Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Awesome-CloudSec-Labs — Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs. | Kitploit
Tools/GitHubGitHub/iknowjason/awesome-cloudsec-labs
Container SecurityServerless SecurityCTFPenetration TestingCloud SecurityLearning & EducationIncident ResponseCurated ResourcesLearning Paths & Courses

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Labs & Practice
GitHubiknowjason/awesome-cloudsec-labs

Awesome-CloudSec-Labs

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

View Repository
2.2k332270 years agoReviewed by Kitploit

Awesome Cloud Security Labs

A list of free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

Sorted by Technology and Category

NameTechnologyCategoryAuthorNotes
The Ultimate Cloud Security ChampionshipAWSAuthor-hosted CTF ChallengeWizA monthly CTF challenge, with challenges curated by a Star Wiz researcher. Challenges and leaderboard hosted by Wiz.
CloudFoxableAWSSelf-hosted CTF ChallengeSeth ArtCreate your own vulnerable by design AWS penetration testing playground
Pwned LabsAWSAuthor-hosted Guided Labs, CTFIan AustinRequires account registration; Commercial paid subscriptions; free hosted labs for learning cloud security
The Big IAM ChallengeAWSAuthor-hosted CTF ChallengeWizCTF challenge to identify and exploit IAM misconfigurations
The Cloud Hunting GamesAWSAuthor-hosted CTF ChallengeWizCTF ransomware challenge designed to teach real-world cloud investation based on TTPs seen in the wild
CloudSec TidbitsAWSSelf-hosted ChallengeDoyensecThree web app security flaws specific to AWS cloud, self-hosted with terraform
AWS Well-Architected Security WorkshopAWSSelf-hosted, guided labsAWS Well-ArchitectedSeveral hands-on-labs to help you learn, measure, and improve the security of your architecture using best practices from the Security pillar of the AWS Well-Architected Framework.
AWS CIRT WorkshopAWSSelf-hosted, guided labAWS CIRTBuild with Cloudformation, explore 5 common incident response scenarios observed by AWS CIRT
CloudGoatAWSSelf-hosted, guided vulnerability labMultiple, Rhino Security LabsPython orchestration of terraform
Attacking and Defending Serverless ApplicationsAWSSelf-hosted, guided vulnerability workshopRyan NicholsonAttack and defend a Lambda that you build in your own AWS account with author provided terraform
IAM VulnerableAWSSelf-hosted, guided vulnerability labSeth ArtIAM-focused priv esc playground with 31 pathways, create in your own AWS account using terraform, solid docs
flaws.cloudAWSAuthor-hosted, CTF challengeScott PiperChallenge style with levels and clues
flaws2.cloudAWSAuthor-hosted, CTF challengeScott PiperChallenge style Attacker and Defender paths
CI/CDon'tAWSSelf-hosted CTF walkthroughNick FrichetteHost with terraform in your own AWS account, vulnerable CI/CD CTF infrastructure
AWSGoatAWSSelf-hosted, attack and defense manualsMultiple, ine-labsBring your own aws account, Build with terraform, two modules, provides attack and defense manuals
SadcloudAWSSelf-hostedMultiple, NCC GroupTerraform code; not guided like CloudGoat
DVCAAWSSelf-hosted demo labMaxime LeblancDeploy a Damn Vulnerable Cloud Application in your own AWS account to practice privilege escalation
lambhackAWSSelf-hosted labJames WickettDeploy a very vulnerable AWS lambda serverless application in your AWS account
AWSCloudPentestAWSSelf-hosted labPunit DarjiDeploy vulnerable AWS scenarios in your account using terraform and learn how to exploit them. Companion YouTube channel.
EntraGoatAzureSelf-hosted labSemperisA deliberately vulnerable Microsoft Entra ID infrastructure. Uses Powershell Graph SDK scripts with a nice NodeJS web UI for management. Six vulnerable attack path scenarios with solutions documented.
BadZureAzureSelf-hosted labMauricio VelazcoPowershell Graph SDK script that spins up your own Azure AD (Entra ID) lab with attack paths. Currently no walk through or guide.
Broken AzureAzureAuthor-hosted, CTF challengeSecuraProvides hints, optionally self-host in your own Azure account using terraform
Mandiant Azure WorkshopAzureSelf-hosted, guided commandsMultipleVulnerable by design Azure lab with two scenarios; build with terraform
AzureGoatAzureSelf-hosted, attack and defense manualsMultiple, ine-labsBring your own Azure tenant, Build with terraform, one module, provides attack and defense manuals
XMGoatAzureSelf-hosted, guided labsMultipleBuild with terraform, 5 scenarios, solution docs provided
CONVEXAzureSelf-hosted, CTFMultipleSpin up three Capture the Flag environments in your Azure tenant using powershell
GCP CTF WorkshopGCPSelf-hosted, lab guideMarion Säckel, Marcus HallbergHost in your own GCP account, build with terraform using bash setup script, solution and hints provided
GCP Goat (Josh Jebaraj)GCPSelf-hosted, mdbook lab guideJosh JebarajHost in your own GCP account, build with provided scripts, nice guided lab workbook
GCPGoat (ine-labs)GCPSelf-hosted, attack and defense manualsMultiple, ine-labsBring your own GCP account, Build with terraform, one module, provides attack and defense manuals
Thunder CTFGCPSelf-hosted, CTFMultipleBring your own GCP account, 6 levels, practice attacking vulnerable cloud projects on GCP
Download Tool