Cloud

Cloud

Google Dorks

Online tool

Enumeration - Bruteforce

Cloud Enum

s3enum

lazys3

S3Scanner

GCP - Find Assets

Public AWS S3 Buckets

Scan for sensitive files and secrets - CloudShovel

Misconf - Permissions ?

AWS

Private and Public SSH Keys Leaked

Cloudflare R2 Buckets

O365 / Microsoft 365

Spray - Validate O365

Identify usernames

We can instead try to use custom tools such as o365spray or MailSniper for Microsoft Office 365 or CredKing for Gmail or Okta. Keep in mind that these tools need to be up-to-date because if the service provider changes something (which happens often), the tools may not work anymore

Power-Pwn

Last updated