CloudGoat is Rhino Security Labs' 'Vulnerable by Design' AWS deployment tool that allows users to hone their cloud cybersecurity skills through 'capture-the-flag' style scenarios. Each scenario is composed of AWS resources to create structured learning experiences, offering both easy and hard challenges with multiple paths to victory. The tool aims to provide focused, curated, high-quality learning experiences with good documentation.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A cheatsheet for understanding privilege escalation with examples, not for enumeration using Linux Commands.
A collection of security vulnerabilities in regular expressions used in WAFs with a focus on bypass examples and high severity issues.
A comprehensive guide to mobile application penetration testing, covering various topics and techniques
Security cheatsheets to aid penetration testers and security enthusiasts in remembering useful but not frequently used commands.
Curated list of acronyms and terms related to cyber security landscape with explanations beyond buzzwords.
A comprehensive SQL injection cheat sheet covering various database management systems and techniques.
A comprehensive educational resource that provides structured guidance on penetration testing methodology, tools, and techniques organized around the penetration testing attack chain.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.