Automic VaultAutomic Vault

brew

cloudfox mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für cloudfox in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install cloudfox

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#cloudfox

nixpkgs package indexes · pkgs/by-name/cl/cloudfox/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Automating situational awareness for cloud penetration tests

Verlauf

Projektgeschichte und Nutzung

CloudFox is Bishop Fox's open-source command-line tool for cloud penetration-test situational awareness. It began as an AWS-focused offensive-security enumerator and later grew into a multi-cloud tool covering AWS, Azure, and GCP.

Projektgeschichte

Bishop Fox introduced CloudFox in September 2022 as a way to turn repeated shell, JSON, and cloud-API enumeration work from cloud penetration tests into a portable CLI. The official tool page describes the inspiration as something like PowerView for cloud infrastructure: a set of enumeration commands that reveal practical attack paths.

The project kept the operational model simple for package users: a Go command-line executable with modular commands and GitHub-hosted documentation. By 2026, the CloudFox wiki described AWS, Azure, and GCP support, and Bishop Fox separately announced CloudFox GCP as a purpose-built module suite for Google Cloud attack-path identification.

Adoptionsgeschichte

CloudFox's adoption is concentrated in cloud offensive-security and assessment workflows rather than general cloud administration. Bishop Fox materials present it as a tool used in cloud penetration tests, and the public GitHub project shows a specialist but visible user base, with packaged distribution through Homebrew and Nix recorded in the batch input.

Wie es verwendet wird

Users run CloudFox from the terminal against cloud environments to enumerate identities, permissions, resources, and likely attack paths. The official wiki documents provider-specific command families, including AWS command help and examples, while the README frames the tool as situational awareness for unfamiliar cloud environments.

Warum Paket-Nerds sich dafür interessieren

For package-manager users, CloudFox is a good example of a modern security assessment tool shipped as a cross-platform Go CLI: it is easy to bottle, distribute, and keep close to upstream releases. Its value in Homebrew is that a practitioner can install a cloud-enumeration toolkit without cloning a repository or managing language-specific runtime setup.

Zeitleiste

  • 2022: Bishop Fox introduced CloudFox as an AWS-focused cloud penetration-testing CLI.
  • 2024: The GitHub wiki documented AWS command usage and examples.
  • 2026: Bishop Fox announced CloudFox GCP, and the wiki described AWS, Azure, and GCP support.
  • 2026: GitHub releases listed CloudFox 2.x builds for Linux, macOS, and Windows.

Related projects

  • CloudFox sits near other cloud security enumeration and attack-path projects, but its official materials particularly connect it to Bishop Fox's FoxMapper and to NCC Group's Principal Mapper, because CloudFox GCP can use graph-analysis data for privilege-escalation, lateral-movement, and data-exfiltration paths.

Sicherheitslage

Risikostufe: red

escape, surveillance, or offensive capability signal. infrastructure mutation or orchestration signal.

Risikoklassifikator

red Risiko · mittel Konfidenz · escape-surveillance-offensive

Warum

  • escape, surveillance, or offensive capability signal
  • infrastructure mutation or orchestration signal

Signale

  • text:cloud
  • text:penetration

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
cloudfoxcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version2.0.5
Manager aktualisiert2026-06-15
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv2.0.5

https://github.com/BishopFox/cloudfox

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:cloudfox
Version2.0.5
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/cloudfox
Homepagehttps://bishopfox.com/blog/introducing-cloudfox
Repositoryhttps://github.com/BishopFox/cloudfox
Upstream-Dokumentationhttps://github.com/BishopFox/cloudfox#readme
LizenzMIT
Quellarchivhttps://github.com/BishopFox/cloudfox/archive/refs/tags/v2.0.5.tar.gz
Zuletzt aktualisiert2026-06-15T10:20:13-04:00
Pulseupdated
Build-Abhängigkeitengo
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namecloudfox
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

cloudfox

nix profile install nixpkgs#cloudfox
  • normalized package name match
  • Abgeglichen nach: Cloudfox
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/cl/cloudfox/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment