
Scan for misconfigured S3 buckets across S3-compatible APIs!
Features - Usage - Quick Start - Installation - Discuss
INPUT: (1 required)
-bucket string Name of bucket to check.
-bucket-file string File of bucket names to check.
-mq Connect to RabbitMQ to get buckets. Requires config file key "mq". Default: "false"
OUTPUT:
-db Save results to a Postgres database. Requires config file key "db.uri". Default: "false"
-json Print logs to stdout in JSON format instead of human-readable. Default: "false"
OPTIONS:
-enumerate Enumerate bucket objects (can be time-consuming). Default: "false"
-provider string Object storage provider: aws, custom, digitalocean, dreamhost, gcp, linode, scaleway - custom requires config file. Default: "aws"
-threads int Number of threads to scan with. Default: "4"
DEBUG:
-verbose Enable verbose logging. Default: "false"
-version Print version Default: "false"
If config file is required these locations will be searched for config.yml: "." "/etc/s3scanner/" "$HOME/.s3scanner/"
If you've found this tool useful, please consider donating to support its development. You can find sponsor options on the side of this repo page or in FUNDING.yml
Huge thank you to tines for being an ongoing sponsor of this project.
Scan AWS for bucket names listed in a file, enumerate all objects
$ s3scanner -bucket-file names.txt -enumerate
Scan a bucket in GCP, enumerate all objects, and save results to database
$ s3scanner -provider gcp -db -bucket my-bucket -enumerate
| Platform | Version | Steps |
|---|---|---|
| BlackArch | pacman -S s3scanner | |
| Docker | docker run ghcr.io/sa7mon/s3scanner | |
| Go | go install -v github.com/sa7mon/s3scanner@latest | |
| Kali Linux | apt install s3scanner | |
| MacOS | brew install s3scanner | |
| Parrot OS | apt install s3scanner | |
| Windows - winget | winget install s3scanner | |
| NixOS stable | nix-shell -p s3scanner | |
| NixOS unstable | nix-shell -p s3scanner | |
| Other - Build from source | git clone [email protected]:sa7mon/S3Scanner.git && cd S3Scanner && go build -o s3scanner . |
s3scanner requires exactly one type of input: -bucket, -bucket-file, or -mq.
INPUT: (1 required)
-bucket string Name of bucket to check.
-bucket-file string File of bucket names to check.
-mq Connect to RabbitMQ to get buckets. Requires config file key "mq". Default: "false"
-bucketScan a single bucket
s3scanner -bucket secret_uploads