Skip to main content

hunt-cloud-misconfig

Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessible via SSRF, Cognito identity pool abuse, CloudWatch RUM weaponization. GCP: public GCS buckets, exposed Cloud Run services, Cloud Functions unauth access, Firestore open rules, leaked service account JSON → token generation → IAM enumeration, Artifact Registry image download, source code buckets (gcf-sources-*). Azure: public blob containers, exposed Function App. MinIO: health/admin API, default credentials, bucket listing. (Kubernetes/Docker exposure is owned by hunt-k8s; CI/CD pipeline attacks by hunt-cicd.) Detection: targeted dorking, certificate transparency, JS bundle secret extraction, port scan for known service ports. Validate: actual data read / write / RCE. Use when hunting cloud-native storage and compute misconfig (S3/G

Zur Installation springen

Quellinformationen

Repository
Wyl-cmd/kxns-cli
Letzte Quellaktivität
25. Juli 2026 um 08:23
Erkannte Sprache von SKILL.md
Englisch
Sterne
4
Forks
0

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.