
google-ctf
Archived CTF challenge sources and deployable sandboxes since 2017, with intentionally vulnerable exercises for hands-on security training and…

Archived CTF challenge sources and deployable sandboxes since 2017, with intentionally vulnerable exercises for hands-on security training and…

Lord Of Active Directory - automatic vulnerable active directory on AWS

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

Create your own vulnerable by design AWS penetration testing playground


This repository holds a target infrastructure you can use for running the nimbostratus tools.

Network Security Project

End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to…

Google Chrome CVE-2026-6307 PoC

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

AzureGoat : A Damn Vulnerable Azure Infrastructure

AWSGoat : A Damn Vulnerable AWS Infrastructure

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

GCPGoat : A Damn Vulnerable GCP Infrastructure