Stats
Actions
Tags
From greyhatcc
Hunt for cloud infrastructure misconfigurations - S3 buckets, Firebase, Cognito, CDN origins
How this command is triggered — by the user, by Claude, or both
Slash command
/greyhatcc:cloud <domain or org name>This command is limited to the following tools:
The summary Claude sees in its command listing — used to decide when to auto-load this command
# Cloud Misconfiguration Hunting
Invoke the `greyhatcc:cloud-misconfig` skill for target: {{ARGUMENTS}}
Systematic cloud infrastructure assessment across all major providers:
**AWS:**
- S3 bucket discovery via DNS brute force, JS bundle extraction, and CNAME analysis
- S3 permission testing: ListBucket, GetObject, PutObject, ACL enumeration
- S3 bucket takeover detection for abandoned buckets still referenced by the target
- CloudFront misconfiguration: origin access, cache behavior, custom error pages
- Cognito user pool enumeration: self-signup, attribute manipulation, unverified claim...Invoke the greyhatcc:cloud-misconfig skill for target: {{ARGUMENTS}}
Systematic cloud infrastructure assessment across all major providers:
AWS:
Google Cloud:
Azure:
General Cloud Attacks:
npx claudepluginhub overtimepog/greyhatcc --plugin greyhatcc