Skip to content
← LibraryTechnique entry
C-PUBLIC-BUCKET-HUNTReconnaissance

Public Bucket Hunting

Brute-force bucket names (S3, GCS, Azure Blob) via wordlists scoped to org name + common patterns; check ACL.

§ Where this technique fits

C-PUBLIC-BUCKET-HUNT is catalogued under the Reconnaissance tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 1 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    S3 / Blob / GCS Mass Exfil
    C-S3-EXFIL · Collection
    seen 1×