A self-hosted, deliberately vulnerable cloud lab for authorized security training and AI-agent benchmarking. Run the interactive Python entrypoint on macOS, Linux, Windows, or WSL to create the lab in an AWS, Azure, or GCP scope that you own.
Caution
This project creates weak identities, exposed synthetic data, mutable
workloads, and optionally destructive permissions. Use a dedicated, disposable,
non-production cloud account. Your workstation and Terraform state must stay
outside the lab. Nothing cleans up automatically. You run
python3 cloudrange.py --teardown RANGE_ID yourself. Read
Safety and isolation before setup.
New here? Start with the operator guide.
- A realistic lab. Identities, networks, storage, secrets, compute, serverless, messaging, and registries that interact instead of isolated, one-off simulations.
- 239 catalogued weaknesses, each with a permanent
BAR-*ID, grouped into 44 categories. See what is vulnerable in the lab. - A benchmark harness. Run repeatable agent evaluations and score the results offline.
- Safe defaults. Public exposure, destructive paths, costly services, host access, and tenant-wide paths are each a separate opt-in.
flowchart LR
A[Clone repository] --> B[Log in to provider]
B --> C["setup<br/>builds control plane"]
C --> D["plan<br/>saves a bound plan"]
D --> E["deploy<br/>builds the weak lab"]
E --> F[Verify and test]
F --> G["teardown<br/>you run this"]
G --> H["verify-clean<br/>proves it is gone"]
setup builds the control plane; deploy builds the vulnerable lab.
Python 3.11 or newer is required. Install Python,
Git, Terraform 1.8+, and the CLI for your provider (aws, az, or gcloud).
Open either coding agent and paste this prompt:
Set up Cloud Attack Range from https://github.com/bugbasesecurity/cloud-attack-range on this machine. Read
README.mdanddocs/wiki/setup.md. Ask me the questions needed to choose the configuration, then follow the documented workflow. Stop before deployment so I can review the plan.
git clone https://github.com/bugbasesecurity/cloud-attack-range.git
cd cloud-attack-range
python3 cloudrange.py --helpKeep this checkout in place until teardown and verify-clean finish. On
native Windows, run py -3 cloudrange.py --setup. If preflight reports missing
tools, run python3 cloudrange.py --install-deps --provider aws, replacing
aws with your provider.
Set a provider budget alert before you start.
python3 cloudrange.py --preflight --provider aws # read-only check of this machine
aws login --profile range-bootstrap # or: az login / gcloud auth login
python3 cloudrange.py --setup # wizard; builds the control plane
python3 cloudrange.py --doctor RANGE_ID # readiness report
python3 cloudrange.py --plan RANGE_ID # saved, digest-bound plan
python3 cloudrange.py --deploy RANGE_ID # creates the vulnerable lab
python3 cloudrange.py --status RANGE_IDAzure setup cannot create the disposable Entra tenant or its first subscription. Create both manually. On a remote machine, select them with:
az login --use-device-code --tenant YOUR_DISPOSABLE_TENANT_ID
az account set --subscription YOUR_DISPOSABLE_SUBSCRIPTION_IDSee Azure bootstrap for the required IDs and roles.
When you are done, run:
python3 cloudrange.py --teardown RANGE_ID
python3 cloudrange.py --verify-clean RANGE_IDFull walkthrough: Setup from zero.
| Preset | Cloud layout | Use it for |
|---|---|---|
Core Safe |
One AWS, Azure, or GCP scope | First run, single-cloud benchmarking |
Containers |
Core plus EKS, AKS, or GKE and attack pods | Kubernetes and workload identity |
Advanced |
One provider, individually selected controls | Broader reviewed campaigns |
Advanced does not enable everything; each control is confirmed separately.
A Range ID is the permanent name of a lab instance, such as
research-aws-01. Setup asks you to choose one, and lifecycle commands use it
to identify the range. It cannot be renamed or reused. See the
Range ID contract.
The benchmark harness provides a provider-neutral run format and offline scorer. The solutions are published in what is vulnerable in the lab, so keep evaluated models away from that page and this repository. See the benchmark protocol.
Apache License 2.0. The license does not authorize testing systems you do not own.
