CloudFox Logo

CloudFox

0
Free
Updated 11 March 2025
Visit Website

CloudFox helps you gain situational awareness in unfamiliar cloud environments. It’s an open source command line tool created to help penetration testers and other offensive security professionals find exploitable attack paths in cloud infrastructure. CloudFox helps you answer the following common questions (and many more): - What regions is this AWS account using and roughly how many resources are in the account? - What secrets are lurking in EC2 userdata or service specific environment variables? - What workloads have administrative permissions attached? - What actions/permissions does this [principal] have? - What role trusts are overly permissive or allow cross-account assumption? - What endpoints/hostnames/IPs can I attack from an external starting point (public internet)? - What endpoints/hostnames/IPs can I attack from an internal starting point (assumed breach within the VPC)? - What filesystems can I potentially mount from a compromised resource inside the VPC? Demos, Examples, Walkthroughs Blog - Introducing: CloudFox Video - CloudFox + CloudFoxable A Powerful Duo for Mastering the Art of Identifying and Exploiting AWS Attack Paths Video - Penetration Testing with CloudFox

FEATURES

SIMILAR TOOLS

minikube implements a local Kubernetes cluster for easy application development and supports various Kubernetes features.

AWS serverless cloud security tool for parsing and alerting on CloudTrail logs using EQL.

Lists AWS resources using the AWS Cloud Control API and writes them to a JSON output file.

Lists Amazon S3 Buckets while browsing

Comprehensive suite of tools and resources by Microsoft Azure for ensuring security and protection of data and applications in the cloud.

A multi-cloud tool for centralizing assets across multiple clouds with minimal configuration.

gVisor is an application kernel that provides isolation for running sandboxed containers.

A setuid implementation of a subset of user namespaces, providing a way to run unprivileged containers without requiring root privileges.

An AWS Lambda auditing tool that provides asset visibility and actionable results through statistical analysis and security checks.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved