EN
ENNA

cloud_enum vs CloudFox

GitHub Stats

2.1k
Stars
2.3k
294
Forks
226
3
Issues
7
8mo ago
Updated
14d ago
MIT
License
MIT
Python
Language
Go

About cloud_enum

cloud_enum is a multi-cloud OSINT tool that enumerates public resources in Amazon Web Services, Microsoft Azure, and Google Cloud Platform. Given a set of keywords, it discovers publicly accessible storage buckets (S3, Azure Blobs, GCP Buckets), web applications (Azure App Services, AWS Elastic Beanstalk), databases, and other resources that may be inadvertently exposed. It uses brute-force enumeration with configurable wordlists and mutation rules to generate permutations of target keywords, then checks each cloud provider for matching resources. This is particularly effective during the reconnaissance phase of penetration tests or bug bounty hunting, where misconfigured cloud storage is a common finding.

About CloudFox

CloudFox is a tool for identifying exploitable attack paths within cloud infrastructures. It enumerates IAM permissions, secrets, and network exposure to uncover potential vulnerabilities in AWS and Azure environments. Written in Go, CloudFox helps security professionals assess the security posture of cloud deployments by revealing misconfigurations and access control weaknesses. The tool is essential for cloud security audits and penetration testing.

Platform Support

🐧linux🍎macos🪟windows
🐧linux🍎macos🪟windows

Tags

cloud_enum only

cloud-osints3azure-blobsgcp-bucketsenumerationmulti-cloud

CloudFox only

cloud-attack-pathsiam-enumerationawsazure