EN
ENNA

cloud_enum vs CloudSploit

GitHub Stats

2.1k
Stars
3.7k
294
Forks
739
3
Issues
207
8mo ago
Updated
1mo ago
MIT
License
GPL-3.0
Python
Language
JavaScript

About cloud_enum

cloud_enum is a multi-cloud OSINT tool that enumerates public resources in Amazon Web Services, Microsoft Azure, and Google Cloud Platform. Given a set of keywords, it discovers publicly accessible storage buckets (S3, Azure Blobs, GCP Buckets), web applications (Azure App Services, AWS Elastic Beanstalk), databases, and other resources that may be inadvertently exposed. It uses brute-force enumeration with configurable wordlists and mutation rules to generate permutations of target keywords, then checks each cloud provider for matching resources. This is particularly effective during the reconnaissance phase of penetration tests or bug bounty hunting, where misconfigured cloud storage is a common finding.

About CloudSploit

CloudSploit is an open-source security configuration scanner for cloud environments, including AWS, Azure, GCP, and Oracle Cloud. It detects misconfigurations and security risks by analyzing cloud service settings against best practices. Written in JavaScript, CloudSploit is used by security teams to identify vulnerabilities in cloud infrastructure and ensure compliance with security standards. Its comprehensive coverage makes it a critical tool for cloud security monitoring.

Platform Support

🐧linux🍎macos🪟windows
🐧linux🍎macos🪟windows

Tags

cloud_enum only

cloud-osints3azure-blobsgcp-bucketsenumerationmulti-cloud

CloudSploit only

cloud-securitymisconfigurationawsazure