Tools: cloud-infrastructure (23)
Pentesting tools tagged cloud-infrastructure. See all tools or the category key.
AADInternals (T)
PowerShell toolkit for Azure AD and Entra ID assessment, including tenant reconnaissance and hybrid identity attack-path analysis.
Amass (T)
Advanced attack surface mapping framework for DNS and subdomain enumeration with graph correlation and extensive data-source support.
AWSBucketDump (T)
Python tool that enumerates AWS S3 buckets and optionally downloads accessible objects using keyword and pattern-based discovery.
BucketLoot (T)
Open-source cloud bucket discovery utility with limited current documentation and unclear maintenance signals.
Checkov (T)
Infrastructure-as-code security scanner that checks Terraform, CloudFormation, Kubernetes, and other cloud configs against policy rules.
Cloud Custodian (T)
Policy-as-code engine for cloud governance and security that can detect and remediate risky cloud configurations.
cloud_enum (T)
Multi-cloud enumeration tool that looks for exposed AWS, Azure, and GCP storage assets from target naming patterns.
dnsrecon (T)
DNS enumeration script for recon workflows, supporting record discovery, zone transfer checks, brute-force, and reverse lookups.
GCPBucketBrute (T)
Google Cloud Storage bucket enumeration utility for identifying publicly accessible or weakly protected buckets.
goblob (T)
Go-based Azure blob storage enumeration utility designed for fast discovery of publicly exposed containers and blobs.
lazys3 (T)
S3 bucket brute-forcing utility that generates candidate names from permutations and checks bucket accessibility.
MicroBurst (T)
PowerShell collection focused on Azure security assessment, including subscription discovery and cloud service misconfiguration checks.
Prowler (T)
Cloud security posture and compliance assessment framework covering AWS, Azure, GCP, Kubernetes, and SaaS surfaces.
Public Buckets
Search interface for publicly indexed cloud object storage buckets and files across multiple providers.
ROADtools (T)
Azure AD exploration framework for dumping tenant objects, principals, and permissions to support attack-path and privilege analysis.
S3Scanner (T)
Command-line scanner for enumerating and checking S3 bucket misconfigurations across AWS and compatible object storage services.
ScoutSuite (T)
Multi-cloud auditing tool that inventories cloud resources and highlights security risks in an interactive HTML report.
SpiderFoot (T)
Automated OSINT collection tool with 200+ modules for reconnaissance and threat intelligence.
Steampipe (T)
SQL interface over cloud APIs and services, enabling ad hoc querying of AWS, Azure, GCP, and many other data sources.
Stormspotter (T)
Graph-based Azure reconnaissance platform that maps cloud attack paths and trust relationships using Neo4j-backed visualization.
Subfinder (T)
Fast passive subdomain discovery utility that aggregates results from many curated OSINT and API-backed sources.
Sublist3r (T)
Passive subdomain enumeration tool that aggregates subdomains from public search engines and certificate-related sources.
theHarvester (T)
Command-line tool for gathering emails, subdomains, IPs, and URLs from public sources.