Clouds are a great tool to create a convenient infrastructure for applications and services. Companies and independent developers move their projects to AWS or Azure, often without thinking about security. But in vain.
I will share with you some resources (known vulnerable laboratories) that will help pentesters, specialists or enthusiasts, gain practical experience in searching for vulnerabilities in cloud applications deployed on Google Cloud, AWS or Azure. Resources contain practical and theoretical material:
• FLAWS; ( )
• FLAWS2; ( )
( )
• ( ( )
• Sadcloud; ( )
( )
• ( Goat;
( ) • ( ( )
• caponeme; ( )
• CloudGoat; ( )
• Thunder CTF; ( )
• CloudFoxable; ( )
• IAM Vulnerable; ( )
• AWS Detonation Lab; ( )
• OWASP WrongSecrets; ( )
• OWASP ServerlessGoat; ( )
• AWS S3 CTF Challenges; ( )
• ( Big IAM Challenge by Wiz; ( )
• AWS Well Architected Security Labs; ( )
• Damn Vulnerable Cloud Application; ( )
• CdkGoat - Vulnerable AWS CDK Infrastructure; ( )
• Cfngoat - Vulnerable Cloudformation Template; ( )
• TerraGoat - Vulnerable Terraform Infrastructure; ( )
• AWSGoat - A Damn Vulnerable AWS Infrastructure;
( )
• AzureGoat - A Damn Vulnerable Azure Infrastructure; ( )
• Breaking and Pwning Apps and Servers on AWS and Azure. (
I will share with you some resources (known vulnerable laboratories) that will help pentesters, specialists or enthusiasts, gain practical experience in searching for vulnerabilities in cloud applications deployed on Google Cloud, AWS or Azure. Resources contain practical and theoretical material:
• FLAWS; ( )
• FLAWS2; ( )
( )
• ( ( )
• Sadcloud; ( )
( )
• ( Goat;
( ) • ( ( )
• caponeme; ( )
• CloudGoat; ( )
• Thunder CTF; ( )
• CloudFoxable; ( )
• IAM Vulnerable; ( )
• AWS Detonation Lab; ( )
• OWASP WrongSecrets; ( )
• OWASP ServerlessGoat; ( )
• AWS S3 CTF Challenges; ( )
• ( Big IAM Challenge by Wiz; ( )
• AWS Well Architected Security Labs; ( )
• Damn Vulnerable Cloud Application; ( )
• CdkGoat - Vulnerable AWS CDK Infrastructure; ( )
• Cfngoat - Vulnerable Cloudformation Template; ( )
• TerraGoat - Vulnerable Terraform Infrastructure; ( )
• AWSGoat - A Damn Vulnerable AWS Infrastructure;
( )
• AzureGoat - A Damn Vulnerable Azure Infrastructure; ( )
• Breaking and Pwning Apps and Servers on AWS and Azure. (
Last edited by a moderator: