Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
S3Scanner — Scan for misconfigured S3 buckets across S3-compatible APIs! | Kitploit
Tools/GitHubGitHub/sa7mon/s3scanner
Vulnerability ScannersInformation GatheringCloud SecurityMisconfiguration
GitHubsa7mon/s3scanner

S3Scanner

Scan for misconfigured S3 buckets across S3-compatible APIs!

View Repository
3.2k414182 months agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

S3Scanner

Features - Usage - Quick Start - Installation - Discuss


A tool to find open S3 buckets in AWS or other cloud providers:
  • AWS
  • DigitalOcean
  • DreamHost
  • GCP
  • Linode
  • Scaleway
  • Custom
demo

Features

  • ⚡️ Multi-threaded scanning
  • 🔭 Supports many built-in S3 storage providers or custom
  • 🕵️‍♀️ Scans all bucket permissions to find misconfigurations
  • 💾 Save results to Postgres database
  • 🐇 Connect to RabbitMQ for automated scanning at scale
  • 🐳 Docker support

Used By

banner for six2dez/reconftw banner for yogeshojha/rengine banner for pry0cc/axiom - reads 'the dynamic infrastructure framework for everybody'

Usage

INPUT: (1 required)
  -bucket        string  Name of bucket to check.
  -bucket-file   string  File of bucket names to check.
  -mq                    Connect to RabbitMQ to get buckets. Requires config file key "mq". Default: "false"

OUTPUT:
  -db       Save results to a Postgres database. Requires config file key "db.uri". Default: "false"
  -json     Print logs to stdout in JSON format instead of human-readable. Default: "false"

OPTIONS:
  -enumerate           Enumerate bucket objects (can be time-consuming). Default: "false"
  -provider    string  Object storage provider: aws, custom, digitalocean, dreamhost, gcp, linode, scaleway - custom requires config file. Default: "aws"
  -threads     int     Number of threads to scan with. Default: "4"

DEBUG:
  -verbose     Enable verbose logging. Default: "false"
  -version     Print version Default: "false"

If config file is required these locations will be searched for config.yml: "." "/etc/s3scanner/" "$HOME/.s3scanner/"

🚀 Support

If you've found this tool useful, please consider donating to support its development. You can find sponsor options on the side of this repo page or in FUNDING.yml

Huge thank you to tines for being an ongoing sponsor of this project.

Quick Start

Scan AWS for bucket names listed in a file, enumerate all objects

$ s3scanner -bucket-file names.txt -enumerate

Scan a bucket in GCP, enumerate all objects, and save results to database

$ s3scanner -provider gcp -db -bucket my-bucket -enumerate

Installation

PlatformVersionSteps
BlackArchBlackArch packagepacman -S s3scanner
DockerDocker releasedocker run ghcr.io/sa7mon/s3scanner
GoGolanggo install -v github.com/sa7mon/s3scanner@latest
Kali LinuxKali packageapt install s3scanner
MacOShomebrew versionbrew install s3scanner
Parrot OSParrot packageapt install s3scanner
Windows - wingetwinget install s3scanner
NixOS stablenixpkgs unstable packagenix-shell -p s3scanner
NixOS unstablenixpkgs unstable packagenix-shell -p s3scanner
Other - Build from sourceGitHub releasegit clone [email protected]:sa7mon/S3Scanner.git && cd S3Scanner && go build -o s3scanner .

Using

Input

s3scanner requires exactly one type of input: -bucket, -bucket-file, or -mq.

INPUT: (1 required)
  -bucket        string  Name of bucket to check.
  -bucket-file   string  File of bucket names to check.
  -mq                    Connect to RabbitMQ to get buckets. Requires config file key "mq". Default: "false"

-bucket

Scan a single bucket

s3scanner -bucket secret_uploads
Download Tool