Loading...
TerraGoat is a deliberately vulnerable Terraform repository that demonstrates common cloud infrastructure misconfigurations for training and testing security tools.

TerraGoat is a deliberately vulnerable Terraform repository that demonstrates common cloud infrastructure misconfigurations for training and testing security tools.
TerraGoat is a deliberately vulnerable Terraform repository created by Bridgecrew that contains intentional cloud infrastructure misconfigurations. The tool serves as a training and testing environment for DevSecOps teams to understand common security issues in cloud deployments. It demonstrates various configuration errors that typically occur in production cloud environments across different cloud providers. TerraGoat enables security professionals to practice identifying and remediating infrastructure misconfigurations. The repository provides examples of vulnerable Terraform code that can be used to test policy-as-code frameworks and security scanning tools. The tool supports testing and validation of infrastructure security tools like Checkov and other static analysis solutions. It helps teams develop and refine their misconfiguration prevention strategies by providing realistic examples of problematic configurations. TerraGoat includes various types of cloud security misconfigurations spanning compute, storage, networking, and identity management services. The vulnerable configurations are designed to mirror real-world scenarios that security teams encounter in production environments.
Common questions about TerraGoat including features, pricing, alternatives, and user reviews.
TerraGoat is TerraGoat is a deliberately vulnerable Terraform repository that demonstrates common cloud infrastructure misconfigurations for training and testing security tools.. It is a Cloud Security solution designed to help security teams with Policy, Education, Infrastructure As Code.
CSPM tool for detecting and remediating cloud misconfigurations
IaC security scanning for Kubernetes, Terraform, CloudFormation, and ARM templates
Enforces preventive cloud security guardrails to block misconfigs & shadow IT.
Get strategic cybersecurity insights in your inbox