Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cloudgoat — CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool | Kitploit
Tools/GitHubGitHub/rhinosecuritylabs/cloudgoat
Vulnerability ScannersServerless SecurityCTFPenetration TestingCloud SecurityMisconfigurationLearning & EducationLabs & PracticeTop in Labs & Practice #12Top in Serverless Security #12
3.7k763276 months agoReviewed by Kitploit
GitHubrhinosecuritylabs/cloudgoat

cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CloudGoat (☁️🐐)

Rhino PyPI GitHub license PRs Welcome

CloudGoat is Rhino Security Labs' "Vulnerable by Design" cloud deployment tool.

Quick reference

  • Where to get help: the Rhino Security Labs Discord, or Stack Overflow

  • Where to file issues: https://github.com/RhinoSecurityLabs/cloudgoat/issues

  • Maintained by: the CloudGoat Community

CloudGoat 2.0 is here!

CloudGoat is Rhino Security Labs' "Vulnerable by Design" cloud deployment tool. It allows you to hone your cloud cybersecurity skills by creating and completing several "capture-the-flag" style scenarios. Each scenario is composed of cloud resources arranged together to create a structured learning experience. Some scenarios are easy, some are hard, and many offer multiple paths to victory. As the attacker, it is your mission to explore the environment, identify vulnerabilities, and exploit your way to the scenario's goal(s).

Below are our main goals for CloudGoat:

  • Focused, Curated, High-Quality Learning Experiences - Each of CloudGoat’s scenarios should provide the opportunity for experimentation, exploration, and building hands-on cloud security skills.
  • Good Documentation - We've done our best to ensure that CloudGoat’s scenarios are well-documented and easy to understand and evaluate in terms of difficulty, content, structure, and skills-required.
  • Easy to Install and Use - We understand that CloudGoat is a means to an end - learning and practicing cloud security penetration testing. Therefore, we aim to keep things simple, straightforward, and reliable.
  • Modularity - Each scenario is a standalone learning environment with a clear goal (or set of goals), and CloudGoat is able to start up, reset, or shut down each scenario independently.
  • Expandability - CloudGoat’s core components (python app and scenarios) are designed to permit easy and independent expansion - by us or the community.

Before you proceed, please take note of these warnings!

Warning #1: CloudGoat creates intentionally vulnerable resources into your account. DO NOT deploy CloudGoat in a production environment or alongside any sensitive resources.

Warning #2: CloudGoat can only manage resources it creates. If you create any resources yourself in the course of a scenario, you should remove them manually before running the destroy command.

Requirements

  • Linux or MacOS. Windows is not officially supported.
    • Argument tab-completion requires bash 4.2+ (Linux, or OSX with some difficulty).
  • Python3.9+ is required.
  • Terraform >= 1.5.0 installed and in your $PATH.
  • The AWS CLI installed and in your $PATH, and an AWS account with sufficient privileges to create and destroy resources.
  • The AZ CLI installed and in your $PATH, and an Azure account with sufficient privileges to create and destroy resources.
  • jq

Linux

sudo apt install terraform awscli azure-cli jq -y

Mac

brew install terraform awscli azure-cli jq

Quick Start

To install CloudGoat, make sure your system meets the requirements above, and then run the following commands:

pipx install cloudgoat

You may also want to run some quick configuration commands - it'll save you some time later:

Configure for AWS - tell CloudGoat which AWS profile to use.

cloudgoat config aws

Configure for Azure - tell CloudGoat which Azure subscription to use.

cloudgoat config azure

Log in to Azure - CloudGoat uses the active az account.

az login

Configure whitelist

cloudgoat config whitelist --auto

Now, at your command, CloudGoat can create an instance of a scenario in the cloud. When the environment is ready, a new folder will be created in the project base directory named after the scenario and with a unique scenario ID appended. Inside this folder will be a file called start.txt, which will contain all of the resources you'll need to begin the scenario, though these are also printed to your console when the create command completes. Sometimes an SSH keypair named cloudgoat/cloudgoat.pub will be created as well.

Note: Don't delete or modify the scenario instance folder or the files inside, as this could prevent CloudGoat from being able to manage your scenario's resources.

Download Tool