Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
oss — Cross-cloud S3-compatible object storage CLI to list, export, and download buckets across AWS, Aliyun, Tencent, Huawei and more, with anonymous browsing and bucket discovery scanning. | Kitploit
Tools/GitHubGitHub/ejfkdev/oss
Cloud Infrastructure SecurityOSINT (Open Source Intelligence)ReconnaissanceScripting & AutomationData ExfiltrationInformation GatheringPenetration TestingCloud SecurityUtilities & FrameworksAPI Security
GitHub
12221 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
ejfkdev/oss

oss

Cross-cloud S3-compatible object storage CLI to list, export, and download buckets across AWS, Aliyun, Tencent, Huawei and more, with anonymous browsing and bucket discovery scanning.

View Repository
Share

oss

ci release

中文 | English

A cross-cloud object storage CLI based on the S3 protocol. One binary for all major providers: AWS S3, Aliyun OSS, Tencent COS, Huawei OBS, Baidu BOS, Kingsoft KS3, UCloud US3, JD Cloud OSS, Google Cloud Storage, Cloudflare R2, Scaleway, Wasabi, DigitalOcean Spaces, Yandex, Exoscale, Arvan Cloud, Backblaze B2, MinIO and any other S3-compatible service.

  • 🌐 Anonymous bucket browsing: just pass a URL to list/download public-read buckets — no credentials needed
  • 🔗 URL as the entry point: access via https://... URLs; provider domains are recognized and bucket/region parsed automatically. URL query parameters (prefix, delimiter, max-keys, continuation-token, marker, start-after) act as listing filters, similar to aws-s3-bucket-browser
  • 📁 Path-forwarded buckets: buckets mounted under a path by a reverse proxy / CDN (e.g. https://files.example.com/mybucket/) are handled automatically via path-style parsing
  • 🎫 Extra query params passthrough: non-listing URL parameters (e.g. ?token=abc auth gateways) are injected into every API request (list/download/upload/presign) before SigV4 signing
  • 🔑 Flexible auth: AK/SK, STS session tokens, AWS profiles (incl. assume-role), anonymous
  • 🗂 Listing cache: fetched listings are cached locally by default; repeated listing/export becomes instant (hundreds of times faster for -d-style full-scan cases)
  • 📤 Export file lists: export filtered listings to txt / csv / xlsx / yaml / markdown (--export)
  • ⬇️ Filtered batch download: cp -r downloads everything matching --include/--exclude/--prefix, preserving the key directory structure
  • 🔍 Bucket discovery: find probes (batch: multiple args / stdin) which cloud storage hosts a bucket, accepting bucket names and full bucket URLs; anonymous probes also detect whether anonymous directory listing is allowed, highlighting anonymously listable buckets in bright green, with --export to txt/csv/xlsx/yaml/md including a dedicated listable_url field
  • 🔌 Network access: oss serve offers a REST API + OpenAPI 3 document + MCP tool endpoint on one port; oss mcp stdio|http|sse exposes ls/stat/cat/presign/find as MCP tools for clients like Claude
  • 🎨 Terminal-friendly: colored output on interactive terminals, plain text when piped (--color auto|always|never)
  • 🌍 Bilingual help: the system language is auto-detected — Chinese help in Chinese environments, English otherwise (override with OSS_LANG=zh|en)
  • 📄 Huge-bucket friendly: streaming pagination (constant memory), NDJSON streaming output, bounded concurrent downloads — millions of objects without memory pressure
  • 🚀 Parallel transfers: multi-file concurrency + per-file multipart concurrency, progress bars, skip-existing, atomic .part writes
  • 🛠 Network control: -x proxy, -H custom headers (UA / Cookie …), -k skip TLS verification

Installation

Option 1: Homebrew (macOS / Linux, recommended)

brew install ejfkdev/tap/oss

Option 2: go install (requires Go 1.24+)

go install github.com/ejfkdev/oss@latest

Option 3: prebuilt binaries

Download the archive for your platform from GitHub Releases (linux/darwin/windows × amd64/arm64) and extract. Release binaries are stripped; Linux/Windows builds are UPX-compressed (macOS builds are not: UPX-packed Mach-O binaries are killed by the kernel). Every release ships with a SHA256 checksum file.

Option 4: build from source (requires Go 1.24+):

git clone https://github.com/ejfkdev/oss && cd oss
make build      # produces ./oss
make install    # installs into $GOPATH/bin
make release    # cross-compiles all platforms into dist/

Quick start

# Browse a public bucket anonymously (no credentials)
oss ls https://noaa-nwm-pds.s3.amazonaws.com/?delimiter=/
oss ls "https://noaa-nwm-pds.s3.amazonaws.com/?prefix=nwm.20250101/&delimiter=/&max-keys=20"
oss cp -r https://noaa-nwm-pds.s3.amazonaws.com/nwm.20250101/ ./nwm/ --jobs 32

# Aliyun OSS
oss ls oss://mybucket/logs/ --ak <AK> --sk <SK> --region cn-hangzhou
export OSS_ACCESS_KEY_ID=xxx OSS_SECRET_ACCESS_KEY=yyy   # or use env vars
oss ls mybucket --provider aliyun                         # bare bucket name

# Tencent COS / Huawei OBS
oss ls s3://bucket-1250000000 --provider tencent --region ap-guangzhou
oss ls https://bucket.obs.cn-north-4.myhuaweicloud.com/prefix/

# Yandex / Exoscale / Arvan
oss ls s3://mybucket --provider yandex
oss ls s3://mybucket --provider exoscale --region ch-gva-2

# MinIO / self-hosted S3
oss ls s3://mybucket -e http://127.0.0.1:9000 --ak minioadmin --sk minioadmin
oss ls http://127.0.0.1:9000/mybucket/prefix/             # IP/port auto-detected as path-style

# Proxy, custom UA / Cookie
oss ls s3://mybucket -x http://127.0.0.1:7890 \
    -H "User-Agent: my-agent/1.0" -H "Cookie: session=abc"

# Path-forwarded bucket (reverse proxy mounting a bucket under a path)
oss ls "https://files.example.com/mybucket/?prefix=2026/&max-keys=10"
oss cp "https://files.example.com/mybucket/<key>" ./

# Access with extra parameters (token etc. is attached to every request)
oss ls "http://gateway.example.com/bucket?token=abc"
oss cp "http://gateway.example.com/bucket/file.bin?token=abc" ./

Target syntax

FormExample
schemes3://bucket/prefix, oss://, cos://, obs://
bare bucketmybucket/prefix (with --provider / -e)
HTTP URLhttps://bucket.s3.us-east-1.amazonaws.com/prefix?prefix=logs/

Provider domains recognized automatically (endpoint / region / bucket are parsed):

ProviderDomain example
AWSbucket.s3.region.amazonaws.com, s3.region.amazonaws.com/bucket
Aliyunbucket.oss-cn-hangzhou.aliyuncs.com (incl. accelerate)
Tencentbucket-appid.cos.ap-guangzhou.myqcloud.com
Huaweibucket.obs.cn-north-4.myhuaweicloud.com
Baidu BOSbucket.s3.bj.bcebos.com, s3.bj.bcebos.com/bucket
Kingsoft KS3bucket.ks3-cn-beijing.ksyuncs.com
UCloud US3bucket.s3-cn-sh2.ufileos.com
JD Cloud OSSs3.cn-north-1.jdcloud-oss.com/bucket (path-style)
CTYun OOSbucket.oos-cn.ctyunapi.cn (incl. resource-pool & Hong Kong endpoints)
CUCloud OSSbucket.obs-helf.cucloud.cn (industry-cloud regions)
China Mobile EOSbucket.eos-wuxi-1.cmecloud.cn (30 regions)
QingCloud QStorbucket.s3.pek3a.qsstor.com (S3-compatible domain qsstor.com)
Scalewaybucket.s3.fr-par.scw.cloud (fr-par/nl-ams/pl-waw)
Wasabibucket.s3.us-east-1.wasabisys.com (14 regions)
DigitalOcean Spacesnyc3.digitaloceanspaces.com/bucket (9 regions)
Yandexbucket.storage.yandexcloud.net
Exoscale SOSbucket.ch-gva-2.sos.exoscale.com (6 regions)
Arvan Cloudbucket.s3.ir-thr-at1.arvanstorage.ir
Cloudflare R2bucket.<account_id>.r2.cloudflarestorage.com
GCSstorage.googleapis.com/bucket (HMAC keys)

Any other host (MinIO, Ceph, path-forwarded buckets, CNAME…) is parsed as path-style: the first path segment is the bucket, the rest is the key, e.g. https://files.example.com/mybucket/sub/key.jpg → bucket mybucket, key sub/key.jpg. If the host points directly at a bucket (CNAME), use --bucket NAME explicitly. With no target at all, oss ls lists all buckets.

URL query parameters fall into two categories:

Download Tool