{"id":13649486,"url":"https://github.com/XMCyber/XMGoat","last_synced_at":"2025-04-22T14:31:47.467Z","repository":{"id":44908220,"uuid":"426994106","full_name":"XMCyber/XMGoat","owner":"XMCyber","description":null,"archived":false,"fork":false,"pushed_at":"2023-04-22T00:52:20.000Z","size":281,"stargazers_count":169,"open_issues_count":0,"forks_count":30,"subscribers_count":9,"default_branch":"main","last_synced_at":"2024-11-10T00:33:05.653Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/XMCyber.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2021-11-11T12:32:12.000Z","updated_at":"2024-11-08T18:22:28.000Z","dependencies_parsed_at":"2024-01-14T12:17:18.507Z","dependency_job_id":"145b4b4f-7f62-4f92-8e27-3fc83847fd66","html_url":"https://github.com/XMCyber/XMGoat","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/XMCyber%2FXMGoat","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/XMCyber%2FXMGoat/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/XMCyber%2FXMGoat/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/XMCyber%2FXMGoat/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/XMCyber","download_url":"https://codeload.github.com/XMCyber/XMGoat/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250259040,"owners_count":21401028,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T02:00:17.447Z","updated_at":"2025-04-22T14:31:42.456Z","avatar_url":"https://github.com/XMCyber.png","language":"HCL","funding_links":[],"categories":["Sorted by Technology and Category","Intentionally Vulnerable Challenges"],"sub_categories":[],"readme":"# XMGoat \r\n\u003cimg src=\"https://github.com/XMCyber/XMGoat/blob/main/xmgoat_new.png\" width=\"400\" height=\"400\"\u003e\r\n\r\n## Overview\r\nXM Goat is composed of XM Cyber terraform templates that help you learn about common Azure security issues. Each template is a vulnerable environment, with some significant misconfigurations. Your job is to attack and compromise the environments.\r\n\r\nHere’s what to do for each environment:\r\n\r\n1. Run installation and then get started.\r\n\r\n2. With the initial user and service principal credentials, attack the environment based on the scenario flow (for example, XMGoat/scenarios/scenario_1/scenario1_flow.png).\r\n\r\n3. If you need help with your attack, refer to the solution (for example, XMGoat/scenarios/scenario_1/solution.md).\r\n\r\n4. When you’re done learning the attack, clean up.\r\n\r\n## Requirements\r\n* Azure tenant\r\n* Terafform version 1.0.9 or above\r\n* Azure CLI\r\n* Azure User with Owner permissions on Subscription and Global Admin privileges in AAD\r\n\r\n## Installation\r\nRun these commands:\r\n```\r\n$ az login\r\n$ git clone https://github.com/XMCyber/XMGoat.git\r\n$ cd XMGoat\r\n$ cd scenarios\r\n$ cd scenario_\u003c\\SCENARIO\u003e\r\n```\r\nWhere \u003c\\SCENARIO\u003e is the scenario number you want to complete\r\n```\r\n$ terraform init\r\n$ terraform plan -out \u003c\\FILENAME\u003e\r\n$ terraform apply \u003c\\FILENAME\u003e\r\n```\r\nWhere \u003c\\FILENAME\u003e is the name of the output file\r\n\r\n## Get started\r\nTo get the initial user and service principal credentials, run the following query:\r\n```\r\n$ terraform output --json\r\n```\r\nFor Service Principals, use application_id.value and application_secret.value.\r\n\r\nFor Users, use username.value and password.value.\r\n\r\n## Cleaning up\r\nAfter completing the scenario, run the following command in order to clean all the resources created in your tenant\r\n```\r\n$ az login\r\n$ cd XMGoat\r\n$ cd scenarios\r\n$ cd scenario_\u003c\\SCENARIO\u003e\r\n```\r\nWhere \u003c\\SCENARIO\u003e is the scenario number you want to complete\r\n```\r\n$ terraform destroy\r\n```\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FXMCyber%2FXMGoat","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FXMCyber%2FXMGoat","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FXMCyber%2FXMGoat/lists"}