
A Burp Suite extension that uses Shodan to discover cloud buckets and tests them for publicly accessible vulnerabilities through passive scanning.

A Burp Suite extension that uses Shodan to discover cloud buckets and tests them for publicly accessible vulnerabilities through passive scanning.
Burp Anonymous Cloud is a Burp Suite extension that performs passive scanning to identify cloud storage buckets and test them for publicly accessible vulnerabilities. The extension integrates with Shodan's search engine to discover cloud buckets across various cloud platforms. Once buckets are identified, it leverages Burp's proxy functionality to conduct vulnerability assessments on these cloud storage resources. The tool focuses on identifying potential security risks in cloud infrastructure by testing for common misconfigurations and access control issues. It operates as a passive scanner, meaning it does not actively exploit vulnerabilities but rather identifies potential security weaknesses. The extension requires both a Shodan API key for cloud bucket discovery and a properly configured Burp proxy setup to function. It is designed to help security professionals assess the security posture of cloud storage implementations during web application security testing.
Common questions about Burp Anonymous Cloud including features, pricing, alternatives, and user reviews.
Burp Anonymous Cloud is A Burp Suite extension that uses Shodan to discover cloud buckets and tests them for publicly accessible vulnerabilities through passive scanning. It is a Cloud Security solution designed to help security teams with S3.
Multi-cloud compliance platform with 150+ frameworks and CIS benchmarks
An open-source framework that inventories and manages AWS resources across multiple accounts by collecting data via Cross Account Assume Roles and storing it in a centralized S3 bucket for analysis.
A Terraform module that establishes security baseline configurations for AWS accounts based on CIS benchmarks and AWS security best practices.
Krampus is an AWS resource management tool that automates the deletion and disabling of cloud objects based on JSON task files for security remediation and cost control.