Cloud Pivot Finder
From external domains to cloud infrastructure compromise paths.
Important
CRITICAL: Only test cloud infrastructure you have explicit authorization to test. Unauthorized access to cloud resources is a criminal offense.
Instructions
Step 1: Cloud Provider Detection
python scripts/cloud_detector.py --domain {target_domain}
Identify cloud hosting:
- IP range analysis: Match IPs against AWS, GCP, Azure published IP ranges
- DNS analysis: CNAME patterns (*.amazonaws.com, *.googleusercontent.com, *.azurewebsites.net)
- Header analysis: Server headers, X-Amz-, X-GUploader-, x-ms-* headers
- Certificate analysis: Issuer and SAN entries pointing to cloud services
- CDN detection: CloudFront, Cloud CDN, Azure CDN distributions
Output: Map of domain -> cloud provider -> service type.
Step 2: Storage Bucket Enumeration
python scripts/bucket_enum.py --domain {target_domain} --provider {aws|gcp|azure|all}
Naming pattern brute-force:
- {domain}, {domain}-backup, {domain}-dev, {domain}-staging
- {company}-assets, {company}-uploads, {company}-data
- {project}-{env} combinations
Per-provider testing:
- S3: Check for public ListBucket, GetObject, PutObject
- GCS: Check for allUsers/allAuthenticatedUsers permissions
- Azure Blob: Check for public container access
For each accessible bucket:
- List contents (if ListBucket allowed)
- Check for sensitive files (.env, credentials, backups, database dumps)
- Test write access (attempt to upload test file, delete immediately)
- Check bucket policy for overly permissive configurations
Step 3: Subdomain Takeover Detection
python scripts/takeover_scanner.py --subdomains {subdomain_list}
Check every subdomain's CNAME for dangling references:
- AWS: S3, CloudFront, Elastic Beanstalk, ELB
- Azure: Azure Websites, Traffic Manager, CDN, Blob
- GCP: Cloud Storage, App Engine, Firebase
- Other: Heroku, GitHub Pages, Fastly, Shopify, Zendesk, Unbounce, Surge.sh
For each dangling CNAME:
- Verify the target is actually unclaimed
- Determine the takeover method
- Assess impact (cookie scope, same-origin policy implications)
- Generate takeover PoC instructions
Step 4: Serverless and Container Discovery
python scripts/serverless_finder.py --domain {target_domain}
Discover:
- Lambda Function URLs: {function-id}.lambda-url.{region}.on.aws
- API Gateway: {api-id}.execute-api.{region}.amazonaws.com
- Cloud Functions: {region}-{project}.cloudfunctions.net
- Cloud Run: *.run.app
- Azure Functions: {app}.azurewebsites.net/api/
- Container registries: ECR, GCR, ACR public images
Test each for:
- Unauthenticated access
- Error messages revealing internal details
- Excessive function output (debug mode)
Step 5: CI/CD and IaC Exposure
python scripts/cicd_finder.py --domain {target_domain}
Search for:
- Exposed CI/CD: Jenkins, GitLab CI, GitHub Actions artifacts
- Terraform state files: .tfstate files on S3/GCS/HTTP
- CloudFormation templates: Exposed template files
- Docker/K8s configs: docker-compose.yml, kubernetes manifests
- Helm charts: values.yaml with secrets
- Environment files: .env files with cloud credentials
Step 6: Cloud Metadata Pivot Paths
python scripts/metadata_paths.py --recon-data {recon_json}
For each web application on cloud infrastructure:
- Identify potential SSRF vectors (URL parameters, PDF generators, webhooks)
- Map the SSRF -> metadata -> credential chain
- Assess what the IAM role/service account can access
- Document the complete pivot path
Step 7: Report Generation
python scripts/cloud_report.py --project {name}
Output:
- Cloud infrastructure map
- Accessible storage buckets with content inventory
- Subdomain takeover opportunities
- Serverless/container exposure
- CI/CD and IaC exposure
- Pivot paths from web to cloud
- Prioritized remediation plan
Error Handling
Rate Limiting on Cloud APIs
- S3 listing: Built-in exponential backoff
- DNS resolution: Use multiple resolvers
- If blocked: Reduce concurrency with
--threads 5
No Cloud Infrastructure Detected
If domain appears to be on-premise:
- Still check for cloud storage buckets (may use S3 for backups)
- Check for CI/CD exposure (GitHub Actions, etc.)
