RhinoSecurityLabs / cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
BSD 3-Clause "New" or "Revised" License
2.88k stars 597 forks source link

263 Feature Request: Scenario Template & Contribution Guide #264

Closed TeneBrae93 closed 1 week ago

TeneBrae93 commented 3 months ago

Overview of Changes

TeneBrae93 commented 3 months ago

Good catch @andrew-aiken on the existing template (didn't even realize that) - and neither did the people I talked to at Rhino when we discussed this. It's also pretty light on details (doesn't show whitelisting a public resource like an EC2 which is a specific problem we ran into with a community-submitted scenario - the EC2 is public on the internet).

I added a new commit that just removes this old one entirely, and puts this new one in the scenario folder. I think this makes it easier for people to find; also by adding it to the main README's contribution guidelines, this one should be less hidden.

Finally, I noticed some things I missed (manifest.yml in particular), so I added that to the new scenario template.