Create your own vulnerable by design AWS penetration testing playground
☆437Feb 16, 2026Updated last month
Alternatives and similar repositories for cloudfoxable
Users that are interested in cloudfoxable are comparing it to the libraries listed below
Sorting:
- Automating situational awareness for cloud penetration tests.☆2,309Mar 10, 2026Updated last week
- Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.☆553Mar 12, 2026Updated last week
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,908Oct 1, 2025Updated 5 months ago
- CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool☆3,510Updated this week
- CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.☆292Sep 4, 2024Updated last year
- Granular, Actionable Adversary Emulation for the Cloud☆2,277Mar 12, 2026Updated last week
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆1,984May 20, 2025Updated 10 months ago
- Simple tool to identify and remediate the use of the AWS EC2 IMDSv1.☆15Aug 12, 2021Updated 4 years ago
- A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure☆758Oct 14, 2023Updated 2 years ago
- DeRF (Detection Replay Framework) is an "Attacks As A Service" framework, allowing the emulation of offensive techniques and generation o…☆101Jan 12, 2024Updated 2 years ago
- An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and secur…☆174Mar 11, 2026Updated last week
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆142Jan 2, 2025Updated last year
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆2,554Feb 10, 2026Updated last month
- IMDSPOOF is a cyber deception tool that spoofs the AWS IMDS service to return HoneyTokens that can be alerted on.☆106Nov 24, 2023Updated 2 years ago
- Halberd : Multi-Cloud Agentic Attack Tool☆335Jan 12, 2026Updated 2 months ago
- Crowdsourced list of sensitive IAM Actions☆159Oct 29, 2024Updated last year
- Cloudlist is a tool for listing Assets from multiple Cloud Providers.☆1,011Mar 11, 2026Updated last week
- Determine privileges from cloud credentials via brute-force testing.☆69Aug 22, 2024Updated last year
- ☆176Apr 22, 2023Updated 2 years ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,097Updated this week
- Generates runbooks for GuardDuty findings☆38Jun 24, 2024Updated last year
- SCP management tool☆135Oct 23, 2023Updated 2 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆48Jun 13, 2023Updated 2 years ago
- cloudgrep is grep for cloud storage☆326Updated this week
- AzureGoat : A Damn Vulnerable Azure Infrastructure☆918Oct 30, 2024Updated last year
- An AWS IAM policy statement parser and query tool.☆199Feb 10, 2026Updated last month
- A tool for quickly evaluating IAM permissions in AWS.☆1,544Aug 2, 2024Updated last year
- Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure☆49Dec 29, 2023Updated 2 years ago
- Harness the security superpowers of your cloud asset inventory☆11Sep 22, 2024Updated last year
- This repo contains IOC, malware and malware analysis associated with Public cloud☆249Nov 11, 2024Updated last year
- This repository provides a comprehensive collection of Pulumi scenarios utilized by cnappgoat☆22Jan 28, 2025Updated last year
- A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-pur…☆630Mar 21, 2025Updated 11 months ago
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆113Nov 13, 2024Updated last year
- BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse en…☆505Mar 4, 2026Updated 2 weeks ago
- This application was built to help reduce the amount of time it takes to review AWS Lambda code.☆61Nov 11, 2024Updated last year
- A curated list of Awesome Security Challenges.☆211Nov 6, 2024Updated last year
- A collection of resources, tools and more for penetration testing and securing Microsofts cloud platform Azure.☆1,183Dec 27, 2023Updated 2 years ago
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆17Jun 11, 2024Updated last year
- CloudGrappler is a purpose-built tool designed for effortless querying of high-fidelity and single-event detections related to well-known…☆266Nov 21, 2025Updated 3 months ago