Security News > 2023 > October > GOAD: Vulnerable Active Directory environment for practicing attack techniques

GOAD: Vulnerable Active Directory environment for practicing attack techniques
2023-10-26 04:00

It provides a vulnerable Active Directory environment for pen testers to practice common attack methods.

"When the Zerologon vulnerability surfaced, it highlighted our urgent need for a test lab at work. Furthermore, a training lab became essential to adequately prepare our new pentesters for internal assessments. It's clear: necessity was the birthplace of this idea," Mayfly, pentester at Orange Cyberdefense and creator of GOAD, told Help Net Security.

"The community's feedback has been overwhelmingly positive. I've heard of educators in Australia and Brazil repurposing the lab for their classes - an opportunity I wish I'd had during my studies. Many, including my colleagues, utilize it to practice both classic and emerging attack techniques and to prep for specialized certifications like OSCP, CRTE, and OSEP,".

Requirements and download. The total space needed for the lab is ~115 GB. GOAD is available for free on GitHub.

Important to keep in mind: GOAD is highly vulnerable.

Refrain from reusing recipes to construct your environment and never deploy this setting on the internet without ensuring it's isolated.


News URL

https://www.helpnetsecurity.com/2023/10/26/goad-game-of-active-directory/