CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
CloudGoat is Rhino Security Labs' "Vulnerable by Design" cloud deployment tool.
Where to get help: the Rhino Security Labs Discord, or Stack Overflow
Where to file issues: https://github.com/RhinoSecurityLabs/cloudgoat/issues
Maintained by: the CloudGoat Community
CloudGoat is Rhino Security Labs' "Vulnerable by Design" cloud deployment tool. It allows you to hone your cloud cybersecurity skills by creating and completing several "capture-the-flag" style scenarios. Each scenario is composed of cloud resources arranged together to create a structured learning experience. Some scenarios are easy, some are hard, and many offer multiple paths to victory. As the attacker, it is your mission to explore the environment, identify vulnerabilities, and exploit your way to the scenario's goal(s).
Below are our main goals for CloudGoat:
Before you proceed, please take note of these warnings!
Warning #1: CloudGoat creates intentionally vulnerable resources into your account. DO NOT deploy CloudGoat in a production environment or alongside any sensitive resources.
Warning #2: CloudGoat can only manage resources it creates. If you create any resources yourself in the course of a scenario, you should remove them manually before running the
destroycommand.
Linux
sudo apt install terraform awscli azure-cli jq -y
Mac
brew install terraform awscli azure-cli jq
To install CloudGoat, make sure your system meets the requirements above, and then run the following commands:
pipx install cloudgoat
You may also want to run some quick configuration commands - it'll save you some time later:
Configure for AWS - tell CloudGoat which AWS profile to use.
cloudgoat config aws
Configure for Azure - tell CloudGoat which Azure subscription to use.
cloudgoat config azure
Log in to Azure - CloudGoat uses the active az account.
az login
Configure whitelist
cloudgoat config whitelist --auto
Now, at your command, CloudGoat can create an instance of a scenario in the cloud. When the environment is ready, a new folder will be created in the project base directory named after the scenario and with a unique scenario ID appended. Inside this folder will be a file called start.txt, which will contain all of the resources you'll need to begin the scenario, though these are also printed to your console when the create command completes. Sometimes an SSH keypair named cloudgoat/cloudgoat.pub will be created as well.
Note: Don't delete or modify the scenario instance folder or the files inside, as this could prevent CloudGoat from being able to manage your scenario's resources.