Skip to content
OPS // KITitspentest.sh

R-CLO

CloudBrute

Fast, concurrent Go tool that permutation-brute-forces a target's infrastructure and storage across AWS, Azure, GCP, DigitalOcean, Alibaba, and more.

Official siteBack to catalog

OVERVIEW

CloudBrute (github.com/0xsha/CloudBrute) is a Go command-line tool built for bug bounty hunters, red teamers, and pentesters who need to find a target company's infrastructure, files, and apps hosted across the top cloud providers — Amazon, Google, Microsoft, DigitalOcean, Vultr, Linode, and Alibaba — without prior knowledge of which provider the target actually uses.

It works entirely black-box: given a domain and a keyword, it builds permutations from a wordlist and fires concurrent HTTP/DNS checks at each provider's storage and app-hosting patterns, using goroutines to keep large wordlists fast. Results can be filtered to a specific provider or mode (storage vs. apps) and written to an output file for later triage.

USE CASES

Practical use cases

  • 01

    Running a single scan that covers seven cloud providers when the target's actual provider is unknown.

  • 02

    Bug bounty recon to find exposed storage buckets and app endpoints tied to a program's in-scope domains.

  • 03

    Tuning thread (`-t`) and timeout (`-T`) values to balance scan speed against a target's rate limits.

  • 04

    Forcing a single provider with `-c` once initial results suggest where the target's infrastructure actually lives.

QUICK START

For a fast, black-box sweep of a target company's name and known keywords across many cloud providers at once, with no authentication required.

  1. Download a release binary from GitHub or build from source with `go build`.
  2. Grab a target-specific keyword and domain, and pick a wordlist from the `data/` directory (or supply your own with `-w`).
  3. Run a storage-mode scan first with `-m storage`, since storage buckets are the most common quick win.
  4. Tune `-t` (threads) and `-T` (timeout) to the target's tolerance, and write results to a file with `-o`.
  5. Re-run in app mode (`-m app`) or against a single forced provider (`-c`) once storage results narrow down the likely provider.
CloudBrute — bash
CloudBrute -d target.com -k target -m storage -t 80 -T 10 -w ./data/storage_small.txt -o target_output.txt

BEFORE YOU RUN IT

What to check before running it

High thread counts (`-t 80` or more) generate a large volume of requests quickly — this reads as a scan to WAFs, CDNs, and the cloud providers' own abuse systems.

Only run scans against the domain and keywords covered by the authorized engagement or bug bounty program scope.

A discovered storage bucket or app endpoint still requires manual verification of its actual exposure before it becomes a reportable finding.

KEEP EXPLORING

View the whole phase →