- Inform user and suggest alternative approaches
Examples
Example 1: Full Cloud Assessment
User says: "Map the cloud infrastructure for example.com"
Actions:
- Detect cloud providers
- Enumerate storage buckets
- Check for subdomain takeover
- Find serverless endpoints
- Check CI/CD exposure
- Map pivot paths
- Generate comprehensive report
Example 2: S3 Bucket Hunt
User says: "Find S3 buckets for example.com"
Actions:
- Generate naming patterns from domain/company name
- Test each pattern for existence
- Check permissions on found buckets
- List accessible contents
- Report findings
Example 3: Subdomain Takeover Scan
User says: "Check for subdomain takeover on these 50 subdomains"
Actions:
- Resolve CNAME for each subdomain
- Check each CNAME against takeover fingerprints
- Verify dangling references
- Generate takeover PoC for confirmable targets
1---2name: cloud-pivot-finder3description: Maps cloud infrastructure from domains and identifies pivot paths from external to cloud internals. Detects cloud providers, enumerates S3/GCS/Azure storage, finds subdomain takeover opportunities, discovers serverless functions, CI/CD exposure, and IaC leaks. Use when user asks for "cloud security", "S3 enumeration", "subdomain takeover", "cloud recon", "bucket enumeration", "cloud pivot", or provides domains hosted on AWS/GCP/Azure. For authorized testing only.4---5
6# Cloud Pivot Finder
7
8From external domains to cloud infrastructure compromise paths.
9
10## Important
11
12CRITICAL: Only test cloud infrastructure you have explicit authorization to test. Unauthorized access to cloud resources is a criminal offense.
13
14## Instructions
15
16### Step 1: Cloud Provider Detection
17
18```bash
19python scripts/cloud_detector.py --domain {target_domain}
20```
21
22Identify cloud hosting:
231. **IP range analysis**: Match IPs against AWS, GCP, Azure published IP ranges
242. **DNS analysis**: CNAME patterns (*.amazonaws.com, *.googleusercontent.com, *.azurewebsites.net)
253. **Header analysis**: Server headers, X-Amz-*, X-GUploader-*, x-ms-* headers
264. **Certificate analysis**: Issuer and SAN entries pointing to cloud services
275. **CDN detection**: CloudFront, Cloud CDN, Azure CDN distributions
28
29Output: Map of domain -> cloud provider -> service type.
30
31### Step 2: Storage Bucket Enumeration
32
33```bash
34python scripts/bucket_enum.py --domain {target_domain} --provider {aws|gcp|azure|all}
35```
36
37**Naming pattern brute-force:**
38- {domain}, {domain}-backup, {domain}-dev, {domain}-staging
39- {company}-assets, {company}-uploads, {company}-data
40- {project}-{env} combinations
41
42**Per-provider testing:**
43- **S3**: Check for public ListBucket, GetObject, PutObject
44- **GCS**: Check for allUsers/allAuthenticatedUsers permissions
45- **Azure Blob**: Check for public container access
46
47For each accessible bucket:
481. List contents (if ListBucket allowed)
492. Check for sensitive files (.env, credentials, backups, database dumps)
503. Test write access (attempt to upload test file, delete immediately)
514. Check bucket policy for overly permissive configurations
52
53### Step 3: Subdomain Takeover Detection
54
55```bash
56python scripts/takeover_scanner.py --subdomains {subdomain_list}
57```
58
59Check every subdomain's CNAME for dangling references:
60- **AWS**: S3, CloudFront, Elastic Beanstalk, ELB
61- **Azure**: Azure Websites, Traffic Manager, CDN, Blob
62- **GCP**: Cloud Storage, App Engine, Firebase
63- **Other**: Heroku, GitHub Pages, Fastly, Shopify, Zendesk, Unbounce, Surge.sh
64
