#1
We are selling our data from RapidFort from the CanisterWorm campaign we did with TeamPCP. This data is from March, they have failed to notify customers or even make a breach statement. 
And, for the journalists, there's some DoD data in here! Hooray!

Info:
Size on Disk: 569GB
Total Files: 140,061
S3 Buckets extracted from: 48


Price: $40k, negotiable
QTOX:  FD714A3E7C0059EF70825AF78ED544880DC9990EBF9859B798CC8F2B03
Session:  05c8ae06e40a63cfd94d3307a3461ca668aa88bb18686083d6927e969249501075
S3 Bucket Manifest:

rapidfort-dev | 38GB / 1,750 Files
Developer image hardening pipelines, has the input, and the hardened images, in .tar.gz, along with the RSA keys that are related, per job.
Per Job: `vulns.json`, `pkg_analysis.json`, `dirlist.json`, `netscan.json`, `isoscan.json`

rapidfort | 2.4 GB / 30 files
Production hardening bucket
Contains 5 plaintext AWS cred files, for 5 different users

rf-azure-nightly-debug | 13 GB / 585 files
Azure hardening pipeline + Artifacts
Input images, hardened output, vuln scans before + after
Seccomp profiles (syscall allow/deny), package inventories, passwd mappings, env vars etc

rf-azure-nightly-release | 3.9 GB / 74 files 
Production Release validation on Azure, smoketest containers.

rapidfort-transit | 5.1 GB / 7 files
Staging/transit for pipeline jobs
AMI binary images, 6 copies, each 410MB-1.6GB,  raw VM image data for VM hardening workflows

rapidfort-rfscan | 345 MB / 25 files
The RFScan cli tool that RapidFort provides to customers.

That was only the start, the largest category is their Vulnerability DB Pipeline, this is where ~235GB of the data is, across 10 buckets.

rf-vulnerability-data | 13 GB / 151 files
Production vulnerability source data
Per-distro release version mappings 
AI-extended vulnerability data (~80 compressed archives `vulns_ai_extended_data.json_*.tar.xz`), daily snapshots June 2025, suggesting they did ML-enhanced CVE enrichment
Java Maven package archives
Full vuln list archives (`.tar.bz2`, `.tar.xz`)

rf-vulnerability-data-dev-jc1 | 53 GB / 277 files
Dev environment (JC1 cluster) 
Compiled vuln-list snapshots from February 2026

rf-vulnerability-data-dev-jc3 | 42 GB / 585 files
Dev environment (JC3 cluster)
Additional metadata, crosspoll data, Java/Maven data, raw data, relvers

rf-vulnerability-data-test | 130 MB / 52 files
Test environment vulnerability reference
`amazon_all_fixed_vers.json`, CVE justification records
`configdb_backup_*.sql.gz` — SQL database backups

rf-vulnerability-data-test-dev-jc1 | 12 GB / 136 files
Comprehensive test vuln processing environment
Vuln-list archives, Java Maven data, cross-pollination data (`not-for-us.json`)
NVD sync state, EOL release data, Golang module mappings, raw Fedora/RH source data

rf-vulnerability-data-test-dev-jc3 | 57 GB / 107 files 
Largest single bucket
RapidRisk justification store: `rf_justification.json`, `rf_justification_v2.json`, `rf_unknown_packages.json`, `rf_upstream_patch.json`, `rf_packages_patches.json`
Vuln-list archives from December 2025

rfvdb-artifact-storage-preprod | 53 GB / 4,817 files
Pre-production compiled vulnerability database updates
`metadata.json` + timestamped `update.{epoch}.zst|xz` files (~1.5 GB each)
Extremely high file count (5,508 objects listed)

rfvdb-artifact-storage-prod | 50 GB / 71 files
Production vulnerability database updates
Same structure as preprod — metadata + timestamped compressed updates
Dates range from January 31 to February 17, 2025 (epoch timestamps: ~1738353104 to ~1739811780)

rfvdb-artifact-storage-temp | 7.5 GB / 11 files
Temporary vulnerability database artifact storage

rfvdb-pre-artifact-storage-preprod | 28 GB / 4,817 files
Pre-artifact storage for pre-production 
UUID-organized artifact directories

Risk Intel

rapidrisk | 20 GB / 742 files
RapidRisk vulnerability intelligence service
`Justifications/` — CVE triage/justification JSONs with per-CVE status, analyst notes, source URLs (Debian, Kerberos, etc.)
`RapidFixTime/Releases/Data/` — timestamped OS package release dictionaries tracking release cadences across Alpine and other distros for fix-time prediction

DevOps && Infra

rf-devops-automation | 3.7 GB / 603 files
Central DevOps hub
Full Kubernetes kubeconfigs for AKS clusters: `curated-qa1-kubeconfig-sp.yaml` (9.7 KB), `dev-cluster-kubeconfig-sp.yaml` (9.7 KB)
GitLab config with PostgreSQL credentials and Azure storage keys Jenkins Helm overrides
45+ numbered build directories for CLI version tracking
vulnsdb-dump/dump.rdb.xz (vulnerability DB)
`dod-pipeline-override/` Department of Defense platform release manifests & Helm chart overrides (AWS, SaaS, ptrace-stub variants, ingress, cloud-storage, resources, user configs) (DoD Deployment Configs)
AWS billing CSVs (June 2025 – March 2026)
IP allowlist configurations
Platform-specific Helm overrides
3.7 GB zip of Department Of Defense pipeline automation

rf-terraform-state-aws2 | 28 KB / 1 file
Terraform v1.12.2 state file
Defines public ECR repos

