The last S3 security document that we'll ever need, and how to use it - TrustOnCloud
https://github.com/iamavu/Slyther
Slyther is AWS Security tool to check read/write/delete access for S3 buckets
https://github.com/eth0izzle/bucket-stream
This tool simply listens to various certificate transparency logs (via certstream) and attempts to find public S3 buckets from permutations of the certificates domain name.