Ross ROSS = Recommend OSS · open-source software intelligence for agents

RhinoSecurityLabs/cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool observed · 2026-08-28

github.com/RhinoSecurityLabs/cloudgoat · Python · BSD-3-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

78/100

  • Activity 79
  • Release rhythm 63
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 35
  • age_days: 2970
  • days_rel: 166
  • days_push: 127
  • n_releases_24m: 8

Full methodology

Adoption not part of the score

3708 stars · 768 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

CloudGoat is Rhino Security Labs' 'Vulnerable by Design' AWS deployment tool that provisions intentionally vulnerable cloud environments for security training. It lets practitioners deploy realistic AWS misconfigurations and practice offensive and defensive cloud security techniques.

Use cases

  • practice aws penetration testing in a safe lab
  • learn cloud security misconfigurations hands-on
  • deploy vulnerable aws environments for training
  • simulate privilege escalation scenarios in aws
  • train red and blue teams on cloud attacks
  • test cloud detection and response capabilities

When to choose

  • you need realistic, intentionally vulnerable AWS environments for security training
  • you want to practice cloud pentesting or IAM privilege escalation techniques
  • you're building cloud security labs for a team or course

When to avoid

  • you need a production-hardened AWS deployment tool
  • you want vulnerability scanning of existing infrastructure rather than deploying vulnerable labs
  • you work outside AWS (no Azure/GCP support)

Facets

cli-tool · maturity active

security penetration-testing infrastructure-as-code cli security penetration-testing cloud-computing developer-tools python cli cross-platform aws vulnerable-by-design cloud-security security-training pentest-lab terraform devops

1 source

Member repositories

RepositoryRoleHealth v2
RhinoSecurityLabs/cloudgoatmain78

For agents

markdown · JSON · MCP: product_card(name="RhinoSecurityLabs/cloudgoat")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem