Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
☆550Sep 11, 2025Updated 5 months ago
Alternatives and similar repositories for iam-vulnerable
Users that are interested in iam-vulnerable are comparing it to the libraries listed below
Sorting:
- CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool☆3,490Feb 12, 2026Updated 3 weeks ago
- A tool for quickly evaluating IAM permissions in AWS.☆1,541Aug 2, 2024Updated last year
- Automating situational awareness for cloud penetration tests.☆2,299Updated this week
- Granular, Actionable Adversary Emulation for the Cloud☆2,267Updated this week
- Create your own vulnerable by design AWS penetration testing playground☆437Feb 16, 2026Updated 2 weeks ago
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆1,978May 20, 2025Updated 9 months ago
- IAM-Deescalate helps mitigate privilege escalation risk in AWS identity and access management (IAM)☆98Sep 14, 2022Updated 3 years ago
- A graph-based tool for visualizing effective access and resource relationships in AWS environments.☆995Oct 4, 2022Updated 3 years ago
- A utility to convert your AWS CLI credentials into AWS console access.☆257May 7, 2020Updated 5 years ago
- Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized repo…☆2,185Updated this week
- A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure☆753Oct 14, 2023Updated 2 years ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,080Feb 24, 2026Updated last week
- GCPGoat : A Damn Vulnerable GCP Infrastructure☆431Oct 29, 2024Updated last year
- An encyclopedia for offensive and defensive security knowledge in cloud native technologies.☆2,532Feb 10, 2026Updated 3 weeks ago
- Unauthenticated enumeration of AWS, Azure, and GCP Principals☆283Nov 27, 2025Updated 3 months ago
- AzureGoat : A Damn Vulnerable Azure Infrastructure☆917Oct 30, 2024Updated last year
- A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.☆924Jul 25, 2019Updated 6 years ago
- An AWS IAM policy statement parser and query tool.☆198Feb 10, 2026Updated 3 weeks ago
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,881Oct 1, 2025Updated 5 months ago
- Crowdsourced list of sensitive IAM Actions☆159Oct 29, 2024Updated last year
- Automated Attack Simulation in the Cloud, complete with detection use cases.☆606Nov 28, 2024Updated last year
- Damn Vulnerable Cloud Application☆208Sep 12, 2018Updated 7 years ago
- Cloudlist is a tool for listing Assets from multiple Cloud Providers.☆1,006Updated this week
- Enumerate the permissions associated with AWS credential set☆1,222Feb 5, 2024Updated 2 years ago
- Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic☆308Jan 6, 2023Updated 3 years ago
- WeirdAAL (AWS Attack Library)☆837Jan 13, 2025Updated last year
- ☆176Apr 22, 2023Updated 2 years ago
- Awesome cloud enumerator☆1,100Mar 9, 2025Updated 11 months ago
- ☆229Feb 24, 2026Updated last week
- A collection of manifests that will create pods with elevated privileges.☆687Dec 30, 2025Updated 2 months ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,803Sep 17, 2024Updated last year
- Multi-Cloud Security Auditing Tool☆7,551Sep 23, 2025Updated 5 months ago
- Search exposed EBS volumes for secrets☆302Apr 24, 2023Updated 2 years ago
- Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on p…☆5,427Nov 18, 2025Updated 3 months ago
- Identify privilege escalation paths within and across different clouds☆718Feb 6, 2026Updated 3 weeks ago
- CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.☆292Sep 4, 2024Updated last year
- ☆614Jun 1, 2023Updated 2 years ago
- A repository of breaches of AWS customers☆795Jan 24, 2026Updated last month
- Azure Security Resources and Notes☆1,713Feb 17, 2026Updated 2 weeks ago