Cloud
Cloud




Google Dorks
Online tool

Enumeration - Bruteforce
Cloud Enum

s3enum
lazys3
S3Scanner
GCP - Find Assets

Public AWS S3 Buckets
Scan for sensitive files and secrets - CloudShovel
Misconf - Permissions ?
AWSPrivate and Public SSH Keys Leaked

Cloudflare R2 Buckets
O365 / Microsoft 365
Spray - Validate O365
Identify usernames
We can instead try to use custom tools such as o365spray or MailSniper for Microsoft Office 365 or CredKing for Gmail or Okta. Keep in mind that these tools need to be up-to-date because if the service provider changes something (which happens often), the tools may not work anymore
Power-Pwn
Last updated
