Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CloudFox is an open-source command-line enumeration tool for authorized cloud penetration tests and offensive-security assessments. It gathers information about cloud identities, permissions, workloads, endpoints, secrets and other relationships so a tester can investigate possible attack paths. It does not, by itself, prove that every reported condition is exploitable.

Bishop Fox introduced CloudFox on September 13, 2022 with AWS support. The launch article listed Azure, Google Cloud Platform (GCP) and Kubernetes as roadmap items; current project documentation lists AWS, Azure and GCP support.

What CloudFox is

CloudFox codifies recurring shell-based cloud-enumeration work into a portable, modular command-line tool. Its intended users are cloud penetration testers and other offensive-security professionals working with permission from the account or organization owner.

The tool is an information-gathering aid, not an automatic exploit scanner. A finding such as an administrative permission, a reachable endpoint or a secret in metadata still requires validation in the authorized environment, including checking whether the credential is current, usable and in scope.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Bishop Fox announced in 2022

Seth Art and Carlos Vendramini announced CloudFox on September 13, 2022. That release described AWS as the supported provider and put Azure, GCP and Kubernetes on the roadmap. The announcement framed the project as a way to replace repeated, ad-hoc shell pipelines with a modular workflow.

The launch article also stated: “That said, no matter what permission you run CloudFox with, you can rest assured that nothing will be created, deleted, or updated.” This is the statement made in the 2022 announcement; testers should still review current documentation, credentials and operational controls before running any assessment.

What the current project covers

Current Bishop Fox materials list AWS, Azure and GCP. Provider status and command totals differ slightly by documentation page, so the figures below are snapshots rather than permanent product limits.

Provider README command count Wiki command count Documented status
AWS 34 34 Stable
Azure 4 4 Active development
GCP 60 58 Stable

The README and wiki are the sources for those counts and use different snapshots or counting conventions. A separate Bishop Fox announcement dated February 26, 2026 describes the GCP launch as having 64 modules. “Modules” and “commands” are not necessarily the same unit, so these numbers should not be combined into one total.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Questions CloudFox helps a tester investigate

The project documentation organizes enumeration around practical attack-path questions:

  • Which regions does an AWS account use, and approximately how many resources are present?
  • Are secrets exposed in EC2 user data or service-specific environment variables?
  • Which workloads have administrative permissions attached?
  • What actions can the discovered principals perform?
  • Do role trust policies allow unintended principals to assume a role?
  • Which endpoints, hostnames or IP addresses are reachable from an external or internal starting point?
  • Are there filesystems that a workload or identity could potentially mount?

These outputs identify leads for a human-led assessment. CloudFox does not establish exploitability, business impact or authorization to access a target.

GCP capabilities described in 2026

Bishop Fox’s February 26, 2026 GCP announcement describes enumeration of cloud resources, identity permissions and service-account risks across an organization hierarchy. It discusses possible privilege-escalation and lateral-movement analysis when CloudFox is paired with FoxMapper. Those are described capabilities and potential analysis paths, not guaranteed outcomes in every project or organization.

Permissions and prerequisites

AWS

Install and authenticate the AWS CLI with credentials scoped to the assessment. CloudFox can be used in a white-box engagement with limited read-only permissions or in a black-box exercise using credentials discovered during the engagement. The exact visibility depends on the policies attached to the identity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Azure

Use the Azure CLI and an account with viewer-like access appropriate to the subscription, tenant or resource scope being assessed. Broader scopes require corresponding authorization.

GCP

Install the Google Cloud SDK and authenticate it for the project or organization in scope. Bishop Fox says roles/viewer is sufficient for basic single-project enumeration; comprehensive organization-wide work requires additional viewer or reviewer roles described by the project documentation.

Installation and updating

CloudFox is distributed as open-source software rather than as a physical product. The project documents four installation routes:

  • Download a release binary.
  • Install through Homebrew.
  • Install with Go.
  • Compile from source.

Use the current repository’s installation instructions for the exact package name, binary architecture and release asset. Before running an assessment, verify the installed version and authenticate the provider CLI that matches the cloud you are testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Required compatibility update

The repository README carries a December 2025 warning: users need CloudFox v1.17.0 or newer because earlier versions stopped working after AWS changed the format of its public service-mapping file. Treat v1.17.0 as the project-stated minimum, and check the current release for any later requirement before testing.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Typical AWS workflow

  1. Confirm written authorization, target accounts or organizations, allowed regions and handling rules for discovered secrets.
  2. Install CloudFox v1.17.0 or newer and the AWS CLI.
  3. Configure the AWS CLI with the least-privileged credentials that meet the engagement’s goals.
  4. Run the provider-specific enumeration commands documented by the current release. The AWS documentation includes an all-checks workflow for bundled enumeration.
  5. Review identities, trust relationships, permissions, workloads, endpoints and exposed data as investigation leads.
  6. Validate each lead manually and record the identity, scope, evidence and remediation without making unauthorized changes.

How to evaluate CloudFox

Evaluation question What to check
Provider coverage AWS and GCP are documented as stable; Azure is listed but marked active development on the wiki.
Permission model Determine whether read-only, viewer-like or broader roles are available and authorized.
Workflow style Use individual modular commands for focused checks or the documented AWS all-checks workflow for a broad pass.
Assessment scope Separate a single account or project review from an organization-wide identity and trust analysis.
Maintenance Check the current release, especially the v1.17.0-or-newer AWS compatibility notice.

CloudFox versus CloudFoxable

CloudFoxable is a related Bishop Fox practice sandbox for hands-on cloud-security learning. It is separate from the CloudFox enumeration tool and should be treated as a training resource, not as a CloudFox hardware product or a verified commercial affiliate offer.

Is CloudFox an Amazon product?

No. CloudFox is open-source software distributed through binaries, a package manager or source code. There is no supported CloudFox-specific physical Amazon product established by the project materials.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.