Modèles d’analyse des secrets
Advanced Security gère plusieurs ensembles de modèles d’analyse des secrets par défaut :
- *Modèles de protection push : utilisés pour détecter les secrets potentiels au moment de l’envoi dans les référentiels avec la protection push de l’analyse des secrets activée.
- Modèles d’alerte utilisateur : utilisés pour détecter les secrets potentiels dans les référentiels où les alertes d’analyse des secrets sont activées.
- Modèles non-fournisseurs : utilisés pour détecter les occurrences courantes de secrets structurés dans les référentiels où les alertes d’analyse des secrets sont activées.
Secrets pris en charge
Section | Explication |
---|---|
Fournisseur | Nom du fournisseur de jetons. |
Nom du jeton | Type de jeton détecté par l’analyse des secrets d'Advanced Security. |
Utilisateur | Un jeton pour lequel des fuites sont signalées aux utilisateurs post-push. S’applique à tous les référentiels où Advanced Security est activé |
Protection push. | Jeton pour lequel des fuites sont signalées aux utilisateurs sur l’envoi (push). S’applique à tous les référentiels où la protection push secrète est activée. |
Validité | Jetons pour lesquels Advanced Security tente d’effectuer une vérification de validité. |
Modèles de fournisseurs de partenaire
Le tableau suivant répertorie les modèles de fournisseurs de partenaire pris en charge par l’analyse des secrets.
Fournisseur | Token Name (Nom du jeton) | Protection Push | Alertes utilisateur | Vérification de validité |
---|---|---|---|---|
E/S Adafruit | AdafruitIOKey | ![]() |
![]() |
|
Adobe | AdobeDeviceToken | ![]() |
||
Adobe | AdobeServiceToken | ![]() |
||
Adobe | AdobeShortLivedAccessToken | ![]() |
||
Akamai | AkamaiCredentials | ![]() |
||
Alibaba Cloud | AlibabaCloudCredentials | ![]() |
![]() |
|
Amazon | AmazonMwsAuthToken | ![]() |
||
Amazon | AmazonOAuthCredentials | ![]() |
![]() |
|
Amazon | AwsCredentials | ![]() |
![]() |
|
Amazon | AwsTemporaryCredentials | ![]() |
![]() |
|
Asana | AsanaPat | ![]() |
![]() |
|
Atlassian | AtlassianApiToken | ![]() |
||
Atlassian | AtlassianJwt | ![]() |
||
Atlassian | BitbucketCloudOAuthCredentials | ![]() |
||
Atlassian | BitbucketServerPat | ![]() |
![]() |
|
Beamer | BeamerApiKey | ![]() |
||
Brevo | BrevoApiKey | ![]() |
![]() |
|
Brevo | BrevoSmtpKey | ![]() |
![]() |
|
Canadian Digital Service | CdsCanadaNotifyApiKey | ![]() |
![]() |
|
Checkout.com | CheckoutIdentifiableSecretKey | ![]() |
||
Chief Tools | ChiefToolsToken | ![]() |
![]() |
|
Cisco | CiscoLocalAccountCredentials | ![]() |
||
Clojars | ClojarsDeployToken | ![]() |
||
Cloudant | CloudantCredentials | ![]() |
||
Cloudflare | CloudflareApiToken | ![]() |
||
Contentful | ContentfulPersonalAccessToken | ![]() |
||
Crates.io | CratesApiKey | ![]() |
||
DevCycle | DevCycleClientApiKey | ![]() |
![]() |
|
DevCycle | DevCycleManagementApiToken | ![]() |
||
DevCycle | DevCycleMobileApiKey | ![]() |
![]() |
|
DevCycle | DevCycleServerApiKey | ![]() |
![]() |
|
DigitalOcean | DigitalOceanOAuthToken | ![]() |
![]() |
|
DigitalOcean | DigitalOceanPat | ![]() |
![]() |
|
DigitalOcean | DigitalOceanRefreshToken | ![]() |
![]() |
|
DigitalOcean | DigitalOceanSystemToken | ![]() |
![]() |
|
Discord | DiscordApiCredentials | ![]() |
||
Discord | DiscordApiToken | ![]() |
![]() |
|
Doppler | DopplerAuditToken | ![]() |
![]() |
|
Doppler | DopplerCliToken | ![]() |
![]() |
|
Doppler | DopplerPersonalToken | ![]() |
![]() |
|
Doppler | DopplerScimToken | ![]() |
![]() |
|
Doppler | DopplerServiceToken | ![]() |
![]() |
|
Dropbox | DropboxAccessToken | ![]() |
||
Dropbox | DropboxAppCredentials | ![]() |
||
Dropbox | DropboxOAuth2ShortLivedAccessToken | ![]() |
![]() |
|
Duffel | DuffelAccessToken | ![]() |
![]() |
|
Dynatrace | DynatraceInternalToken | ![]() |
||
EasyPost | EasyPostApiKey | ![]() |
![]() |
|
Ebay | EBayProductionClientCredentials | ![]() |
||
Ebay | EBaySandboxClientCredentials | ![]() |
||
Elastic | ElasticCloudApiKey | ![]() |
||
Elastic | ElasticStackApiKey | ![]() |
||
EventBrite | PicaticApiKey | ![]() |
||
FacebookAccessToken | ![]() |
|||
FacebookAppCredentials | ![]() |
|||
OculusAccessToken | ![]() |
|||
Fastly | FastlyApiToken | ![]() |
||
Figma | FigmaPat | ![]() |
![]() |
|
Finicity | FinicityAppKey | ![]() |
||
Flutterwave | FlutterwaveLiveApiSecretKey | ![]() |
![]() |
|
Flutterwave | FlutterwaveTestApiSecretKey | ![]() |
||
Frame.io | FrameIODeveloperToken | ![]() |
||
Frame.io | FrameIOJwt | ![]() |
||
Fullstory | FullStoryApiKey | ![]() |
![]() |
|
GitHub | GitHubAppCredentials | ![]() |
||
GitHub | GitHubAppToken | ![]() |
![]() |
|
GitHub | GitHubClassicPat | ![]() |
![]() |
|
GitHub | GitHubOAuthAccessToken | ![]() |
![]() |
|
GitHub | GitHubPat | ![]() |
![]() |
|
GitHub | GitHubRefreshToken | ![]() |
![]() |
|
GitHub | GitHubServerToServerToken | ![]() |
![]() |
|
GitHub | GitHubUserToServerToken | ![]() |
![]() |
|
GitLab | GitLabAccessToken | ![]() |
||
GoCardless | GoCardlessLiveAccessToken | ![]() |
||
GoCardless | GoCardlessSandboxAccessToken | ![]() |
||
FirebaseCloudMessagingServerKey | ![]() |
|||
GoogleApiKey | ![]() |
|||
GoogleCloudPrivateKeyId | ![]() |
![]() |
||
GoogleCloudStorageServiceAccountAccessKey | ![]() |
![]() |
||
GoogleCloudStorageUserAccessKey | ![]() |
![]() |
||
GoogleOAuthAccessToken | ![]() |
|||
GoogleOAuthCredentials | ![]() |
|||
GoogleOAuthRefreshToken | ![]() |
|||
GoogleServiceAccountKey | ![]() |
|||
Grafana | GrafanaApiKey | ![]() |
![]() |
|
Grafana | GrafanaCloudApiToken | ![]() |
||
Grafana | GrafanaProjectApiKey | ![]() |
||
Grafana | GrafanaProjectServiceAccountToken | ![]() |
||
Hashicorp | HashiCorpVaultBatchLegacyToken | ![]() |
![]() |
|
Hashicorp | HashiCorpVaultBatchToken | ![]() |
![]() |
|
Hashicorp | HashiCorpVaultRootServiceToken | ![]() |
![]() |
|
Hashicorp | HashiCorpVaultServiceLegacyToken | ![]() |
![]() |
|
Hashicorp | HashiCorpVaultServiceToken | ![]() |
![]() |
|
Hashicorp | TerraformCloudEnterpriseToken | ![]() |
![]() |
|
HighNote | HighnoteRkKey | ![]() |
![]() |
|
HighNote | HighnoteSkKey | ![]() |
![]() |
|
HubSpot | HubspotApiKey | ![]() |
![]() |
|
HubSpot | HubSpotApiPersonalAccessKey | ![]() |
![]() |
|
HuggingFace | HuggingFaceAccessToken | ![]() |
||
Intercom | IntercomAccessToken | ![]() |
![]() |
|
Ionic | IonicPat | ![]() |
![]() |
|
Ionic | IonicRefreshToken | ![]() |
![]() |
|
JD Cloud | JdCloudAccessKey | ![]() |
||
JFrog | JFrogPlatformAccessToken | ![]() |
![]() |
|
JFrog | JFrogPlatformApiKey | ![]() |
![]() |
|
Linéaire | LinearApiKey | ![]() |
![]() |
|
Linéaire | LinearOAuthAccessToken | ![]() |
![]() |
|
Lob | LobLiveApiKey | ![]() |
||
Lob | LobTestApiKey | ![]() |
||
LocalStack | LocalStackApiKey | ![]() |
||
LogicMonitor | LogicMonitorBearerToken | ![]() |
![]() |
|
LogicMonitor | LogicMonitorLmv1AccessKey | ![]() |
![]() |
|
MailChimp | MailChimpApiKey | ![]() |
||
Mailgun | MailgunApiCredentials | ![]() |
||
Mapbox | MapboxSecretAccessToken | ![]() |
||
MessageBird | MessageBirdApiKey | ![]() |
||
Microsoft | AadClientAppIdentifiableCredentials | ![]() |
![]() |
|
Microsoft | AdoPat | ![]() |
![]() |
|
Microsoft | AzureApimDirectManagementSas | ![]() |
||
Microsoft | AzureApimGatewaySas | ![]() |
||
Microsoft | AzureApimIdentifiableDirectManagementKey | ![]() |
![]() |
|
Microsoft | AzureApimIdentifiableGatewayKey | ![]() |
![]() |
|
Microsoft | AzureApimIdentifiableRepositoryKey | ![]() |
![]() |
|
Microsoft | AzureApimIdentifiableSubscriptionKey | ![]() |
![]() |
|
Microsoft | AzureApimLegacyDirectManagementKey | ![]() |
||
Microsoft | AzureApimLegacyGatewayKey | ![]() |
![]() |
|
Microsoft | AzureApimLegacyRepositoryKey | ![]() |
![]() |
|
Microsoft | AzureApimLegacySubscriptionKey | ![]() |
||
Microsoft | AzureApimRepositorySas | ![]() |
||
Microsoft | AzureAppConfigurationCredentials | ![]() |
![]() |
|
Microsoft | AzureApplicationInsightsCredentials | ![]() |
||
Microsoft | AzureBatchIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureBatchLegacyKey | ![]() |
||
Microsoft | AzureBlockchainCredentials | ![]() |
||
Microsoft | AzureCacheForRedisIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureCacheForRedisIdentifiablePrivateServiceKey | ![]() |
![]() |
|
Microsoft | AzureCacheForRedisLegacyKey | ![]() |
![]() |
|
Microsoft | AzureCdnSas | ![]() |
||
Microsoft | AzureCognitiveServicesKey | ![]() |
||
Microsoft | AzureCognitiveServicesTranslatorKey | ![]() |
||
Microsoft | AzureCommunicationServicesKey | ![]() |
![]() |
|
Microsoft | AzureContainerRegistryIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureContainerRegistryLegacyKey | ![]() |
![]() |
|
Microsoft | AzureCosmosDBIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureCosmosDBIdentifiablePrivateServiceKey | ![]() |
![]() |
|
Microsoft | AzureCosmosDBLegacyKey | ![]() |
![]() |
|
Microsoft | AzureDatabricksPat | ![]() |
![]() |
|
Microsoft | AzureDevOpsOAuthToken | ![]() |
||
Microsoft | AzureEventGridKey | ![]() |
![]() |
|
Microsoft | AzureEventHubIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureEventHubIdentifiablePrivateServiceSystemKey | ![]() |
![]() |
|
Microsoft | AzureFluidRelayKey | ![]() |
||
Microsoft | AzureFunctionIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureFunctionLegacyKey | ![]() |
![]() |
|
Microsoft | AzureGenomicsKey | ![]() |
||
Microsoft | AzureHDInsightCredentials | ![]() |
||
Microsoft | AzureIotDeviceIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureIotDeviceLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureIotDeviceProvisioningIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureIotDeviceProvisioningLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureIotHubIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureIotHubLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureLogicAppSas | ![]() |
||
Microsoft | AzureManagementCertificate | ![]() |
||
Microsoft | AzureMapsKey | ![]() |
||
Microsoft | AzureMixedRealityCredentials | ![]() |
||
Microsoft | AzureMLIdentifiablePrivateServicePrincipalCredentials | ![]() |
![]() |
|
Microsoft | AzureMLWebServiceClassicIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureMLWebServiceKey | ![]() |
||
Microsoft | AzureOpenAIKey | ![]() |
||
Microsoft | AzureRelayIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureSearchIdentifiableAdminKey | ![]() |
![]() |
|
Microsoft | AzureSearchIdentifiablePrivateServiceAdminKey | ![]() |
![]() |
|
Microsoft | AzureSearchIdentifiableQueryKey | ![]() |
![]() |
|
Microsoft | AzureSearchLegacyKey | ![]() |
||
Microsoft | AzureServiceBusIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureServiceBusIdentifiablePrivateServiceSystemKey | ![]() |
![]() |
|
Microsoft | AzureServiceBusLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureServiceDeploymentCredentials | ![]() |
||
Microsoft | AzureSignalRKey | ![]() |
![]() |
|
Microsoft | AzureStorageAccountIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureStorageAccountLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureStorageIdentifiablePrivateServiceKey | ![]() |
![]() |
|
Microsoft | AzureStorageLooseSas | ![]() |
||
Microsoft | AzureStorageSas | ![]() |
||
Microsoft | AzureWebAppBotCredentials | ![]() |
||
Microsoft | AzureWebAppBotKey | ![]() |
||
Microsoft | AzureWebPubSubCredentials | ![]() |
![]() |
|
Microsoft | BingApiKey | ![]() |
||
Microsoft | BingMapsKey | ![]() |
||
Microsoft | BingSearchKey | ![]() |
||
Microsoft | OfficeIncomingWebhook | ![]() |
![]() |
|
Microsoft | Sas | ![]() |
||
Microsoft | SqlIdentifiableCredentials | ![]() |
![]() |
|
Microsoft | VisualStudioAppCenterKey | ![]() |
||
Midtrans | MidtransServerKey | ![]() |
![]() |
|
New Relic | NewRelicInsightsQueryKey | ![]() |
![]() |
|
New Relic | NewRelicLicenseKey | ![]() |
||
New Relic | NewRelicPersonalApiKey | ![]() |
![]() |
|
New Relic | NewRelicRestApiKey | ![]() |
![]() |
|
Notion | NotionIntegrationToken | ![]() |
||
Notion | NotionOAuthClientCredentials | ![]() |
||
npm | NpmAuthorIdentifiableToken | ![]() |
![]() |
|
npm | NpmCredentials | ![]() |
![]() |
|
npm | NpmLegacyAuthorToken | ![]() |
||
NuGet | NuGetApiKey | ![]() |
![]() |
|
NuGet | NuGetCredentials | ![]() |
||
Octopus Deploy | OctopusDeployApiKey | ![]() |
||
Onfido | OnfidoApiToken | ![]() |
![]() |
|
OpenAI | OpenAIApiKeyV2 | ![]() |
![]() |
|
Palantir | PalantirJwt | ![]() |
||
PayPal | PayPalBraintreeAccessToken | ![]() |
||
Utilisateur | PersonaProductionApiKey | ![]() |
![]() |
|
Utilisateur | PersonaSandboxApiKey | ![]() |
||
PineCone | PineconeApiKey | ![]() |
||
PlanetScale | PlanetScaleDatabasePassword | ![]() |
![]() |
|
PlanetScale | PlanetScaleOAuthToken | ![]() |
![]() |
|
PlanetScale | PlanetScaleServiceToken | ![]() |
![]() |
|
Plivo | PlivoCredentials | ![]() |
||
Prefect | PrefectServerApiToken | ![]() |
![]() |
|
Prefect | PrefectUserApiToken | ![]() |
![]() |
|
Proctorio | ProctorioConsumerKey | ![]() |
||
Proctorio | ProctorioLinkageKey | ![]() |
||
Proctorio | ProctorioRegistrationKey | ![]() |
||
Proctorio | ProctorioSecretKeyV2 | ![]() |
![]() |
|
Pulumi | PulumiAccessToken | ![]() |
||
PyPI | PyPiApiToken | ![]() |
||
ReadMe | ReadMeApiKey | ![]() |
![]() |
|
redirect.pizza | RedirectPizzaApiToken | ![]() |
![]() |
|
Rubygems | RubyGemsApiKey | ![]() |
||
SAMPLE | SecretScanningSampleToken | |||
Samsara | SamsaraApiAccessToken | ![]() |
![]() |
|
Samsara | SamsaraOAuth2AccessToken | ![]() |
![]() |
|
Segment.io | SegmentPublicApiToken | ![]() |
||
SendGrid | SendGridApiKey | ![]() |
![]() |
|
Shippo | ShippoLiveApiToken | ![]() |
![]() |
|
Shippo | ShippoTestApiToken | ![]() |
||
Shopify | ShopifyAccessToken | ![]() |
![]() |
|
Shopify | ShopifyAppClientCredentials | ![]() |
||
Shopify | ShopifyAppClientSecret | ![]() |
||
Shopify | ShopifyAppOAuthAccessToken | ![]() |
||
Shopify | ShopifyCustomAppAccessToken | ![]() |
||
Shopify | ShopifyMarketplaceToken | ![]() |
||
Shopify | ShopifyMerchantToken | ![]() |
||
Shopify | ShopifyPartnerApiToken | ![]() |
||
Shopify | ShopifyPrivateAppPassword | ![]() |
||
Shopify | ShopifySharedSecret | ![]() |
![]() |
|
Slack | SlackApiKey | ![]() |
![]() |
|
Slack | SlackAppLevelToken | ![]() |
![]() |
|
Slack | SlackWebhook | ![]() |
||
Slack | SlackWorkflowKey | ![]() |
||
Splunk | SplunkHecApiKey | ![]() |
||
Splunk | SplunkJwtToken | ![]() |
||
Splunk | SplunkSessionKey | ![]() |
||
Carré | SquareApplicationSecret | ![]() |
||
Carré | SquareCredentials | ![]() |
||
Carré | SquarePat | ![]() |
||
SSLMate | SSLMateApiKey | ![]() |
||
SSLMAte | SSLMateClusterSecret | ![]() |
||
Stripe | StripeLiveApiKey | ![]() |
![]() |
|
Stripe | StripeLiveRestrictedApiKey | ![]() |
||
Stripe | StripeTestApiKey | ![]() |
||
