Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: cloud-infrastructure (23)

Pentesting tools tagged cloud-infrastructure. See all tools or the category key.

Team (best effort)

AADInternals (T)

PowerShell toolkit for Azure AD and Entra ID assessment, including tenant reconnaissance and hybrid identity attack-path analysis.

cloud-infrastructure

Amass (T)

Advanced attack surface mapping framework for DNS and subdomain enumeration with graph correlation and extensive data-source support.

cloud-infrastructure

AWSBucketDump (T)

Python tool that enumerates AWS S3 buckets and optionally downloads accessible objects using keyword and pattern-based discovery.

cloud-infrastructure

BucketLoot (T)

Open-source cloud bucket discovery utility with limited current documentation and unclear maintenance signals.

cloud-infrastructure

Checkov (T)

Infrastructure-as-code security scanner that checks Terraform, CloudFormation, Kubernetes, and other cloud configs against policy rules.

cloud-infrastructure

Cloud Custodian (T)

Policy-as-code engine for cloud governance and security that can detect and remediate risky cloud configurations.

cloud-infrastructure

cloud_enum (T)

Multi-cloud enumeration tool that looks for exposed AWS, Azure, and GCP storage assets from target naming patterns.

cloud-infrastructure

dnsrecon (T)

DNS enumeration script for recon workflows, supporting record discovery, zone transfer checks, brute-force, and reverse lookups.

cloud-infrastructure

GCPBucketBrute (T)

Google Cloud Storage bucket enumeration utility for identifying publicly accessible or weakly protected buckets.

cloud-infrastructure

goblob (T)

Go-based Azure blob storage enumeration utility designed for fast discovery of publicly exposed containers and blobs.

cloud-infrastructure

lazys3 (T)

S3 bucket brute-forcing utility that generates candidate names from permutations and checks bucket accessibility.

cloud-infrastructure

MicroBurst (T)

PowerShell collection focused on Azure security assessment, including subscription discovery and cloud service misconfiguration checks.

cloud-infrastructure

Prowler (T)

Cloud security posture and compliance assessment framework covering AWS, Azure, GCP, Kubernetes, and SaaS surfaces.

cloud-infrastructure

Public Buckets

Search interface for publicly indexed cloud object storage buckets and files across multiple providers.

cloud-infrastructure

ROADtools (T)

Azure AD exploration framework for dumping tenant objects, principals, and permissions to support attack-path and privilege analysis.

cloud-infrastructure

S3Scanner (T)

Command-line scanner for enumerating and checking S3 bucket misconfigurations across AWS and compatible object storage services.

cloud-infrastructure

ScoutSuite (T)

Multi-cloud auditing tool that inventories cloud resources and highlights security risks in an interactive HTML report.

cloud-infrastructure

SpiderFoot (T)

Automated OSINT collection tool with 200+ modules for reconnaissance and threat intelligence.

cloud-infrastructure

Steampipe (T)

SQL interface over cloud APIs and services, enabling ad hoc querying of AWS, Azure, GCP, and many other data sources.

cloud-infrastructure

Stormspotter (T)

Graph-based Azure reconnaissance platform that maps cloud attack paths and trust relationships using Neo4j-backed visualization.

cloud-infrastructure

Subfinder (T)

Fast passive subdomain discovery utility that aggregates results from many curated OSINT and API-backed sources.

cloud-infrastructure

Sublist3r (T)

Passive subdomain enumeration tool that aggregates subdomains from public search engines and certificate-related sources.

cloud-infrastructure

theHarvester (T)

Command-line tool for gathering emails, subdomains, IPs, and URLs from public sources.

cloud-infrastructure domain-name email-address