Skip to main content

hunt-cloud-misconfig

Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessible via SSRF, Cognito identity pool abuse, CloudWatch RUM weaponization. GCP: public GCS buckets, exposed Cloud Run services, Cloud Functions unauth access, Firestore open rules, leaked service account JSON → token generation → IAM enumeration, Artifact Registry image download, source code buckets (gcf-sources-*). Azure: public blob containers, exposed Function App. MinIO: health/admin API, default credentials, bucket listing. (Kubernetes/Docker exposure is owned by hunt-k8s; CI/CD pipeline attacks by hunt-cicd.) Detection: targeted dorking, certificate transparency, JS bundle secret extraction, port scan for known service ports. Validate: actual data read / write / RCE. Use when hunting cloud-native storage and compute misconfig (S3/G

インストールへ移動

ソース情報

リポジトリ
Wyl-cmd/kxns-cli
ソースの最終更新活動
2026年7月25日 08:23
検出された SKILL.md の言語
英語
スター
4
フォーク
0

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。