CloudFox is a command line tool created to help penetration testers and other offensive security professionals find exploitable attack paths in cloud infrastructure. It currently supports AWS.
The main inspiration for cloudfox was to create something like PowerView for cloud infrastructure. A collection of enumeration commands that illuminate attack paths even for those relatively new to cloud penetration testing. To do this, we codified our many sed/awk/grep/jq incantations into a tool that is portable, modular, and quick. Our primary audience is penetration testers, but we think cloudfox will be useful for all cloud security practitioners. CloudFox currently supports AWS.
With CloudFox, security practitioners can:
CloudFoxable is an intentionally vulnerable AWS environment created specifically to teach the art of AWS cloud penetration testing, while showcasing CloudFox’s capabilities that help you find latent attack paths more effectively.
Drawing inspiration from CloudGoat, flaws.cloud, and Metasploitable, CloudFoxable provides a wide array of flags and attack paths in a capture-the-flag (CTF) format.
Seth Art (OSCP) is a Principal Security Consultant at Bishop Fox, where he currently focuses on penetration testing cloud environments, Kubernetes clusters, and traditional internal networks. Seth is the author of multiple open-source projects including IAM Vulnerable, Bad Pods, celeryStalk, and PyCodeInjection, has presented at security conferences, including DerbyCon and BSidesDC, published multiple CVEs, and is the founder of IthacaSec, a security meetup in upstate NY.
Carlos Vendramini (OSCP, GPEN, GWAPT) previously served as a Senior Security Consultant at Bishop Fox, where he focuses on penetration testing cloud environments, kubernetes clusters, and web applications. Carlos holds a bachelor’s degree in Computer Engineering from Federal University of Espirito Santo. Prior to Bishop Fox, Carlos worked for Fortune 500 companies in the financial and insurance sectors where he gained experience with penetration testing, vulnerability assessments, red teaming, and social engineering. In addition to penetration testing, Carlos enjoys discovering how SDKs and APIs for popular technologies operate and writing code to automate security tasks.
Tool Talk: CloudFox
Watch as we explore Bishop Fox’s very own CloudFox, a command line tool that helps offensive security practitioners navigate unfamiliar cloud environments and find exploitable attack paths in cloud infrastructure. Tune in to our livestream for a demo of CloudFox!
CyberRisk Alliance Cloud Adoption Security Report
Explore key findings and insights from the CRA Business Intelligence Cloud Security Survey of more than 300 security leaders & practitioners.
Feb 24, 2022
Cloud 9: Top Cloud Penetration Testing Tools
By Britt Kemp
Sep 23, 2021
IAM Vulnerable - Assessing the AWS Assessment Tools
By Seth Art
Sep 09, 2021
IAM Vulnerable - An AWS IAM Privilege Escalation Playground
By Seth Art
Jun 07, 2022
Using CloudTrail to Pivot to AWS Accounts
By Gerben Kleijn
This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.