
A Go-based tool for discovering and inventorying internet-facing AWS assets across single or multiple accounts to help maintain comprehensive cloud attack surface visibility.

A Go-based tool for discovering and inventorying internet-facing AWS assets across single or multiple accounts to help maintain comprehensive cloud attack surface visibility.
Smogcloud is a cloud asset discovery tool designed to identify exposed AWS resources across single or multiple accounts. The tool helps security professionals maintain comprehensive asset inventories by monitoring internet-facing assets that may be dynamic or ephemeral in nature. The application discovers internet-facing FQDNs and IP addresses across AWS environments, enabling users to identify potential misconfigurations, vulnerabilities, and unused assets. It can detect services that are not currently monitored and identify shadow IT resources that may have been deployed without proper oversight. Smogcloud is built in Go and requires basic setup including AWS environment variables for the target accounts. The tool is particularly useful for security engineers, penetration testers, and AWS administrators who need to maintain visibility into their cloud attack surface on a regular basis. The tool addresses the challenge of tracking assets in dynamic cloud environments where resources are frequently created, modified, or destroyed, making manual inventory management impractical.
Common questions about Smogcloud including features, pricing, alternatives, and user reviews.
Smogcloud is A Go-based tool for discovering and inventorying internet-facing AWS assets across single or multiple accounts to help maintain comprehensive cloud attack surface visibility. It is a Attack Surface solution designed to help security teams with Reconnaissance, AWS, Security Tools.
FestIn discovers open S3 buckets associated with a domain using crawling and DNS reconnaissance techniques.
Cloud_enum is a multi-cloud OSINT tool that enumerates publicly accessible resources across AWS, Azure, and Google Cloud platforms for security assessment purposes.
A black-box reconnaissance tool that discovers cloud infrastructure, files, and applications across major cloud providers for security testing purposes.
A Go-based web crawler that supports multiple protocols and authentication methods for systematic web resource discovery and collection.