TerraGoat Logo

TerraGoat

TerraGoat is a deliberately vulnerable Terraform repository that demonstrates common cloud infrastructure misconfigurations for training and testing security tools.

1,219
Cloud Security
Free
Visit website
0

TerraGoat Description

TerraGoat is a deliberately vulnerable Terraform repository created by Bridgecrew that contains intentional cloud infrastructure misconfigurations. The tool serves as a training and testing environment for DevSecOps teams to understand common security issues in cloud deployments. It demonstrates various configuration errors that typically occur in production cloud environments across different cloud providers. TerraGoat enables security professionals to practice identifying and remediating infrastructure misconfigurations. The repository provides examples of vulnerable Terraform code that can be used to test policy-as-code frameworks and security scanning tools. The tool supports testing and validation of infrastructure security tools like Checkov and other static analysis solutions. It helps teams develop and refine their misconfiguration prevention strategies by providing realistic examples of problematic configurations. TerraGoat includes various types of cloud security misconfigurations spanning compute, storage, networking, and identity management services. The vulnerable configurations are designed to mirror real-world scenarios that security teams encounter in production environments.

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

11
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

6
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →