BucketLoot - An Automated S3-compatible Bucket Inspector

By Owais Shaikh , Umair Nehri on 06 Dec 2023 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
#aws #cloud-pentesting #reconnaissance #data-leak
Focus Areas: πŸ”’ Data Privacy & Protection , ☁️ Cloud Security , 🎯 Penetration Testing
This tool demo covers following tools where the speaker has contributed or authored
BUCKETLOOT

Abstract

BucketLoot is an automated S3-compatible Bucket inspector that can help users extract assets, flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain text.