Skip to main content

hunt-cloud-misconfig

Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessible via SSRF, Cognito identity pool abuse, CloudWatch RUM weaponization. GCP: public GCS buckets, exposed Cloud Run services, Cloud Functions unauth access, Firestore open rules, leaked service account JSON → token generation → IAM enumeration, Artifact Registry image download, source code buckets (gcf-sources-*). Azure: public blob containers, exposed Function App. MinIO: health/admin API, default credentials, bucket listing. (Kubernetes/Docker exposure is owned by hunt-k8s; CI/CD pipeline attacks by hunt-cicd.) Detection: targeted dorking, certificate transparency, JS bundle secret extraction, port scan for known service ports. Validate: actual data read / write / RCE. Use when hunting cloud-native storage and compute misconfig (S3/G

설치로 이동

소스 정보

저장소
Wyl-cmd/kxns-cli
최근 소스 활동
2026년 7월 25일 08:23
감지된 SKILL.md 언어
영어
스타
4
포크
0

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.