{"repo":"0xsha/CloudBrute","free":true,"listed":false,"github":"https://github.com/0xsha/CloudBrute","clone":"git clone https://github.com/0xsha/CloudBrute.git","description":"Awesome cloud enumerator","language":"Go","stars":1144,"topics":["bugbounty","cloud","cloud-security","s3-bucket","amazon","vultr","google","linode","cloud-storage","pentesting"],"license":"MIT","category":"security-tools","readme_excerpt":"CloudBrute A tool to find a company (target) infrastructure, files, and apps on the top cloud providers (Amazon, Google, Microsoft, DigitalOcean, Alibaba, Vultr, Linode). The outcome is useful for bug bounty hunters, red teamers, and penetration testers alike. The complete writeup is available. here At a glance Motivation we are always thinking of something we can automate to make black-box security testing easier. We discussed this idea of creating a multiple platform cloud brute-force hunter.mainly to find open buckets, apps, and databases hosted on the clouds and possibly app behind proxy servers. Here is the list issues on previous approaches we tried to fix: - separated wordlists - lack of proper concurrency - lack of supporting all major cloud providers - require authentication or keys or cloud CLI access - outdated endpoints and regions - Incorrect file storage detection - lack support for proxies (useful for bypassing region restrictions) - lack support for user agent randomization (useful for bypassing rare restrictions) - hard to use, poorly configured Features - Cloud detection (IPINFO API and Source Code) - Supports all major providers - Black-Box (unauthenticated) - Fast (concurrent) - Modular and easily customizable - Cross Platform (windows, linux, mac) - User-Agent Randomization - Proxy Randomization (HTTP, Socks5) Supported Cloud Providers Microsoft: - Storage - Apps Amazon: - Storage - Apps Google: - Storage - Apps DigitalOcean: - storage Vultr: - Storage Li","default_branch":null,"files":null,"tree":[],"storefront":"/r/0xsha","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/0xsha/CloudBrute/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}