Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Map AWS and Azure attack paths and find exploitable misconfigurations with CloudFox.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-09 | ✗→✓ | ▲ Improved | 266% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 100% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 180% | 0% |
| case-08 | ✓→✓ | = Same ✓ | 170% | 0% |
| case-12 | ✓→✓ | = Same ✓ | 453% | 0% |
> Legal Notice: This skill is for authorized cloud penetration testing and assessment only. CloudFox makes read/describe API calls against the cloud account whose credentials you supply. Run it ONLY against accounts you own or are authorized to test under a signed scope. Although CloudFox is read-only by design, the enumeration it performs is reconnaissance against a live environment and must be in scope.
CloudFox is an open-source command-line tool from Bishop Fox that helps penetration testers and red teamers gain situational awareness in unfamiliar cloud environments. Where tools like ScoutSuite focus on a defender-style configuration audit, CloudFox is built from the attacker's perspective: it answers questions like "what are the most attackable secrets, endpoints, and instances in this account, and what can the identity I just compromised actually reach?" It is read-only — it only performs Describe/List/Get style calls — and writes its findings to per-command CSV/TXT/loot files plus a combined report directory, so output can be triaged offline.
CloudFox covers AWS most deeply (30+ commands) and supports Azure. The workhorse is cloudfox aws all-checks, which runs the full battery of enumeration commands with sensible defaults: inventory, internet-reachable endpoints, EC2 instances (with IPs and instance-profile roles), iam-simulator and permissions for IAM analysis, principals, secrets from Secrets Manager/SSM, buckets, role-trusts (which identities can assume which roles — a core attack-path primitive), access-keys, route53, ecr, lambda, and more. CloudFox also emits ready-to-run command suggestions (e.g. aws s3 ls lines, aws ssm start-session lines) in its "loot" files so an operator can pivot immediately.
This skill covers installing CloudFox, authenticating to AWS and Azure, running targeted and full enumeration, interpreting the high-value outputs (role-trusts, secrets, endpoints), and feeding the results into attack-path planning. Source: github.com/BishopFox/cloudfox.
sts:AssumeRole trust relationships to plan lateral movement / privescbash # Homebrew brew install cloudfox # Go (1.21+) go install github.com/BishopFox/cloudfox@latest # or download a release binary from GitHub and chmod +x
bash # AWS — configure a named profile and verify aws configure --profile assess aws sts get-caller-identity --profile assess
# Azure az login az account show
awscli (AWS) and/or azure-cli (Azure) installed for credential setup and follow-up| ID | Name | Use in this skill | |----|------|-------------------| | T1526 | Cloud Service Discovery | CloudFox enumerates the available cloud services and resources in an account | | T1580 | Cloud Infrastructure Discovery | inventory, instances, buckets map the infrastructure footprint | | T1087.004 | Account Discovery: Cloud Account | principals, access-keys enumerate cloud identities | | T1069.003 | Permission Groups Discovery: Cloud Groups | permissions, iam-simulator, role-trusts reveal entitlements | | T1538 | Cloud Service Dashboard | Aggregated situational-awareness reporting across services |
bashaws sts get-caller-identity --profile assess cloudfox aws --profile assess all-checks -o ./loot
bashcloudfox aws --profile assess inventory
bashcloudfox aws --profile assess endpoints cloudfox aws --profile assess instances
role-trusts is the key lateral-movement primitive — it shows who can assume what.
bashcloudfox aws --profile assess principals cloudfox aws --profile assess permissions cloudfox aws --profile assess role-trusts cloudfox aws --profile assess access-keys
bashcloudfox aws --profile assess secrets
bashcloudfox aws --profile assess buckets cloudfox aws --profile assess ecr cloudfox aws --profile assess lambda cloudfox aws --profile assess route53
bashcloudfox aws --profile assess iam-simulator
CloudFox Azure works against the subscriptions the az session can see.
bashcloudfox azure inventory --outdir ./azure-loot cloudfox azure rbac cloudfox azure storage cloudfox azure vms
CloudFox writes per-command CSV/TXT plus a loot directory of pivot commands.
bashls -R ./loot/cloudfox-output/ # Loot files contain ready-to-run follow-ups, e.g. aws s3 ls / ssm start-session lines
See scripts/agent.py to run a curated set of commands and summarize output files.
| Resource | Purpose | Link | |----------|---------|------| | CloudFox GitHub | Source, releases, full command list | https://github.com/BishopFox/cloudfox | | CloudFox docs/wiki | Per-command output explanations | https://github.com/BishopFox/cloudfox/wiki | | Bishop Fox CloudFox blog | Design and usage walkthrough | https://bishopfox.com/blog/introducing-cloudfox | | AWS CLI reference | Follow-up exploitation commands | https://docs.aws.amazon.com/cli/latest/reference/ | | Pacu | Active exploitation after enumeration | https://github.com/RhinoSecurityLabs/pacu |
CloudFox is read-only, but its enumeration is far from silent. Each command issues many Describe*/List*/Get* API calls in a short burst, which is highly visible to defenders:
iam:ListUsers, iam:ListRoles,secretsmanager:ListSecrets, ec2:DescribeInstances, and sts:GetCallerIdentity from one principal within seconds is a strong enumeration signal.
Discovery:IAMUser/AnomalousBehavior andDiscovery:S3/MaliciousIPCaller can fire on this burst pattern.
enumeration bursts, especially from new IPs/ASNs or newly created credentials.
For an authorized assessment, document the source IP and timestamp of CloudFox runs so the blue team can correlate, and prefer running from an in-scope, attributable host.
all-checks once to populate the full output directory.role-trusts first — it reveals the assume-role graph for lateral movement.secrets and env-vars for credentials that unlock new principals.endpoints + instances to map externally reachable attack surface.| Command | Why it matters | |---------|----------------| | all-checks | Runs the full enumeration battery with defaults | | role-trusts | Maps assume-role paths — core for lateral movement/privesc | | endpoints | Surfaces internet-reachable attack surface | | secrets | Exposes credentials in Secrets Manager / SSM | | permissions | Lists effective IAM permissions per principal | | instances | EC2 with IPs and attached instance-profile roles | | access-keys | Active access keys (potential credential targets) |
cloudfox aws --helpsts get-caller-identity / az account showall-checks completed and output directory populatedOther measured skills in the registry, with their headline benchmark lift.