{"id":13390888,"url":"https://github.com/cyberark/BlobHunter","last_synced_at":"2025-03-13T15:32:19.008Z","repository":{"id":41316442,"uuid":"326657311","full_name":"cyberark/BlobHunter","owner":"cyberark","description":"Find exposed data in Azure with this public blob scanner","archived":false,"fork":false,"pushed_at":"2024-07-07T16:03:35.000Z","size":37350,"stargazers_count":304,"open_issues_count":2,"forks_count":56,"subscribers_count":25,"default_branch":"main","last_synced_at":"2024-08-04T21:07:24.629Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://cyberark.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cyberark.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-01-04T11:09:20.000Z","updated_at":"2024-08-01T20:03:53.000Z","dependencies_parsed_at":"2024-07-07T17:26:43.925Z","dependency_job_id":"83ba3688-7e9a-433a-b243-ad4c1167f4ac","html_url":"https://github.com/cyberark/BlobHunter","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":"cyberark/conjur-template","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyberark%2FBlobHunter","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyberark%2FBlobHunter/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyberark%2FBlobHunter/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyberark%2FBlobHunter/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cyberark","download_url":"https://codeload.github.com/cyberark/BlobHunter/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":221380092,"owners_count":16809020,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-30T14:01:36.098Z","updated_at":"2024-10-25T03:30:51.026Z","avatar_url":"https://github.com/cyberark.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\r\n\r\n# BlobHunter\r\n\r\nAn opensource tool for scanning Azure blob storage accounts for publicly opened blobs.  \r\nBlobHunter is a part of [Hunting Azure Blobs Exposes Millions of Sensitive Files](https://www.cyberark.com/resources/threat-research-blog/hunting-azure-blobs-exposes-millions-of-sensitive-files) research.  \r\n  \r\n## Overview\r\n\r\nBlobHunter helps you identify Azure blob storage containers which store files that are publicly available to anyone with an internet connection.  \r\nThe tool will help mitigate risk by identifying poorly configured containers that store sensitive data, which is specifically helpful in larger scale Azure subscriptions where there are a significant number of storage accounts that could be hard to track.  \r\nBlobHunter produces an informative csv result file that provides important details on each publicly opened container in the scanned environment.\r\n\r\n## Requirements\r\n\r\n1. Python 3.5+\r\n\r\n2. Azure CLI\r\n\r\n3. [`requirements.txt`](requirements.txt) packages\r\n\r\n4. Azure user with one of the following [built-in roles](https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles):\r\n\r\n   -\t[Owner](https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#owner)  \r\n   -  [Contributor](https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#contributor)  \r\n   -\t[Storage Account Contributor](https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#storage-account-contributor)  \r\n\r\n   Or any Azure user with a role that allows to perform the following Azure actions:\r\n\r\n   ```\r\n   Microsoft.Resources/subscriptions/read\r\n   Microsoft.Resources/subscriptions/resourceGroups/read\r\n   Microsoft.Storage/storageAccounts/read\r\n   Microsoft.Storage/storageAccounts/listkeys/action\r\n   Microsoft.Storage/storageAccounts/blobServices/containers/read\r\n   Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read\r\n   ```\r\n\r\n## Build\r\n\r\n#### Example for installation on Ubuntu:\r\n\r\n```bash\r\ncurl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash\r\n```\r\n\r\n```bash\r\npip3 install -r requirements.txt\r\n```\r\n\r\n## Usage\r\n\r\nSimply run\r\n\r\n```\r\npython3 BlobHunter.py\r\n```\r\n\r\nIf you are not logged in in the Azure CLI, a browser window will be prompted at you for inserting your Azure user credentials.\r\n\r\n## Demo\r\n![BlobHunter](https://github.com/cyberark/BlobHunter/blob/assets/BlobHunterDemo.gif)\r\n\r\n## References\r\n\r\nFor any question or feedback, please contact [Daniel Niv](https://github.com/DanielNiv), [Asaf Hecht](https://twitter.com/Hechtov) and CyberArk Labs.\r\n\r\n## License\r\n\r\nCopyright (c) 2021 CyberArk Software Ltd. All rights reserved.  \r\nLicensed under the MIT License.  \r\nFor the full license text see [`LICENSE`](LICENSE).\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcyberark%2FBlobHunter","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcyberark%2FBlobHunter","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcyberark%2FBlobHunter/lists"}