m0rtem/CloudFail
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3751
- days_rel: n/a
- days_push: 890
- n_releases_24m: 0
Adoption not part of the score
2683 stars · 517 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
CloudFail is a Python 3 command-line reconnaissance tool that attempts to discover the real IP address of servers hidden behind Cloudflare. It combines misconfigured DNS scanning via DNSDumpster, Crimeflare database lookups, and bruteforcing over 2500 subdomains, optionally routing all requests through Tor.
Use cases
- find the real IP behind a Cloudflare-protected site
- scan a target for misconfigured DNS records
- bruteforce subdomains of a domain during a pentest
- check the Crimeflare database for a domain's historical IPs
- run anonymous reconnaissance through Tor
- gather OSINT on a website's origin server
When to choose
- you are doing authorized penetration testing or security research on Cloudflare-protected targets
- you want a lightweight Python CLI with multiple recon phases in one tool
- you need Tor support to anonymize your scanning traffic
When to avoid
- you have not obtained authorization from the target's network owner
- the target is properly configured and leaks no origin IP - the tool is a PoC with no guaranteed results
- you need a maintained, actively developed scanner - development is minimal
- you need a GUI or Windows-native tooling without extra setup
Facets
cli-tool · maturity maintenance
osint penetration-testing networking web-scraping security penetration-testing osint networking windows cli python cloudflare reconnaissance dns-recon tor subdomain-bruteforce pentesting linux macos
1 source
- readme: https://github.com/m0rtem/CloudFail · fetched 2026-08-28 · d176749f2273
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| m0rtem/CloudFail | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="m0rtem/CloudFail")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem