Examine HTTP headers, error messages, and API responses for AWS account IDs, region names, resource ARNs, and internal hostnames. - Check whether CloudFormation or Terraform state files are accessible in any S3 bucket.