Cloud

Cloudchevron-right

Google Dorkschevron-right

Online tool

Enumeration - Bruteforce

Cloud Enum

s3enum

lazys3

S3Scanner

GCP - Find Assets

Public AWS S3 Buckets

Scan for sensitive files and secrets - CloudShovel

Misconf - Permissions ?

AWSchevron-right

Private and Public SSH Keys Leaked

Cloudflare R2 Buckets

O365 / Microsoft 365

Spray - Validate O365

Identify usernames

We can instead try to use custom tools such as o365sprayarrow-up-right or MailSniperarrow-up-right for Microsoft Office 365 or CredKingarrow-up-right for Gmail or Okta. Keep in mind that these tools need to be up-to-date because if the service provider changes something (which happens often), the tools may not work anymore

Power-Pwn

Last updated