Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
terragoat — Infrastruttura Terraform intenzionalmente vulnerabile per imparare il rilevamento di configurazioni errate nel cloud e le pratiche DevSecOps su AWS, Azure e GCP. | Kitploit
Strumenti/GitHubGitHub/bridgecrewio/terragoat
Sicurezza CloudDevSecOpsConfigurazione ErrataApprendimento e FormazioneLab e Pratica
GitHubbridgecrewio/terragoat

terragoat

Infrastruttura Terraform intenzionalmente vulnerabile per imparare il rilevamento di configurazioni errate nel cloud e le pratiche DevSecOps su AWS, Azure e GCP.

Vedi Repository
1.3k5.8k463 anni faRevisionato da Kitploit
Sito web

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

TerraGoat - Infrastruttura Terraform Vulnerabile

Maintained by Bridgecrew.io Infrastructure Tests CIS Azure CIS GCP CIS AWS PCI Terraform Version slack-community

TerraGoat è il repository Terraform "Vulnerable by Design" di Bridgecrew. Terragoat

TerraGoat è il repository Terraform "Vulnerable by Design" di Bridgecrew. TerraGoat è un progetto di apprendimento e formazione che dimostra come errori di configurazione comuni possano arrivare negli ambienti cloud di produzione.

Indice

  • Introduzione
  • Come iniziare
    • Configurazione AWS
    • Configurazione Azure
    • Configurazione GCP
  • Contribuire
  • Supporto

Introduzione

TerraGoat è stato creato per consentire ai DevSecOps di progettare e implementare una strategia sostenibile di prevenzione delle configurazioni errate. Può essere utilizzato per testare un framework policy-as-code come Bridgecrew & Checkov, linter inline, hook pre-commit o altri metodi di scansione del codice.

TerraGoat segue la tradizione dei progetti *Goat esistenti che forniscono un terreno di formazione di base per esercitarsi nell'implementazione delle migliori pratiche di sviluppo sicuro per l'infrastruttura cloud.

Note importanti

  • Dove ottenere aiuto: il Bridgecrew Community Slack

Prima di procedere, prendi nota di questi avvertimenti:

⚠️ TerraGoat crea intenzionalmente risorse AWS vulnerabili nel tuo account. NON distribuire TerraGoat in un ambiente di produzione o insieme a risorse AWS sensibili.

Requisiti

  • Terraform 0.12
  • aws cli
  • azure cli

Per prevenire l'arrivo di infrastrutture vulnerabili in produzione, consulta: Bridgecrew & checkov, lo strumento open source di analisi statica per infrastruttura come codice.

Come iniziare

Configurazione AWS

Installazione (AWS)

Puoi distribuire più stack TerraGoat in un unico account AWS utilizzando il parametro TF_VAR_environment.

Crea un backend S3 Bucket per mantenere lo stato di Terraform```bash

export TERRAGOAT_STATE_BUCKET="mydevsecops-bucket" export TF_VAR_company_name=acme export TF_VAR_environment=mydevsecops export TF_VAR_region="us-west-2"

aws s3api create-bucket --bucket $TERRAGOAT_STATE_BUCKET
--region $TF_VAR_region --create-bucket-configuration LocationConstraint=$TF_VAR_region

Enable versioning

aws s3api put-bucket-versioning --bucket $TERRAGOAT_STATE_BUCKET --versioning-configuration Status=Enabled

Enable encryption

aws s3api put-bucket-encryption --bucket $TERRAGOAT_STATE_BUCKET --server-side-encryption-configuration '{ "Rules": [ { "ApplyServerSideEncryptionByDefault": { "SSEAlgorithm": "aws:kms" } } ] }'

#### Applica TerraGoat (AWS)```bash
cd terraform/aws/
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"

terraform apply

Rimuovere TerraGoat (AWS)```bash

terraform destroy

#### Creazione di più stack AWS TerraGoat```bash
cd terraform/aws/
export TERRAGOAT_ENV=$TF_VAR_environment
export TERRAGOAT_STACKS_NUM=5
for i in $(seq 1 $TERRAGOAT_STACKS_NUM)
do
    export TF_VAR_environment=$TERRAGOAT_ENV$i
    terraform init \
    -backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
    -backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
    -backend-config="region=$TF_VAR_region"

    terraform apply -auto-approve
done

Eliminazione di più stack TerraGoat (AWS)```bash

cd terraform/aws/ export TF_VAR_environment = $TERRAGOAT_ENV for i in $(seq 1 $TERRAGOAT_STACKS_NUM) do export TF_VAR_environment=$TERRAGOAT_ENV$i terraform init
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET"
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate"
-backend-config="region=$TF_VAR_region"

terraform destroy -auto-approve

done

### Azure Setup

#### Installazione (Azure)

È possibile distribuire più stack TerraGoat in una singola sottoscrizione Azure utilizzando il parametro `TF_VAR_environment`.

#### Creare un backend dell'account di archiviazione Azure per mantenere lo stato di Terraform```bash
export TERRAGOAT_RESOURCE_GROUP="TerraGoatRG"
export TERRAGOAT_STATE_STORAGE_ACCOUNT="mydevsecopssa"
export TERRAGOAT_STATE_CONTAINER="mydevsecops"
export TF_VAR_environment="dev"
export TF_VAR_region="westus"

# Create resource group
az group create --location $TF_VAR_region --name $TERRAGOAT_RESOURCE_GROUP

# Create storage account
az storage account create --name $TERRAGOAT_STATE_STORAGE_ACCOUNT --resource-group $TERRAGOAT_RESOURCE_GROUP --location $TF_VAR_region --sku Standard_LRS --kind StorageV2 --https-only true --encryption-services blob

# Get storage account key
ACCOUNT_KEY=$(az storage account keys list --resource-group $TERRAGOAT_RESOURCE_GROUP --account-name $TERRAGOAT_STATE_STORAGE_ACCOUNT --query [0].value -o tsv)

# Create blob container
az storage container create --name $TERRAGOAT_STATE_CONTAINER --account-name $TERRAGOAT_STATE_STORAGE_ACCOUNT --account-key $ACCOUNT_KEY

Applica TerraGoat (Azure)```bash

cd terraform/azure/ terraform init -reconfigure -backend-config="resource_group_name=$TERRAGOAT_RESOURCE_GROUP"
-backend-config "storage_account_name=$TERRAGOAT_STATE_STORAGE_ACCOUNT"
-backend-config="container_name=$TERRAGOAT_STATE_CONTAINER"
-backend-config "key=$TF_VAR_environment.terraform.tfstate"

terraform apply

#### Rimuovi TerraGoat (Azure)```bash
terraform destroy

Configurazione GCP

Installazione (GCP)

Puoi distribuire più stack TerraGoat in un singolo progetto GCP utilizzando il parametro TF_VAR_environment.

Creare un backend GCS per mantenere lo stato di Terraform

Scarica lo strumento