# 0xsha/CloudBrute

Awesome cloud enumerator

Repository: https://github.com/0xsha/CloudBrute
Canonical: https://ross.abutalabs.com/products/cloudbrute
Language: Go
License: MIT
License Family: permissive
Topics: bugbounty, cloud, cloud-security, s3-bucket, amazon, vultr, google, linode, cloud-storage, pentesting, pentest-tool, hacking, redteam, infosec, digitalocean
Last push: 2025-03-09T17:48:52+00:00

## Health v2 (maintenance only)
Score: 27/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 10, release rhythm 8, longevity 100
- inputs: {"age_days": 2184, "days_push": 542, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1145, forks 158 (observed 2026-08-28T04:03:45.624739+00:00)

## What it is
CloudBrute is a Go CLI tool that enumerates a company's infrastructure, files, and applications across major cloud providers (Amazon, Google, Microsoft, DigitalOcean, Alibaba, Vultr, Linode). It performs unauthenticated black-box discovery of open storage buckets and hosted apps using concurrent brute-forcing with wordlists.

## Use cases
- find open s3 buckets for a company domain
- enumerate cloud-hosted apps during a bug bounty
- discover cloud storage endpoints in a pentest
- black-box recon of a target's cloud infrastructure
- find dev and staging environments on cloud providers
- locate exposed files on cloud storage without credentials

## When to choose
- you need unauthenticated cloud asset discovery across multiple providers
- you want fast concurrent enumeration with proxy and user-agent randomization
- you are doing bug bounty or red team recon on cloud-hosted assets

## When to avoid
- you already have cloud API keys and want authenticated asset inventory
- you need deep scanning of a single provider's full service catalog
- you require a GUI or continuous cloud monitoring rather than one-shot enumeration

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, web-scraping, http-client, cli
- domain: security, penetration-testing, cloud-computing, developer-tools
- platform: windows, cli, go
- tags: bugbounty, red-team, cloud-enumeration, s3-bucket, recon, pentesting, linux, macos

## Member repositories
- 0xsha/CloudBrute (main) score 27

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:45.624739+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:34:13.874741+00:00, confidence not recorded.
  - readme: https://github.com/0xsha/CloudBrute (fetched 2026-08-28T04:03:45.624739+00:00, sha 7602011b0b8e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
