Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
☆553Mar 12, 2026Updated last week
Alternatives and similar repositories for iam-vulnerable
Users that are interested in iam-vulnerable are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool☆3,524Updated this week
- Automating situational awareness for cloud penetration tests.☆2,320Mar 10, 2026Updated 2 weeks ago
- Granular, Actionable Adversary Emulation for the Cloud☆2,283Mar 12, 2026Updated last week
- A tool for quickly evaluating IAM permissions in AWS.☆1,544Aug 2, 2024Updated last year
- Create your own vulnerable by design AWS penetration testing playground☆438Feb 16, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- IAM-Deescalate helps mitigate privilege escalation risk in AWS identity and access management (IAM)☆98Sep 14, 2022Updated 3 years ago
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆1,993May 20, 2025Updated 10 months ago
- A graph-based tool for visualizing effective access and resource relationships in AWS environments.☆1,000Oct 4, 2022Updated 3 years ago
- A utility to convert your AWS CLI credentials into AWS console access.☆257May 7, 2020Updated 5 years ago
- Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized repo…☆2,197Updated this week
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,110Updated this week
- A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure☆758Oct 14, 2023Updated 2 years ago
- Crowdsourced list of sensitive IAM Actions☆159Oct 29, 2024Updated last year
- A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.☆924Jul 25, 2019Updated 6 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆2,585Mar 17, 2026Updated last week
- AzureGoat : A Damn Vulnerable Azure Infrastructure☆919Oct 30, 2024Updated last year
- GCPGoat : A Damn Vulnerable GCP Infrastructure☆436Oct 29, 2024Updated last year
- Enumerate the permissions associated with AWS credential set☆1,229Feb 5, 2024Updated 2 years ago
- Unauthenticated enumeration of AWS, Azure, and GCP Principals☆284Nov 27, 2025Updated 3 months ago
- An AWS IAM policy statement parser and query tool.☆199Feb 10, 2026Updated last month
- A collection of manifests that will create pods with elevated privileges.☆692Dec 30, 2025Updated 2 months ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,908Oct 1, 2025Updated 5 months ago
- WeirdAAL (AWS Attack Library)☆838Jan 13, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆176Apr 22, 2023Updated 2 years ago
- A repository of breaches of AWS customers☆798Mar 11, 2026Updated 2 weeks ago
- Cloudlist is a tool for listing Assets from multiple Cloud Providers.☆1,012Mar 11, 2026Updated 2 weeks ago
- An AWS IAM Privilege Escalation Path Library☆124Mar 16, 2026Updated last week
- ☆229Mar 10, 2026Updated 2 weeks ago
- CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.☆293Sep 4, 2024Updated last year
- Automated Attack Simulation in the Cloud, complete with detection use cases.☆608Nov 28, 2024Updated last year
- Damn Vulnerable Cloud Application☆210Sep 12, 2018Updated 7 years ago
- Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic☆307Jan 6, 2023Updated 3 years ago
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Multi-Cloud Security Auditing Tool☆7,579Sep 23, 2025Updated 6 months ago
- Search exposed EBS volumes for secrets☆302Apr 24, 2023Updated 2 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,807Sep 17, 2024Updated last year
- Awesome cloud enumerator☆1,107Mar 9, 2025Updated last year
- Identify privilege escalation paths within and across different clouds☆719Feb 6, 2026Updated last month
- Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on p…☆5,447Nov 18, 2025Updated 4 months ago
- ☆614Jun 1, 2023Updated 2 years ago