65For each dangling CNAME:
661. Verify the target is actually unclaimed
672. Determine the takeover method
683. Assess impact (cookie scope, same-origin policy implications)
694. Generate takeover PoC instructions
70
71### Step 4: Serverless and Container Discovery
72
73```bash
74python scripts/serverless_finder.py --domain {target_domain}
75```
76
77Discover:
78- **Lambda Function URLs**: {function-id}.lambda-url.{region}.on.aws
79- **API Gateway**: {api-id}.execute-api.{region}.amazonaws.com
80- **Cloud Functions**: {region}-{project}.cloudfunctions.net
81- **Cloud Run**: *.run.app
82- **Azure Functions**: {app}.azurewebsites.net/api/
83- **Container registries**: ECR, GCR, ACR public images
84
85Test each for:
86- Unauthenticated access
87- Error messages revealing internal details
88- Excessive function output (debug mode)
89
90### Step 5: CI/CD and IaC Exposure
91
92```bash
93python scripts/cicd_finder.py --domain {target_domain}
94```
95
96Search for:
97- **Exposed CI/CD**: Jenkins, GitLab CI, GitHub Actions artifacts
98- **Terraform state files**: .tfstate files on S3/GCS/HTTP
99- **CloudFormation templates**: Exposed template files
100- **Docker/K8s configs**: docker-compose.yml, kubernetes manifests
101- **Helm charts**: values.yaml with secrets
102- **Environment files**: .env files with cloud credentials
103
104### Step 6: Cloud Metadata Pivot Paths
105
106```bash
107python scripts/metadata_paths.py --recon-data {recon_json}
108```
109
110For each web application on cloud infrastructure:
1111. Identify potential SSRF vectors (URL parameters, PDF generators, webhooks)
1122. Map the SSRF -> metadata -> credential chain
1133. Assess what the IAM role/service account can access
1144. Document the complete pivot path
115
116### Step 7: Report Generation
117
118```bash
119python scripts/cloud_report.py --project {name}
120```
121
122Output:
1231. Cloud infrastructure map
1242. Accessible storage buckets with content inventory
1253. Subdomain takeover opportunities
1264. Serverless/container exposure
1275. CI/CD and IaC exposure
1286. Pivot paths from web to cloud
1297. Prioritized remediation plan
130
131## Error Handling
132
133### Rate Limiting on Cloud APIs
1341. S3 listing: Built-in exponential backoff
1352. DNS resolution: Use multiple resolvers
1363. If blocked: Reduce concurrency with `--threads 5`
137
138### No Cloud Infrastructure Detected
139If domain appears to be on-premise:
1401. Still check for cloud storage buckets (may use S3 for backups)
1412. Check for CI/CD exposure (GitHub Actions, etc.)
1423. Inform user and suggest alternative approaches
143
144## Examples
145
146### Example 1: Full Cloud Assessment
147User says: "Map the cloud infrastructure for example.com"
148
149Actions:
1501. Detect cloud providers
1512. Enumerate storage buckets
1523. Check for subdomain takeover
1534. Find serverless endpoints
1545. Check CI/CD exposure
1556. Map pivot paths
1567. Generate comprehensive report
157
158### Example 2: S3 Bucket Hunt
159User says: "Find S3 buckets for example.com"
160
161Actions:
1621. Generate naming patterns from domain/company name
1632. Test each pattern for existence
1643. Check permissions on found buckets
1654. List accessible contents
1665. Report findings
167
168### Example 3: Subdomain Takeover Scan
169User says: "Check for subdomain takeover on these 50 subdomains"
170
171Actions:
1721. Resolve CNAME for each subdomain
1732. Check each CNAME against takeover fingerprints
1743. Verify dangling references
1754. Generate takeover PoC for confirmable targets