Home

Awesome

This is a curated list of resources for collecting information about cloud providers.

A presentation that covers the concept of Cloud OSINT and its application in third party cloud provider review https://docs.google.com/presentation/d/113N-x1ocz7xDS5rXcmhmTqDyv2to028yAzedJlKq1J8/edit?usp=sharing

Asset discovery

FreeCommercial
ShodanBitDiscovery
Blutoassetnote
SpiderFoot
https://spyse.com/

SSL and HTTP Security Headers analysis

FreeCommercial
SSLScan
htbridge
HttpObservatory
Testssl.sh

Mobile

FreeCommercial
htbridge mobileNowSecure Intel
vulnersData Theorem
https://android.fallible.co/
https://androidobservatory.org/

Threat Hunting

FreeCommercial
GreyNoise.ioRecorded Future

Audit Reports

FreeCommercial
CSA Star Registrysharedassessments

Vulnerability data

FreeCommercial
OpenBugBounty
PunkSPIDER
Vulners
https://scans.io/

Company details

FreeCommercial
Crunchbase

Code Search

FreeCommercial
nerdydata
https://publicwww.com/

IP Reputation

FreeCommercial
Cisco Talos

DNS Search

FreeCommercial
DNSDumpster, Domaintools etc.Cisco Umbrella

Breach Information

FreeCommercial
Google Search etc.Recorded Future

Cloud Access Security Broker

FreeCommercial
-----Cisco CloudLock, Skyhigh, Bitglass

Third party risk measurement

FreeCommercial
-----Bitsight, securityscorecard

Financial Viability

FreeCommercial
-----Dun & Bradstreet

Content Security Policy Analysis

FreeCommercial
https://csp-evaluator.withgoogle.com/

Tech Stack Evaluation

FreeCommercial
Wapplyzerhttps://www.purplemet.com/
urlscan.io

TLS certificate and associated subdomain analysis

FreeCommercial
censys.io
https://transparencyreport.google.com/https/certificates

Test for IPv6, DNSSEC, DMARC etc. Modern Standards

FreeCommercial
https://en.internet.nl

Open Buckets analysis

FreeCommercial
https://buckets.grayhatwarfare.com

SSH Analysis

FreeCommercial
https://sshcheck.com