37 lines
1.8 KiB
Markdown
37 lines
1.8 KiB
Markdown
# Awesome Cloud Security Labs
|
|
|
|
A list of free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.
|
|
|
|
## Sorted
|
|
|
|
|
|
| Name | Technology | Category | Author | Notes |
|
|
| :------------- |:-------------:| :-----:| :-----: | :------: |
|
|
| [AWS CIRT Workshop](https://aws.amazon.com/blogs/security/aws-cirt-announces-the-release-of-five-publicly-available-workshops/) | AWS | Self-hosted, guided vulnerability lab | AWS CIRT | Build with Cloudformation |
|
|
| [CloudGoat](https://github.com/RhinoSecurityLabs/cloudgoat) | AWS | Self-hosted, guided vulnerability lab | Multiple, [Rhino Security Labs](https://rhinosecuritylabs.com/) | Python orchestration of terraform |
|
|
| [Attacking and Defending Serverless Applications](https://attack-defend-serverless.sanscloudwars.com/) | AWS | Self-hosted, guided vulnerability lab | [Ryan Nicholson](https://twitter.com/ryananicholson) | Attack and defend a Lambda that you build in your own AWS account with author provided terraform |
|
|
| [flaws.cloud](http://flaws.cloud) | AWS | Author-hosted, CTF challenge | [Scott Piper](https://twitter.com/0xdabbad00) | Challenge style with levels and clues |
|
|
| [flaws2.cloud](http://flaws2.cloud) | AWS | Author-hosted, CTF challenge | [Scott Piper](https://twitter.com/0xdabbad00) | Challenge style Attacker and Defender paths |
|
|
| [Sadcloud](https://github.com/nccgroup/sadcloud) | AWS | Self-hosted | Multiple, [NCC Group](https://www.nccgroup.com) | Terraform code; not guided like CloudGoat |
|
|
| [Broken Azure](https://www.brokenazure.cloud/) | Azure | Author-hosted, CTF challenge | [Secura](https://www.nccgroup.com) | Provides hints, build your own at their Github |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
## AWS
|
|
|
|
## Azure
|
|
|
|
## GCP
|
|
|
|
## Kubernetes
|
|
|
|
## Container
|
|
|
|
## Terraform
|
|
|
|
## Research Labs
|
|
|