CloudBrute vs WeirdAAL
GitHub Stats
About CloudBrute
CloudBrute is an enumeration tool used to discover cloud assets across multiple cloud service providers. By leveraging publicly accessible APIs and services, it identifies exposed company resources and infrastructure components. CloudBrute is capable of scanning for assets on popular platforms like AWS, Azure, and Google Cloud, offering insights into potential security exposures. Its utility lies in its ability to provide a comprehensive view of an organization's cloud footprint, aiding in asset management and security assessments.
About WeirdAAL
WeirdAAL (AWS Attack Library) is a Python framework for offensive testing of Amazon Web Services environments. It organizes AWS attacks into categorized modules covering enumeration (listing resources, permissions, and configurations across services), exploitation (abusing misconfigurations and excessive permissions), and persistence (creating backdoor access). WeirdAAL supports testing across a wide range of AWS services including IAM, EC2, S3, Lambda, STS, CloudTrail, and many others. Each module performs a specific action - from enumerating all S3 buckets and their ACLs, to checking for privilege escalation paths through IAM policy misconfigurations, to creating persistence mechanisms via Lambda backdoors. WeirdAAL uses boto3 and works with standard AWS credential configurations, making it easy to test with compromised or provided access keys.
Platform Support
Tags
Shared
CloudBrute only
WeirdAAL only