cf-templates-1ric9bfggnx6d-us-east-1 | 180 KB / 26 files
CloudFormation templates for customer VM scanner onboarding
Creates cross-account IAM roles (STS AssumeRole) for RapidFort to scan customer EC2 images/snapshots/volumes
Lambda + pivot IAM role stack sets

rapidfort-com-public | 96 KB / 21 files 
Public CloudFormation templates distributed to customers
`RFSTACK-*` per-customer templates creating IAM roles for RapidFort's SaaS scanner access
`CF_RF_AwsScanningScript-v1.json` — generic scanning script template
`unit_test` validation file

curated-release | 1.1 GB / 42 files 
Jenkins build server backups for the curated release pipeline
Daily compressed tar archives: `build-jenkins-YYYYMMDDTHHMMSS.tar.gz` (November 2025)
Many duplicate copies due to failed downloads (partial-download resume artifacts)

Scanner Data

redis-dump-scanner | 18 GB / 91 files 
Redis database backups from the scanner service
RDB dump files (up to 2.4 GB uncompressed) — `dump.rdb.*`, `dump_20_12_24.rdb.*`, `dump-janit.rdb.*`
AWS Inspector vulnerability scan findings for Nexus3 
Package analysis from nginx scans
cross-distro package alias mapping
scanner comparison test script (Trivy, JFrog, Snyk, Anchore/Grype)
`rfcat.tar` (845 MB), `rfcli.tar` (566 MB) — CLI tool images
SPDX documents, BOM scripts, vulnerability JSONs 
`backup.tar.gz` (765 MB) — general backup
`Legacy/` subdirectory with older data

scanner-storage | 33 GB / 52 files
`rf_dev_unvalidated_artifact/`  unvalidated scanner artifacts with metadata + compressed updates

scanner-scrapper-data | 32 GB / 89 files
`artifact/` — scanner scraper artifacts

artifacthub-crawl | 134 MB / 10,827 files
Crawled ArtifactHub data (Helm chart registry) 
`package_details/` — 10,647 JSON files (one per Helm package UUID) with name, description, readme, CVE counts, container images, versions, repo metadata
`package_meta/` — paginated listing files
Used to identify which Helm charts/images to scan or harden

cloudfront-274057717848-logs | 6 GB / 37,953 files
CloudFront CDN access logs for distribution `E14VNCQB9IHDQA` (`cdn.rapidfort.com`)
Date range: September–October 2025
Logs show Ubuntu package mirror requests (`/mirror5/mirror/archive.ubuntu.com/`) and curated packages (`/pub2/curated/rfubu/`)
Each entry: timestamp, client IP, HTTP method, URI, status, user-agent, bytes

rf-aws-nlb-logs-2 | 39 MB / 50 files
Kubernetes pod container logs via AWS NLB
`iso-master` (container isolation/instrumentation) pods — production, staging, CI
`aws-logs-write-test` permission validation files

aws-cloudtrail-logs-274057717848-eb381d52 | empty (0 files)

aws-cloudtrail-logs-274057717848-f5a27da3 — 456 KB / 77 files
Second CloudTrail destination — some AWS API call logs present

Billing

cost-data-exports | 525 MB / 66 files
AWS Cost and Usage Reports (CUR)
Monthly exports: February 2024 – January 2026
`Manifest.json` + gzipped CSV billing data
Columns: line-item costs, product details, pricing, reservations, savings plans
Resource tags: `user:Customer`, `user:GeneratedBy`, `user:Purpose`

Test Envs

rf-test-us-east-1 | 650 MB / 49 files
Container scanning test environment
EC2 bootstrap configs (`user_data`) with app admin credentials and IAM role ARNs
UUID-organized image analysis results (input images, stubbed output, vuln/package reports)
Docker registry storage backend

rf-test-us-west-2 | 20 KB / 2 files
Simply bootstrap creds, nothing else

rapidfort-e2e-logs | 504 KB / 59 files
E2E test execution logs (19 timestamped test run folders)
Container test logs: rfstub, rfcat, rfrbom
VM STIG compliance scan logs, Grype scanner results
Tests against `nightly.azure.rapidfort.io` covering 76+ container images

rapidfort-test-encryption | 16 KB / 3 files
three throwaway files testing S3 encryption

standalone-test-rf | 43 MB / 42 files
Standalone scanner test environment
Per-IP directories (`10.0.38.224`, `172.31.85.50`, etc.) with scan results
UUID-organized artifact directories

rapidfort-demo | 28 KB / 5 files
FluentD logs from a demo Kubernetes cluster (February 2021)

Security Testing 

aws-takeovercloud-pivot-s3-access-testing | 12 KB / 2 files
CTF/security exercise artifacts
Lambda function `lambda_function.py` that creates an IAM role with `AdministratorAccess` policy
Trusts an externally-specified role ARN for AWS account takeover pivot simulation
A `.zip` deployment package of the same

There's a further 11 empty/inactive buckets, I am not listing these, they contain nothing and the post is long enough as is.

Exposed Credentials & Secrets

6 AWS Credential pairs
2 full kubeconfig files with service principal auth for AKS clusters
GitLab PostgreSQL creds
GitLab PostgreSQL replication user credentials
PostgreSQL password
Full Azure storage account key
Access key with full container access to GitLab registry storage
RSA private keys and encryption keys
EC2 Instance Credentials
QTOX:??300B2D5FD09996D9DCFD714A3E7C0059EF70825AF78ED544880DC9990EBF9859B798CC8F2B03
Session:??05c8ae06e40a63cfd94d3307a3461ca668aa88bb18686083d6927e969249501075