CloudGoat는 Rhino Security Labs의 "의도적으로 취약하게 설계된" AWS 배포 도구입니다.
CloudGoat는 Rhino Security Labs의 "Vulnerable by Design" 클라우드 배포 도구입니다.
도움을 받을 수 있는 곳: Rhino Security Labs Discord 또는 Stack Overflow
이슈를 제출할 곳: https://github.com/RhinoSecurityLabs/cloudgoat/issues
관리 주체: CloudGoat 커뮤니티
CloudGoat는 Rhino Security Labs의 "Vulnerable by Design" 클라우드 배포 도구입니다. 이 도구를 통해 여러 "캡처 더 플래그" 스타일 시나리오를 생성하고 완료하면서 클라우드 사이버보안 기술을 연마할 수 있습니다. 각 시나리오는 구조화된 학습 경험을 제공하기 위해 함께 배치된 클라우드 리소스로 구성됩니다. 쉬운 시나리오부터 어려운 시나리오까지 있으며, 많은 시나리오가 목표를 달성할 수 있는 여러 경로를 제공합니다. 공격자로서 환경을 탐색하고, 취약점을 식별하며, 시나리오의 목표를 달성하기 위해 공략하는 것이 임무입니다.
다음은 CloudGoat의 주요 목표입니다:
계속 진행하기 전에 다음 경고 사항을 숙지하십시오!
경고 #1: CloudGoat는 의도적으로 취약한 리소스를 사용자 계정에 생성합니다. 프로덕션 환경이나 중요한 리소스와 함께 CloudGoat를 배포하지 마십시오.
경고 #2: CloudGoat는 자신이 생성한 리소스만 관리할 수 있습니다. 시나리오 진행 중 직접 리소스를 생성한 경우
destroy명령을 실행하기 전에 수동으로 제거해야 합니다.
Linux```bash sudo apt install terraform awscli azure-cli jq -y
Mac```bash
brew install terraform awscli azure-cli jq
CloudGoat를 설치하려면 시스템이 위의 요구 사항을 충족하는지 확인한 후 다음 명령을 실행하십시오:```bash pipx install cloudgoat
몇 가지 빠른 구성 명령을 실행하고 싶을 수도 있습니다. 나중에 시간을 절약할 수 있습니다:
AWS용 구성 - CloudGoat에 사용할 AWS 프로필을 알려줍니다.```bash
cloudgoat config aws
Azure용 구성 - CloudGoat에게 사용할 Azure 구독을 알려주세요.```bash cloudgoat config azure
Azure에 로그인 - CloudGoat는 활성 `az` 계정을 사용합니다.```bash
az login
허용 목록 구성```bash cloudgoat config whitelist --auto
Now, at your command, CloudGoat can `create` an instance of a scenario in the cloud. When the environment is ready, a new folder will be created in the project base directory named after the scenario and with a unique scenario ID appended. Inside this folder will be a file called `start.txt`, which will contain all of the resources you'll need to begin the scenario, though these are also printed to your console when the `create` command completes. Sometimes an SSH keypair named `cloudgoat`/`cloudgoat.pub` will be created as well.
> **참고:** 시나리오 인스턴스 폴더나 그 안의 파일을 삭제하거나 수정하지 마세요. 그렇게 하면 CloudGoat가 시나리오 리소스를 관리하지 못할 수 있습니다.
시나리오를 진행하는 동안 방향이 필요하면 시나리오의 readme를 참조하세요. 막히는 경우 각 경로의 워크스루 하단에 치트 시트 링크가 있습니다.
시나리오가 끝나면 직접 생성한 리소스를 삭제하고(기억하세요: CloudGoat는 자신이 생성한 리소스만 관리할 수 있습니다) `destroy` 명령을 실행하세요. 이후 웹 콘솔을 잠시 살펴보는 것이 좋습니다. 혹시 삭제되지 않은 것이 있을 수 있으니까요.
You can read the full documentation for CloudGoat's commands [here in the Usage Guide section](#usage-guide).
## CloudGoat Docker 이미지 사용 방법
[](http://play-with-docker.com?stack=https://raw.githubusercontent.com/RhinoSecurityLabs/cloudgoat/master/docker_stack.yml)
### 옵션 1: 기본 엔트리포인트로 실행```console
docker run -it rhinosecuritylabs/cloudgoat:latest
경고: 이 명령을 실행하면 Docker 컨테이너가 시작될 때 로컬 AWS 구성 파일이 컨테이너에 마운트됩니다. 이는 컨테이너에 접근 권한이 있는 모든 사용자가 호스트 컴퓨터의 AWS 자격 증명에 접근할 수 있음을 의미합니다.```console docker run -it -v ~/.aws:/root/.aws/ rhinosecuritylabs/cloudgoat:latest
## 사용 가능한 시나리오
(난이도별 그룹)
<details open>
<summary><strong>쉬움</strong></summary>
---
### iam_enum_basics (쉬움)
`cloudgoat create iam_enum_basics`
이 시나리오에서는 Bob이라는 낮은 권한의 IAM 사용자의 액세스 키를 가지고 시작합니다. AWS CLI를 사용하여 철저한 IAM 열거를 수행해야 합니다. 관리형 정책, 인라인 정책, 그룹 멤버십, 수임 가능 역할을 조사하여 다섯 개의 서로 다른 플래그를 발견하게 됩니다.
[시나리오 페이지 방문](https://github.com/rhinosecuritylabs/cloudgoat/blob/master/cloudgoat/scenarios/aws/iam_enum_basics/README.md)
Tyler Ramsbey 제공