R-CLO
cloud_enum
Multi-cloud OSINT tool that mutates a target keyword to discover public S3 buckets, Azure storage, and GCP resources in one pass.
OVERVIEW
cloud_enum (github.com/initstring/cloud_enum) is a Python OSINT tool that takes one or more keywords — typically a company name, brand, or product — and mutates them against a wordlist of common naming patterns (dev, prod, backup, staging, and so on) to build a large list of candidate resource names, then checks each candidate against AWS, Azure, and GCP simultaneously.
Unlike single-provider bucket brute-forcers, cloud_enum covers all three major providers in one run: open or protected S3 buckets and AWS app endpoints (WorkMail, WorkDocs, Connect) on AWS; storage accounts, blob containers, hosted databases, VMs, and web apps on Azure; and buckets, Firebase realtime databases, App Engine sites, and Cloud Functions on GCP — all from unauthenticated, publicly-resolvable checks.
USE CASES
Practical use cases
- 01
Sweeping AWS, Azure, and GCP in one run during external recon for a company name or brand keyword.
- 02
Finding forgotten dev/staging/backup storage buckets that use predictable naming conventions.
- 03
Feeding a custom mutation wordlist tailored to a target's naming habits observed during OSINT.
- 04
Building an initial cloud attack-surface inventory before a scoped cloud penetration test begins.
QUICK START
During external recon, when you have a company name or brand keyword and want a single pass across AWS, Azure, and GCP for exposed storage and apps.
- Clone the repository and install dependencies with `pip install -r requirements.txt` (or run via `uv`).
- Pick one or more keywords tied to the target — company name, product name, common abbreviations.
- Run the tool with `-k` for each keyword; optionally supply a custom mutation list with `-m`.
- Increase thread count with `-t` for faster scans, and use `-f json` or `-f csv` to save structured output.
- Review flagged buckets and endpoints, then verify access levels manually before reporting.
cloud_enum -k targetcompany -k targetcompany-io -t 10 -f jsonBEFORE YOU RUN IT
What to check before running it
Generating thousands of DNS/HTTP lookups from mutated candidate names is noisy and can be mistaken for a scan by the target's monitoring or the cloud provider's abuse detection.
Only enumerate keywords and namespaces that fall within the authorized engagement scope — brand permutation can easily wander into unrelated third-party assets.
A "found" bucket or endpoint is not itself proof of exposure — confirm actual read/write access before reporting a finding.