CloudFox is an open-source command-line enumeration tool for authorized cloud penetration tests and offensive-security assessments. It gathers information about cloud identities, permissions, workloads, endpoints, secrets and other relationships so a tester can investigate possible attack paths. It does not, by itself, prove that every reported condition is exploitable.
Bishop Fox introduced CloudFox on September 13, 2022 with AWS support. The launch article listed Azure, Google Cloud Platform (GCP) and Kubernetes as roadmap items; current project documentation lists AWS, Azure and GCP support.
What CloudFox is
CloudFox codifies recurring shell-based cloud-enumeration work into a portable, modular command-line tool. Its intended users are cloud penetration testers and other offensive-security professionals working with permission from the account or organization owner.
The tool is an information-gathering aid, not an automatic exploit scanner. A finding such as an administrative permission, a reachable endpoint or a secret in metadata still requires validation in the authorized environment, including checking whether the credential is current, usable and in scope.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
What Bishop Fox announced in 2022
Seth Art and Carlos Vendramini announced CloudFox on September 13, 2022. That release described AWS as the supported provider and put Azure, GCP and Kubernetes on the roadmap. The announcement framed the project as a way to replace repeated, ad-hoc shell pipelines with a modular workflow.
The launch article also stated: “That said, no matter what permission you run CloudFox with, you can rest assured that nothing will be created, deleted, or updated.” This is the statement made in the 2022 announcement; testers should still review current documentation, credentials and operational controls before running any assessment.
What the current project covers
Current Bishop Fox materials list AWS, Azure and GCP. Provider status and command totals differ slightly by documentation page, so the figures below are snapshots rather than permanent product limits.
Rank #2
| Provider | README command count | Wiki command count | Documented status |
|---|---|---|---|
| AWS | 34 | 34 | Stable |
| Azure | 4 | 4 | Active development |
| GCP | 60 | 58 | Stable |
The README and wiki are the sources for those counts and use different snapshots or counting conventions. A separate Bishop Fox announcement dated February 26, 2026 describes the GCP launch as having 64 modules. “Modules” and “commands” are not necessarily the same unit, so these numbers should not be combined into one total.
Questions CloudFox helps a tester investigate
The project documentation organizes enumeration around practical attack-path questions:
- Which regions does an AWS account use, and approximately how many resources are present?
- Are secrets exposed in EC2 user data or service-specific environment variables?
- Which workloads have administrative permissions attached?
- What actions can the discovered principals perform?
- Do role trust policies allow unintended principals to assume a role?
- Which endpoints, hostnames or IP addresses are reachable from an external or internal starting point?
- Are there filesystems that a workload or identity could potentially mount?
These outputs identify leads for a human-led assessment. CloudFox does not establish exploitability, business impact or authorization to access a target.
GCP capabilities described in 2026
Bishop Fox’s February 26, 2026 GCP announcement describes enumeration of cloud resources, identity permissions and service-account risks across an organization hierarchy. It discusses possible privilege-escalation and lateral-movement analysis when CloudFox is paired with FoxMapper. Those are described capabilities and potential analysis paths, not guaranteed outcomes in every project or organization.
Permissions and prerequisites
AWS
Install and authenticate the AWS CLI with credentials scoped to the assessment. CloudFox can be used in a white-box engagement with limited read-only permissions or in a black-box exercise using credentials discovered during the engagement. The exact visibility depends on the policies attached to the identity.
Azure
Use the Azure CLI and an account with viewer-like access appropriate to the subscription, tenant or resource scope being assessed. Broader scopes require corresponding authorization.
GCP
Install the Google Cloud SDK and authenticate it for the project or organization in scope. Bishop Fox says roles/viewer is sufficient for basic single-project enumeration; comprehensive organization-wide work requires additional viewer or reviewer roles described by the project documentation.
Installation and updating
CloudFox is distributed as open-source software rather than as a physical product. The project documents four installation routes:
- Download a release binary.
- Install through Homebrew.
- Install with Go.
- Compile from source.
Use the current repository’s installation instructions for the exact package name, binary architecture and release asset. Before running an assessment, verify the installed version and authenticate the provider CLI that matches the cloud you are testing.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Required compatibility update
The repository README carries a December 2025 warning: users need CloudFox v1.17.0 or newer because earlier versions stopped working after AWS changed the format of its public service-mapping file. Treat v1.17.0 as the project-stated minimum, and check the current release for any later requirement before testing.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Typical AWS workflow
- Confirm written authorization, target accounts or organizations, allowed regions and handling rules for discovered secrets.
- Install CloudFox v1.17.0 or newer and the AWS CLI.
- Configure the AWS CLI with the least-privileged credentials that meet the engagement’s goals.
- Run the provider-specific enumeration commands documented by the current release. The AWS documentation includes an all-checks workflow for bundled enumeration.
- Review identities, trust relationships, permissions, workloads, endpoints and exposed data as investigation leads.
- Validate each lead manually and record the identity, scope, evidence and remediation without making unauthorized changes.
How to evaluate CloudFox
| Evaluation question | What to check |
|---|---|
| Provider coverage | AWS and GCP are documented as stable; Azure is listed but marked active development on the wiki. |
| Permission model | Determine whether read-only, viewer-like or broader roles are available and authorized. |
| Workflow style | Use individual modular commands for focused checks or the documented AWS all-checks workflow for a broad pass. |
| Assessment scope | Separate a single account or project review from an organization-wide identity and trust analysis. |
| Maintenance | Check the current release, especially the v1.17.0-or-newer AWS compatibility notice. |
CloudFox versus CloudFoxable
CloudFoxable is a related Bishop Fox practice sandbox for hands-on cloud-security learning. It is separate from the CloudFox enumeration tool and should be treated as a training resource, not as a CloudFox hardware product or a verified commercial affiliate offer.
Is CloudFox an Amazon product?
No. CloudFox is open-source software distributed through binaries, a package manager or source code. There is no supported CloudFox-specific physical Amazon product established by the project materials.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

