Alternatives to CloudFox
Inventory cloud permissions and resources during an authorized assessment. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
CloudFox
Inventory cloud permissions and resources during an authorized assessment.
Replacements
Listings that take over the same core job as CloudFox.
Prowler
Check cloud environments for security configuration issues.
Prowler checks cloud environments against security configuration checks and frameworks across several providers, focusing on misconfigurations rather than mapping access relationships.
Pacu
AWS exploitation framework for authorised cloud security testing.
Pacu is an AWS exploitation framework with modules for privilege escalation and backdooring, so it goes beyond inventory into active attacks against AWS accounts only.
AzureHound
A command-line collector that exports Microsoft Azure and Entra ID data for analysis in BloodHound.
AzureHound collects Azure and Entra ID data for attack path analysis, but only covers Microsoft's cloud and needs a BloodHound instance to view results.
Similar software
Related functionality, not a direct replacement.
BloodHound Community Edition
Maps attack paths through Active Directory and Entra ID relationships.
Checkov
Scan infrastructure code for configuration problems.
Trivy
Scan software and infrastructure for known security issues.
Amass
OWASP tool that maps an organisation's external attack surface and assets.
ScubaGear
A CISA PowerShell tool that assesses a Microsoft 365 tenant's configuration against the SCuBA security baselines.
Maester
An open-source PowerShell test framework that checks a Microsoft 365 tenant's security configuration.