rhinosecuritylabs/cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 55 minutes ago
Added to GitGenius on September 18th, 2026
Created on July 17th, 2018
Open Issues & Pull Requests: 23 (+0)
GitHub issues: Enabled
Number of forks: 771
Total Stargazers: 3,732 (+0)
Total Subscribers: 68 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 7.0 hours
Mean response time: 20.3 days
90th percentile: 18.3 days
Tracked items: 31

Most active contributors

Sign in to see contributor activity.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 12
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 497 days
Stale 30+ days: 12
Stale 90+ days: 10

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • enhancement (5)
  • docker (1)
  • good first issue (1)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

CloudGoat is a vulnerable-by-design AWS deployment tool that creates intentionally flawed cloud infrastructure for security testing and training purposes.

The tool addresses the need for realistic, hands-on environments where security professionals can practice identifying and exploiting AWS misconfigurations. Rather than studying vulnerabilities in isolation, CloudGoat deploys complete vulnerable scenarios into AWS accounts, allowing practitioners to discover and exploit real cloud security weaknesses in a controlled setting. The tool automates the provisioning of these deliberately insecure architectures, eliminating the manual effort of building test environments from scratch.

CloudGoat suits security teams, penetration testers, and developers who want to learn AWS security through practical exploitation. It works well for organizations conducting internal security training, red team exercises, or proof-of-concept assessments in their own AWS environments. The tool is particularly valuable for those who need reproducible vulnerable scenarios rather than generic security labs, since each scenario is a complete, deployable AWS infrastructure with specific misconfigurations built in.

The project maintains active engagement with contributions and pull requests welcomed. Development activity shows ongoing refinement of existing scenarios and tooling to support current AWS practices.