SecurityCipher
Home Blog About Us

Learn Paths, courses, and reference docs

  • ๐Ÿš€ Start Here Beginner path through the site
  • ๐Ÿ—บ๏ธ Penetration Testing Roadmap Structured path to become a pentester
  • ๐ŸŽ“ Free Security Courses Current free Udemy coupon listings
  • ๐Ÿ“„ Secure Code Explain Vulnerable vs secure code side by side
  • ๐ŸŽฏ Penetration Testing Tricks Field notes for real engagements
  • ๐Ÿ“– Vulnerability Explain How common vulns actually work

Checklists Interactive reviews and LLM risks

  • โœ… Security Checklists Hub All interactive security checklists
  • ๐Ÿ“‹ Writeup Checklists Steps derived from real writeups
  • ๐Ÿง  LLM AI Security Checklist Controls for LLM apps
  • ๐Ÿค– OWASP LLM Top 10 LLM Top 10 risks mapped out
  • ๐Ÿงฐ Burp Suite Guide Step-by-step Burp tutorials
  • ๐Ÿ“˜ Payload Field Manual Safe-first probes and signals

Practice Browser labs, games, and explorers

  • ๐Ÿ”ฌ Interactive Labs SQL injection, AI, architecture review
  • ๐ŸŽฎ Security Games Phishing, JWT, WAF, and more
  • ๐Ÿš— On-Call Drive Neon-city arcade security missions
  • โ€ข Shift Zero SOC desk: phish, OTP, malware, tickets
  • โ“ Application Security Quiz Web, secure coding, and cloud quizzes
  • ๐Ÿ—บ๏ธ OWASP Top 10 Explorer Clickable risk map with signals
  • ๐Ÿ”€ Interactive Attack Paths Recon-to-impact chains

Tools & Career Databases, jobs, and community

  • ๐Ÿ› ๏ธ Security Tools Curated recon, SAST, and bounty tools
  • ๐Ÿ”Ž CVE Lookup Multi-source CVE intelligence
  • ๐Ÿ’ฐ Bug Bounty Programs Live public scopes to search
  • ๐Ÿ’ผ Cybersecurity Jobs Roles from company career pages
  • ๐Ÿง‘โ€๐Ÿ’ป Security Researchers Community profiles and submissions
  • ๐ŸŽค Security Conferences Upcoming and past events
Browse all Security resources hub Freelance Security โ†’
My Resume
Freelance SecurityFreelance
New Security Researchers Join the directory - submit your profile for review Submit profile โ†’
← Security Tools View on GitHub

cloud_enum

Multi-cloud OSINT tool for enumerating public resources in AWS, Azure and GCP.

cloud_enum

Future of cloud_enum

I built this tool in 2019 for a pentest involving Azure, as no other enumeration tools supported it at the time. It grew from there, and I learned a lot while adding features.

Building tools is fun, but maintaining tools is hard. I haven't actively used this tool myself in a while, but I've done my best to fix bugs and review pull requests.

Moving forward, it makes sense to consolidate this functionality into a well-maintained project that handles the essentials (web/dns requests, threading, I/O, logging, etc.). Nuclei is really well suited for this. You can see my first PR to migrate cloud_enum functionality to Nuclei here.

I encourage others to contribute templates to Nuclei, allowing us to focus on detecting cloud resources while leaving the groundwork to Nuclei.

I'll still try to review PRs here to address bugs as time permits, but likely won't have time for major changes.

Thanks to all the great contributors. Good luck with your recon!

Overview

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

Currently enumerates the following:

Amazon Web Services:

  • Open / Protected S3 Buckets
  • awsapps (WorkMail, WorkDocs, Connect, etc.)

Microsoft Azure:

  • Storage Accounts
  • Open Blob Storage Containers
  • Hosted Databases
  • Virtual Machines
  • Web Apps

Google Cloud Platform

  • Open / Protected GCP Buckets
  • Open / Protected Firebase Realtime Databases
  • Google App Engine sites
  • Cloud Functions (enumerates project/regions with existing functions, then brute forces actual function names)
  • Open Firebase Apps

See it in action in Codingo's video demo here.

Usage

Setup

This project uses uv for dependency management. Install uv, then run:

uv sync

Or install it as a standalone tool:

uv tool install git+https://github.com/initstring/cloud_enum

Running

The only required argument is at least one keyword. You can use the built-in fuzzing strings, but you will get better results if you supply your own with -m and/or -b.

You can provide multiple keywords by specifying the -k argument multiple times.

Keywords are mutated automatically using strings from enum_tools/fuzz.txt or a file you provide with the -m flag. Services that require a second-level of brute forcing (Azure Containers and GCP Functions) will also use fuzz.txt by default or a file you provide with the -b flag.

Let's say you were researching "somecompany" whose website is "somecompany.io" that makes a product called "blockchaindoohickey". You could run the tool like this:

uv run cloud_enum -k somecompany -k somecompany.io -k blockchaindoohickey

HTTP scraping and DNS lookups use 5 threads each by default. You can try increasing this, but eventually the cloud providers will rate limit you. Here is an example to increase to 10.

uv run cloud_enum -k keyword -t 10

IMPORTANT: Some resources (Azure Containers, GCP Functions) are discovered per-region. To save time scanning, there is a "REGIONS" variable defined in enum_tools/azure_regions.py and enum_tools/gcp_regions.py that is set by default to use only 1 region. You may want to look at these files and edit them to be relevant to your own work.

Complete Usage Details

usage: cloud_enum [-h] (-k KEYWORD | -kf KEYFILE) [-m MUTATIONS] [-b BRUTE] [-t THREADS]
                  [-ns NAMESERVER] [-nsf NAMESERVERFILE] [-l LOGFILE] [-f FORMAT] [--disable-aws]
                  [--disable-azure] [--disable-gcp] [-qs]

Multi-cloud enumeration utility. All hail OSINT!

options:
  -h, --help            show this help message and exit
  -k, --keyword KEYWORD
                        Keyword. Can use argument multiple times.
  -kf, --keyfile KEYFILE
                        Input file with a single keyword per line.
  -m, --mutations MUTATIONS
                        Mutations. Default: enum_tools/fuzz.txt
  -b, --brute BRUTE     List to brute-force Azure container names. Default: enum_tools/fuzz.txt
  -t, --threads THREADS
                        Threads for HTTP brute-force. Default = 5
  -ns, --nameserver NAMESERVER
                        DNS server to use in brute-force. Default: 1.1.1.1
  -nsf, --nameserverfile NAMESERVERFILE
                        Path to the file containing nameserver IPs
  -l, --logfile LOGFILE
                        Appends found items to specified file.
  -f, --format FORMAT   Format for log file (text,json,csv) - default: text
  --disable-aws         Disable Amazon checks.
  --disable-azure       Disable Azure checks.
  --disable-gcp         Disable Google checks.
  -qs, --quickscan      Disable all mutations and second-level scans

Thanks

So far, I have borrowed from:

  • Some of the permutations from GCPBucketBrute
Press Escape to close the search panel.

Donate

Buy me a Coffee

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Product Security Engineer || AI Security

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • AI-Generated Code Security Bugs: A Vibe Coding Case Study
    AI-Generated Code Security Bugs: A Vibe Coding Case Study
    October 7, 2026/
    0 Comments
  • Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    September 8, 2026/
    0 Comments
  • DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    August 27, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Security Checklists
  • Cybersecurity Jobs
  • Blogs
  • About
  • Contact
ยฉ 2026 Security Cipher. All rights reserved. Privacy Policy ยท Terms & Conditions