Bucket Scanner can scan Amazon S3 as an optional second backend alongside Yandex Cloud Object Storage.
export AWS_REGION=us-east-1
# optional: export AWS_PROFILE=your-profile
# or: export AWS_ACCESS_KEY_ID=... AWS_SECRET_ACCESS_KEY=...
bucket-scanner scan --cloud aws
bucket-scanner scan --cloud aws --aws-region eu-west-1 --probe
bucket-scanner doctor --cloud awsScope in reports uses the AWS account ID from STS (GetCallerIdentity).
No credentials required:
bucket-scanner scan --cloud aws --fixture examples/demo-vulnerable/fixture-aws.tomlIn .bucket-scanner.toml:
[scan]
cloud = "aws"
aws_region = "us-east-1"
aws_profile = "default"
aws_scan_iam = trueAWS buckets get the same core checks as Yandex (ACL, policy, encryption, logging, versioning, lifecycle, tags) plus:
| Rule | Meaning |
|---|---|
aws/block-public-access-incomplete |
Bucket-level Block Public Access not fully enabled |
aws/account-public-access-incomplete |
Account-level Block Public Access not fully enabled |
Minimum IAM for live scans:
s3:ListAllMyBucketss3:GetBucket*,s3:GetEncryptionConfiguration,s3:GetLifecycleConfiguration,s3:GetBucketTaggings3:GetPublicAccessBlock(bucket)s3:GetAccountPublicAccessBlockvia S3 Control (s3control:GetPublicAccessBlock)
Optional IAM user key age checks (aws_scan_iam = true):
iam:ListUsers,iam:ListAccessKeys
Anonymous probe mode uses regional endpoints:
us-east-1:https://{bucket}.s3.amazonaws.com/- Other regions:
https://{bucket}.s3.{region}.amazonaws.com/
Same safety model as Yandex: HEAD + list metadata only, no object body download.
| Yandex (default) | AWS | |
|---|---|---|
| CLI flag | --cloud yandex |
--cloud aws |
| Scope | --folder-id |
STS account ID |
| Auth | YC_TOKEN, SA key, static keys |
AWS profile / env keys |
| Regions | single folder | per-bucket region resolution (default) |
Both backends share chains, SARIF/JSON/Prometheus output, Terraform diff, and repo secret scanning.
bucket-scanner diff examples/demo-vulnerable/terraform-aws \
--cloud aws --fixture examples/demo-vulnerable/fixture-aws.toml