Security tool · cloud

s3scanner

Scans for open S3 buckets (and other cloud storage) and dumps their permissions. Fast cloud misconfig discovery.

awsbucketscloud
Stable IDtool:s3scannerLast updatedLast verifiedLegacy review pendingProvenanceSource-linked

Where s3scanner fits

Scans for open S3 buckets (and other cloud storage) and dumps their permissions. Fast cloud misconfig discovery.

Detection-first use

Start with the least intrusive template that can distinguish your hypothesis from a normal response. Preserve raw output and a negative control.

Installation references

Install with pipxAuthorization required
pipx install s3scanner
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.
Install with goAuthorization required
go install -v github.com/sa7mon/s3scanner@latest
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.

Command templates

Scan bucket listAuthorization required

Populate placeholders only with assets that are explicitly in scope.

s3scanner -bucket-file {input}
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.

Continue the workflow

Attribution and verification

Version history: normalized permanent page created 2026-08-20. Upstream activity and popularity are separate signals and do not establish tool safety.