Stripe | StripeTestRestrictedApiKey | ![]() |
||
Stripe | StripeWebhookSigningSecret | ![]() |
||
Supabase | SupabaseServiceKey | ![]() |
||
Tableau | TableauPersonalAccessToken | ![]() |
||
Telegram | TelegramBotToken | ![]() |
||
Telnyx | TelnyxApiV2Key | ![]() |
||
Tencent Cloud | TencentCloudCredentials | ![]() |
![]() |
|
Tencent Cloud | TencentCloudSecretId | ![]() |
![]() |
|
Twilio | TwilioApiKeyCredentials | ![]() |
||
Twilio | TwilioCredentials | ![]() |
||
Typeform | TypeformPat | ![]() |
![]() |
|
Uniwise | WISEFlowApiKey | ![]() |
![]() |
|
WakaTime | WakaTimeAppCredentials | ![]() |
![]() |
|
WakaTime | WakaTimeOAuthAccessToken | ![]() |
![]() |
|
WakaTime | WakaTimeOAuthRefreshToken | ![]() |
![]() |
|
WorkOS | WorkOSProductionApiKey | ![]() |
![]() |
|
WorkOS | WorkOSStagingApiKey | ![]() |
||
Yandex | YandexCloudApiKey | ![]() |
||
Yandex | YandexCloudIamAccessSecret | ![]() |
||
Yandex | YandexCloudIamCookie | ![]() |
||
Yandex | YandexCloudIamToken | ![]() |
||
Yandex | YandexDictionaryApiKey | ![]() |
||
Yandex | YandexPassportOAuthToken | ![]() |
![]() |
|
Yandex | YandexPredictorApiKey | ![]() |
||
Yandex | YandexTranslateApiKey | ![]() |
||
Zuplo | ZuploConsumerApiKey | ![]() |
![]() |
Modèles non fournisseurs
Le tableau suivant répertorie les secrets générés par des non-fournisseurs détectés par l’analyse des secrets. Les secrets de non-fournisseurs sont visibles en sélectionnant « Autre » dans la liste déroulante Confiance de l’onglet Analyse des secrets. Pour plus d’informations, consultez Gérer les alertes d’analyse des secrets.
Conseil
La détection des modèles de non-fournisseurs est actuellement en version bêta et susceptible d’être modifiée.
Fournisseur | Secret pris en charge | Token Name (Nom du jeton) |
---|---|---|
Générique | Clé de machine ASP.NET | AspNetMachineKey |
Générique | Clé privée encodée DER | DerPrivateKey |
Générique | Jeton Dynatrace | DynatraceToken |
Générique | Informations d'identification GPG | GpgCredentials |
Générique | En-têtes de requête HTTP | HttpAuthorizationRequestHeader |
Générique | Jeton web JavaScript | GenericJwt |
Générique | Informations d’identification LinkedIn | LinkedInCredentials |
Générique | Chaîne de connexion MongoDB | MongoDbCredentials |
Générique | Chaîne de connexion MySQL/MariaDB | MySqlCredentials |
Générique | Clé privée codée par PEM | PemPrivateKey |
Générique | Clé privée PGP | PgpPrivateKey |
Générique | Clé privée formatée PKCS12 | Pkcs12PrivateKey |
Générique | Chaîne de connexion PostgreSQL | PostgreSqlCredentials |
Générique | Clé privée Putty | PuttyPrivateKey |
Générique | Informations d’identification RabbitMQ | RabbitMqCredentials |
Générique | Clé privée RSA | RsaPrivateKey |
Générique | Chaîne de connexion SQL Server | SqlLegacyCredentials |
Générique | Clé privée SSH | OpenSshPrivateKey |
Générique | Clé privée SSH | GitHubSshPrivateKey |
Générique | Informations d’identification codées par URL | UrlCredentials |