OWASP EKS Goat

OWASP EKS Goat is a hands-on AWS EKS security lab that teaches real-world attack and defense techniques for AWS managed Kubernetes clusters.

The lab simulates realistic attack paths and defense mechanisms including misconfigured IAM roles, IRSA abuse, ECR image backdooring, RBAC privilege escalation, and pod-to-node breakout. Participants walk through both the offensive and defensive scenarios.

Attack Scenarios (includes CVE-2024-23897):

  • Exploit Jenkins CVE to leak IAM credentials via IMDSv2.

  • Backdoor ECR images using leaked credentials.

  • Deploy compromised image into the EKS cluster.

  • Escalate privileges and breakout from pod to EC2 node.

  • Abuse IAM roles to exfiltrate data from S3.

Defense Scenarios:

  • Audit cluster state using Kubescape, Kubebench, and Hadolint.

  • Implement Pod Security Context and enforce policies with Kyverno (CEL).

  • Detect runtime behavior with eBPF-based Tetragon.

  • Scan and lock down ECR repositories.

  • Integrate AWS GuardDuty for monitoring.

About OWASP EKS Goat

Project Leaders

Divyanshu Shukla

Divyanshu Shukla

Project lead

Senior security engineer experienced in Cloud Security, Kubernetes Security, DevSecops, Web Application Pentesting, and Threat Modelling. Reported multiple vulnerabilities to companies like Airbnb, Google, Microsoft, AWS, Apple, Amazon, Samsung, Zomato, Xiaomi, Alibaba, Opera, Protonmail, Mobikwik, etc, and received CVE-2019-8727 CVE-2019-16918, CVE-2019-12278, CVE-2019-14962 for reporting issues. Currently co-lead of OWASP EKS Goat, OWASP GKE Goat, Author of Burp-o-mation and a very-vulnerable-serverless application. Also part of AWS Community Builder for security and Defcon Cloud Village crew member 2020/2021/2022. Delivered talks at events like Blackhat Europe, Seasides, C0c0n, Nullcon, Brucon, Bsides Bangalore and Bsides Ahmedabad. Also winner of "Cybersecurity samurai 2023" at Bsides Bangalore 2023 & "Cloud Security Champion'' at CSA Bangalore 2023. Reach out at peachycloudsecurity[dot]com

EmailSocial

Anjali Shukla

Anjali Shukla

Project lead

Anjali is a seasoned cloud security engineer experienced in DevSecOps and Kubernetes security (EKS/GKE) as well as AWS, Azure, and GCP security. She is the founder of Container Security Village and Kubernetes Village, communities dedicated to enhancing cloud-native security. As the project lead for OWASP EKS Goat, she focuses on AWS EKS security research and hands-on exploitation paths. Anjali is a recognized AWS Community Builder and actively shares her research through her YouTube channel, @peachycloudsecurity. Her extensive speaking history includes Black Hat Spring USA, Black Hat Europe, Nullcon, Seasides Goa, BSides Bangalore, CSA Bangalore, and C0c0n. She has also contributed to the community by volunteering at Cloud Village at DEF CON and various BSides events globally.Reach out at peachycloudsecurity[dot]com

EmailSocial

Project Information

Incubator Project
Classification
Other
Language
Shell
License
GNU General Public License v3.0
Contributors
6
GitHub Stars
51
Downloads
0
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP EKS Goat | OWASP Foundation