
AzureGoat: A Vulnerable by Design Infrastructure
AzureGoat is an intentionally vulnerable infrastructure hosted on Azure. It showcases the most recent OWASP Top 10 web application security risks (2021) along with various misconfigurations across services such as App Functions, CosmosDB, Storage Accounts, Automation, and Identities. AzureGoat is designed to replicate real-world infrastructure while incorporating additional vulnerabilities.
It features multiple escalation paths and misconfigurations
It includes various escalation paths and misconfigurations that enable attackers to gain control over the entire infrastructure.
AzureGoat is specifically designed to assist security professionals and penetration testers in honing their skills and assessing their knowledge within a realistic and challenging environment.