# RhinoSecurityLabs/cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

Repository: https://github.com/RhinoSecurityLabs/cloudgoat
Canonical: https://ross.abutalabs.com/products/cloudgoat
Language: Python
License: BSD-3-Clause
License Family: permissive
Last push: 2026-04-28T13:43:43+00:00

## Health v2 (maintenance only)
Score: 78/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 79, release rhythm 63, longevity 100
- inputs: {"age_days": 2970, "days_push": 127, "days_rel": 166, "gap_med": 35, "n_releases_24m": 8}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3708, forks 768 (observed 2026-08-28T04:08:15.130069+00:00)

## What it is
CloudGoat is Rhino Security Labs' 'Vulnerable by Design' AWS deployment tool that provisions intentionally vulnerable cloud environments for security training. It lets practitioners deploy realistic AWS misconfigurations and practice offensive and defensive cloud security techniques.

## Use cases
- practice aws penetration testing in a safe lab
- learn cloud security misconfigurations hands-on
- deploy vulnerable aws environments for training
- simulate privilege escalation scenarios in aws
- train red and blue teams on cloud attacks
- test cloud detection and response capabilities

## When to choose
- you need realistic, intentionally vulnerable AWS environments for security training
- you want to practice cloud pentesting or IAM privilege escalation techniques
- you're building cloud security labs for a team or course

## When to avoid
- you need a production-hardened AWS deployment tool
- you want vulnerability scanning of existing infrastructure rather than deploying vulnerable labs
- you work outside AWS (no Azure/GCP support)

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, infrastructure-as-code, cli
- domain: security, penetration-testing, cloud-computing, developer-tools
- platform: python, cli, cross-platform
- tags: aws, vulnerable-by-design, cloud-security, security-training, pentest-lab, terraform, devops

## Member repositories
- RhinoSecurityLabs/cloudgoat (main) score 78

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:15.130069+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:30:56.884225+00:00, confidence not recorded.
  - readme: https://github.com/RhinoSecurityLabs/cloudgoat (fetched 2026-08-28T04:08:15.130069+00:00, sha a0dc36e298a5)
- Data as of 2026-08-30T08:39:29.467469+00:00.
