# Orange-Cyberdefense/GOAD

game of active directory

Repository: https://github.com/Orange-Cyberdefense/GOAD
Canonical: https://ross.abutalabs.com/products/goad
Language: PowerShell
License: GPL-3.0
License Family: copyleft
Topics: active-directory, infrastructure-as-code, pentest, ansible, terraform, vagrant
Last push: 2026-03-12T06:57:44+00:00

## Health v2 (maintenance only)
Score: 64/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 71, release rhythm 35, longevity 100
- inputs: {"age_days": 1801, "days_push": 174, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 8240, forks 1126 (observed 2026-08-28T04:10:19.811697+00:00)

## What it is
GOAD (Game Of Active Directory) is a pentest lab project that provisions intentionally vulnerable Active Directory environments using Vagrant, Ansible, and Terraform. It provides multiple lab configurations of varying sizes so pentesters can practice common AD attack techniques locally.

## Use cases
- practice active directory attack techniques in a safe lab
- build a vulnerable AD environment for pentest training
- learn kerberoasting, delegation attacks, and domain escalation
- set up a multi-domain multi-forest test lab with vagrant
- train for AD-focused certifications like CRTP or OSCP
- test red team tooling against a realistic AD setup

## When to choose
- you need a realistic, intentionally vulnerable Active Directory lab for practice
- you want automated lab deployment with Vagrant/Ansible/Terraform
- you are training pentesters or preparing for AD attack certifications

## When to avoid
- you need a hardened production Active Directory template - the lab is deliberately insecure
- you lack the hardware resources to run multiple Windows VMs
- you need a cloud-hosted or internet-exposed environment - it must be isolated

## Facets
- artifact type: infra-config
- maturity: active
- function: infrastructure-as-code, penetration-testing, security
- domain: security, penetration-testing
- platform: windows
- tags: active-directory, pentest-lab, ansible, terraform, vagrant, vulnerable-by-design, training-lab, devops, linux, macos, virtualbox

## Member repositories
- Orange-Cyberdefense/GOAD (main) score 64

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:19.811697+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:29:29.476585+00:00, confidence not recorded.
  - readme: https://github.com/Orange-Cyberdefense/GOAD (fetched 2026-08-28T04:10:19.811697+00:00, sha 5c511f6b5377)
- Data as of 2026-08-30T08:39:29.467469+00:00.
