OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws
☆330Jul 30, 2024Updated last year
Alternatives and similar repositories for Serverless-Goat
Users that are interested in Serverless-Goat are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Serverless Architectures Security Top 10 Guide☆339Oct 24, 2019Updated 6 years ago
- OWASP Serverless Top 10☆217Jul 6, 2021Updated 5 years ago
- a Damn Vulnerable Serverless Application☆545Sep 12, 2023Updated 2 years ago
- A deliberately vulnerable web application for learning web application security.☆160Apr 28, 2025Updated last year
- Lambda-Proxy creates an HTTP proxy listening on localhost port 8082. When it receives an HTTP POST request with a very specific structure…☆37Jan 11, 2019Updated 7 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- An AWS Lambda vulnerable application written in flask.☆51Oct 9, 2017Updated 8 years ago
- Damn Vulnerable Cloud Application☆211Sep 12, 2018Updated 7 years ago
- Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates ho…☆99Aug 5, 2024Updated last year
- CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool☆3,672Apr 28, 2026Updated 2 months ago
- A deliberately vulnerable Kubernetes cluster☆133Dec 15, 2023Updated 2 years ago
- CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that demonstrates how commo…☆48May 9, 2023Updated 3 years ago
- Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.☆558Jul 13, 2025Updated last year
- This script is used to generate some basic detections of the aws security services☆73Feb 21, 2022Updated 4 years ago
- A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure☆784Oct 14, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A curated list of awesome serverless security resources such as (e)books, articles, whitepapers, blogs and research papers.☆634May 5, 2022Updated 4 years ago
- Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.☆578Mar 12, 2026Updated 4 months ago
- TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how…☆1,302Jul 13, 2025Updated last year
- A very vulnerable serverless application in AWS Lambda☆99Oct 7, 2019Updated 6 years ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,279May 19, 2026Updated 2 months ago
- Multi-Cloud Security Auditing Tool☆7,755Sep 23, 2025Updated 9 months ago
- Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions☆248Mar 27, 2026Updated 3 months ago
- OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS☆451Dec 29, 2025Updated 6 months ago
- Test utility for cve-2018-1002105☆192Dec 13, 2018Updated 7 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Repository for all the workshop content delivered at nullcon X on 1st of March 2019☆80Apr 4, 2019Updated 7 years ago
- The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Nod…☆2,054Jun 15, 2024Updated 2 years ago
- Collection of scripts that aid in penetration testing of JSON Web Tokens☆59Feb 2, 2019Updated 7 years ago
- ☆11Oct 3, 2014Updated 11 years ago
- Serverless plugin for least privileges.☆250Aug 22, 2021Updated 4 years ago
- A tool for quickly evaluating IAM permissions in AWS.☆1,568Aug 2, 2024Updated last year
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆2,038May 20, 2025Updated last year
- AWS Serverless Security☆400Jul 13, 2022Updated 4 years ago
- Damn Vulnerable Thick Client App☆157Jun 21, 2026Updated 3 weeks ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Utility script to test zip file upload functionality (and possible extraction of zip files) for vulnerabilities (aka Zip Slip)☆32May 31, 2019Updated 7 years ago
- barq: The AWS Cloud Post Exploitation framework!☆389Nov 19, 2022Updated 3 years ago
- Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities☆136Dec 8, 2022Updated 3 years ago
- AzureGoat : A Damn Vulnerable Azure Infrastructure☆954Oct 30, 2024Updated last year
- A collection of AWS penetration testing junk☆1,222Aug 30, 2023Updated 2 years ago
- This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory☆884Updated this week
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆136Apr 28, 2020Updated 6 years ago