AWS Pentesting Lab

Pentesting lab with a Kali Linux instance accessible via ssh & wireguard VPN and with vulnerable instances in a private subnet

Blockchain & Cloud ComputingRubyBSD-3-Clause

Abstract

AWS Pentesting Lab is an open-source Blockchain & Cloud Computing project. Pentesting lab with a Kali Linux instance accessible via ssh & wireguard VPN and with vulnerable instances in a private subnet. PenTesting laboratory deployed as IaC with Terraform on AWS. It deploys a Kali Linux instance accessible via ssh & wireguard VPN. It is built using Ruby, Terraform, AWS. Key capabilities include: User management; Automatically create non privileged users in kali instance with rsa; Wireguard VPN client file per user. The complete source code is publicly available on GitHub under the BSD 3-Clause "New" or "Revised" License, making it a useful reference for students building a Blockchain & Cloud Computing mini project or final-year project.

1. Introduction

PenTesting laboratory deployed as IaC with Terraform on AWS. It deploys a Kali Linux instance accessible via ssh & wireguard VPN. Vulnerable instances in a private subnet.

2. Objective

Pentesting lab with a Kali Linux instance accessible via ssh & wireguard VPN and with vulnerable instances in a private subnet

This project demonstrates how Ruby, Terraform, AWS can be applied to a real-world Blockchain & Cloud Computing problem.

3. Key Features / Modules

  • User management
  • Automatically create non privileged users in kali instance with rsa
  • Wireguard VPN client file per user
  • Command line audit logging in syslog
  • auditd enabled with sudo_log and users_log keys for auditing user actions (see also ausearch command)
  • ToDO: Forward terminal audit to CloudWatch or an S3 Bucket with write once policy

4. Technology Stack

RubyTerraformAWS
  • Kali instance (private key is saved into kali.pem)
  • Wireguard VPN service: client file client_vpn.wg
  • Accessible via ssh/scp
  • Public Subnet 10.0.0.5/24
  • Infection Monkey running on port 5000 (only accesible via vpn or ssh)
  • Vulnerable machine "Metasploitable" (ami build is public)
  • Private subnet 10.0.1.5/24
  • More vulnerable labs/machines/docker (to-be-done)

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Ruby and Bundler
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/juanjoSanz/aws-pentesting-lab.git
cd aws-pentesting-lab
  1. Enable/disable vulnerable instances to be deployed setting 0 or 1 in variables.tf:
  2. Use terraform for deploy infraestructure
  3. SSH: (Only command line) Use autogenerated private key (see terraform output)
  4. Wireguard: Connect your local kali instance via wireguard (see client_vpn.wg generated file)
variable "deploment-control" {
  type = map
  default = {
    #"instance" = 0 or 1, to disable or enable
    "metasploitable3" = 1
    "dvca" = 0
  }
  description = "Control which EC2 instances are deployed, 0 for none or 1"
}
terraform init
terraform plan
terraform apply -auto-approve
KALI_IP=<KALI_IP>     # configure kali public ip
ssh -i kali.pem -o StrictHostKeyChecking=no -o IdentitiesOnly=yes kali@${KALI_IP}
KALI_IP=<KALI_IP>     # configure kali public ip
scp -i kali.pem -o StrictHostKeyChecking=no IdentitiesOnly=yes kali@${KALI_IP}:/home/kali/client_vpn.wg .

####
(local_kali)$ sudo apt-get install –y wireguard
(local_kali)$ sudo gedit /etc/wireguard/wg0.conf # copy contents of client_vpn.wg
(local_kali)$ sudo chmod 700 /etc/wireguard/wg0.conf
(local_kali)$ sudo wg-quick up wg0

(local_kali)$ ping 10.0.0.5  # test connectivity with kali instance in AWS

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add a CI/CD pipeline with GitHub Actions
  • Deploy to a public test network or cloud free tier
  • Add monitoring and cost alerts

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Why does this problem need a blockchain or cloud-native design?
  2. Explain the smart contract / infrastructure components and how they interact.
  3. How are gas costs or cloud costs kept under control?
  4. How is the system secured (keys, IAM, access control)?
  5. How would the solution scale to many more users?

9. Source Code & License

This project is developed by juanjoSanz and published on GitHub under the BSD 3-Clause "New" or "Revised" License. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Blockchain & Cloud Computing project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Blockchain & Cloud Computing Internship