R-CLO
CloudBrute
Fast, concurrent Go tool that permutation-brute-forces a target's infrastructure and storage across AWS, Azure, GCP, DigitalOcean, Alibaba, and more.
OVERVIEW
CloudBrute (github.com/0xsha/CloudBrute) is a Go command-line tool built for bug bounty hunters, red teamers, and pentesters who need to find a target company's infrastructure, files, and apps hosted across the top cloud providers — Amazon, Google, Microsoft, DigitalOcean, Vultr, Linode, and Alibaba — without prior knowledge of which provider the target actually uses.
It works entirely black-box: given a domain and a keyword, it builds permutations from a wordlist and fires concurrent HTTP/DNS checks at each provider's storage and app-hosting patterns, using goroutines to keep large wordlists fast. Results can be filtered to a specific provider or mode (storage vs. apps) and written to an output file for later triage.
USE CASES
Practical use cases
- 01
Running a single scan that covers seven cloud providers when the target's actual provider is unknown.
- 02
Bug bounty recon to find exposed storage buckets and app endpoints tied to a program's in-scope domains.
- 03
Tuning thread (`-t`) and timeout (`-T`) values to balance scan speed against a target's rate limits.
- 04
Forcing a single provider with `-c` once initial results suggest where the target's infrastructure actually lives.
QUICK START
For a fast, black-box sweep of a target company's name and known keywords across many cloud providers at once, with no authentication required.
- Download a release binary from GitHub or build from source with `go build`.
- Grab a target-specific keyword and domain, and pick a wordlist from the `data/` directory (or supply your own with `-w`).
- Run a storage-mode scan first with `-m storage`, since storage buckets are the most common quick win.
- Tune `-t` (threads) and `-T` (timeout) to the target's tolerance, and write results to a file with `-o`.
- Re-run in app mode (`-m app`) or against a single forced provider (`-c`) once storage results narrow down the likely provider.
CloudBrute -d target.com -k target -m storage -t 80 -T 10 -w ./data/storage_small.txt -o target_output.txtBEFORE YOU RUN IT
What to check before running it
High thread counts (`-t 80` or more) generate a large volume of requests quickly — this reads as a scan to WAFs, CDNs, and the cloud providers' own abuse systems.
Only run scans against the domain and keywords covered by the authorized engagement or bug bounty program scope.
A discovered storage bucket or app endpoint still requires manual verification of its actual exposure before it becomes a reportable finding.