
google-ctf
Archived CTF challenge sources and deployable sandboxes since 2017, with intentionally vulnerable exercises for hands-on security training and…

Archived CTF challenge sources and deployable sandboxes since 2017, with intentionally vulnerable exercises for hands-on security training and…

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

AWSGoat : A Damn Vulnerable AWS Infrastructure

AzureGoat : A Damn Vulnerable Azure Infrastructure

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…


Create your own vulnerable by design AWS penetration testing playground

GCPGoat : A Damn Vulnerable GCP Infrastructure

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Lord Of Active Directory - automatic vulnerable active directory on AWS

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

Google Chrome CVE-2026-6307 PoC

This repository holds a target infrastructure you can use for running the nimbostratus tools.

Network Security Project

End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to…