orange-cyberdefense/goad

game of active directory

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 37 minutes ago
Added to GitGenius on September 8th, 2026
Created on September 27th, 2021
Open Issues & Pull Requests: 151 (+0)
GitHub issues: Enabled
Number of forks: 1,135
Total Stargazers: 8,298 (+0)
Total Subscribers: 100 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 3.7 days
Mean response time: 25.5 days
90th percentile: 82.8 days
Tracked items: 188

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 100% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Only 6% of issues opened in the past year have been closed. Three people close 63% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 107
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 511 days
Stale 30+ days: 107
Stale 90+ days: 102

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • v3 (8)
  • bug (5)
  • enhancement (4)
  • windows (4)
  • good first issue (2)
  • proxmox (1)
  • v2 (1)

Detailed Description

GOAD is a pentest Active Directory lab project that provides vulnerable Windows environments for practicing attack techniques.

The tool addresses the need for realistic Active Directory infrastructure to train on without risk to production systems. It uses infrastructure-as-code approaches with Terraform and Vagrant to provision virtual machines, combined with Ansible and PowerShell for configuration. The lab intentionally includes common misconfigurations and security weaknesses found in real Active Directory deployments, allowing pentesters to practice reconnaissance, lateral movement, privilege escalation, and other standard attack chains in a controlled setting.

Adoption suits pentesters and security professionals who need hands-on practice with Active Directory exploitation. The project offers multiple lab variants scaled to different hardware constraints: a full lab with multiple forests and domains, a lighter version for resource-limited machines, a minimal two-VM setup, and specialized labs featuring Microsoft Configuration Manager or challenge scenarios without provided network diagrams. This flexibility means you can choose a configuration matching your available compute resources and learning goals. The tool is explicitly designed for pentest practice and should not be used as a template for production environments due to its intentionally vulnerable configuration.

The project maintains active development with regular updates to lab configurations and documentation. The codebase shows ongoing refinement of deployment automation and lab scenarios. Community contributions indicate sustained engagement with the pentest training use case. Documentation is comprehensive and regularly maintained to support users deploying and working through the various lab configurations.