operating system. The project features a dedicated Docker runtime exploit suite for abusing the Docker API, procfs, and cgroups to gain unauthorized host-level access. It includes specific techniques for bypassing isolation via LXCFS, user namespace exploitation, and ho

    Go
    View on GitHub↗4,692
  • chaitin/veinmind-toolschaitin avatar

    chaitin/veinmind-tools

    1,649View on GitHub↗

    问脉已接入 openai, 可以使用 openai 对扫描的结果进行人性化分析,让您更加清晰的了解本次扫描发现了哪些风险。

    Go
    View on GitHub↗1,649
  • bridgecrewio/terragoatbridgecrewio avatar

    bridgecrewio/terragoat

    1,289View on GitHub↗

    TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    HCLaws-securityazure-securitycloud-security
    View on GitHub↗1,289