Modèles d’analyse des secrets
Advanced Security gère plusieurs ensembles de modèles d’analyse des secrets par défaut :
- *Modèles de protection push : utilisés pour détecter les secrets potentiels au moment de l’envoi dans les référentiels avec la protection push de l’analyse des secrets activée.
- Modèles d’alerte utilisateur : utilisés pour détecter les secrets potentiels dans les référentiels où les alertes d’analyse des secrets sont activées.
- Modèles non-fournisseurs : utilisés pour détecter les occurrences courantes de secrets structurés dans les référentiels où les alertes d’analyse des secrets sont activées.
Secrets pris en charge
Section | Explication |
---|---|
Fournisseur | Nom du fournisseur de jetons. |
Nom du jeton | Type de jeton détecté par l’analyse des secrets d'Advanced Security. |
Utilisateur | Un jeton pour lequel des fuites sont signalées aux utilisateurs post-push. S’applique à tous les référentiels où Advanced Security est activé |
Protection push. | Jeton pour lequel des fuites sont signalées aux utilisateurs sur l’envoi (push). S’applique à tous les référentiels où la protection push secrète est activée. |
Validité | Jetons pour lesquels Advanced Security tente d’effectuer une vérification de validité. |
Modèles de fournisseurs de partenaire
Le tableau suivant répertorie les modèles de fournisseurs de partenaire pris en charge par l’analyse des secrets.
Fournisseur | Token Name (Nom du jeton) | Protection Push | Alertes utilisateur | Vérification de validité |
---|---|---|---|---|
E/S Adafruit | AdafruitIOKey | |||
Adobe | AdobeDeviceToken | |||
Adobe | AdobeServiceToken | |||
Adobe | AdobeShortLivedAccessToken | |||
Akamai | AkamaiCredentials | |||
Alibaba Cloud | AlibabaCloudCredentials | |||
Amazon | AmazonMwsAuthToken | |||
Amazon | AmazonOAuthCredentials | |||
Amazon | AwsCredentials | |||
Amazon | AwsTemporaryCredentials | |||
Asana | AsanaPat | |||
Atlassian | AtlassianApiToken | |||
Atlassian | AtlassianJwt | |||
Atlassian | BitbucketCloudOAuthCredentials | |||
Atlassian | BitbucketServerPat | |||
Beamer | BeamerApiKey | |||
Brevo | BrevoApiKey | |||
Brevo | BrevoSmtpKey | |||
Canadian Digital Service | CdsCanadaNotifyApiKey | |||
Checkout.com | CheckoutIdentifiableSecretKey | |||
Chief Tools | ChiefToolsToken | |||
Cisco | CiscoLocalAccountCredentials | |||
Clojars | ClojarsDeployToken | |||
Cloudant | CloudantCredentials | |||
Cloudflare | CloudflareApiToken | |||
Contentful | ContentfulPersonalAccessToken | |||
Crates.io | CratesApiKey | |||
DevCycle | DevCycleClientApiKey | |||
DevCycle | DevCycleManagementApiToken | |||
DevCycle | DevCycleMobileApiKey | |||
DevCycle | DevCycleServerApiKey | |||
DigitalOcean | DigitalOceanOAuthToken | |||
DigitalOcean | DigitalOceanPat | |||
DigitalOcean | DigitalOceanRefreshToken | |||
DigitalOcean | DigitalOceanSystemToken | |||
Discord | DiscordApiCredentials | |||
Discord | DiscordApiToken | |||
Doppler | DopplerAuditToken | |||
Doppler | DopplerCliToken | |||
Doppler | DopplerPersonalToken | |||
Doppler | DopplerScimToken | |||
Doppler | DopplerServiceToken | |||
Dropbox | DropboxAccessToken | |||
Dropbox | DropboxAppCredentials | |||
Dropbox | DropboxOAuth2ShortLivedAccessToken | |||
Duffel | DuffelAccessToken | |||
Dynatrace | DynatraceInternalToken | |||
EasyPost | EasyPostApiKey | |||
Ebay | EBayProductionClientCredentials | |||
Ebay | EBaySandboxClientCredentials | |||
Elastic | ElasticCloudApiKey | |||
Elastic | ElasticStackApiKey | |||
EventBrite | PicaticApiKey | |||
FacebookAccessToken | ||||
FacebookAppCredentials | ||||
OculusAccessToken | ||||
Fastly | FastlyApiToken | |||
Figma | FigmaPat | |||
Finicity | FinicityAppKey | |||
Flutterwave | FlutterwaveLiveApiSecretKey | |||
Flutterwave | FlutterwaveTestApiSecretKey | |||
Frame.io | FrameIODeveloperToken | |||
Frame.io | FrameIOJwt | |||
Fullstory | FullStoryApiKey | |||
GitHub | GitHubAppCredentials | |||
GitHub | GitHubAppToken | |||
GitHub | GitHubClassicPat | |||
GitHub | GitHubOAuthAccessToken | |||
GitHub | GitHubPat | |||
GitHub | GitHubRefreshToken | |||
GitHub | GitHubServerToServerToken | |||
GitHub | GitHubUserToServerToken | |||
GitLab | GitLabAccessToken | |||
GoCardless | GoCardlessLiveAccessToken | |||
GoCardless | GoCardlessSandboxAccessToken | |||
FirebaseCloudMessagingServerKey | ||||
GoogleApiKey | ||||
GoogleCloudPrivateKeyId | ||||
GoogleCloudStorageServiceAccountAccessKey | ||||
GoogleCloudStorageUserAccessKey | ||||
GoogleOAuthAccessToken | ||||
GoogleOAuthCredentials | ||||
GoogleOAuthRefreshToken | ||||
GoogleServiceAccountKey | ||||
Grafana | GrafanaApiKey | |||
Grafana | GrafanaCloudApiToken | |||
Grafana | GrafanaProjectApiKey | |||
Grafana | GrafanaProjectServiceAccountToken | |||
Hashicorp | HashiCorpVaultBatchLegacyToken | |||
Hashicorp | HashiCorpVaultBatchToken | |||
Hashicorp | HashiCorpVaultRootServiceToken | |||
Hashicorp | HashiCorpVaultServiceLegacyToken | |||
Hashicorp | HashiCorpVaultServiceToken | |||
Hashicorp | TerraformCloudEnterpriseToken | |||
HighNote | HighnoteRkKey | |||
HighNote | HighnoteSkKey | |||
HubSpot | HubspotApiKey | |||
HubSpot | HubSpotApiPersonalAccessKey | |||
HuggingFace | HuggingFaceAccessToken | |||
Intercom | IntercomAccessToken | |||
Ionic | IonicPat | |||
Ionic | IonicRefreshToken | |||
JD Cloud | JdCloudAccessKey | |||
JFrog | JFrogPlatformAccessToken | |||
JFrog | JFrogPlatformApiKey | |||
Linéaire | LinearApiKey | |||
Linéaire | LinearOAuthAccessToken | |||
Lob | LobLiveApiKey | |||
Lob | LobTestApiKey | |||
LocalStack | LocalStackApiKey | |||
LogicMonitor | LogicMonitorBearerToken | |||
LogicMonitor | LogicMonitorLmv1AccessKey | |||
MailChimp | MailChimpApiKey | |||
Mailgun | MailgunApiCredentials | |||
Mapbox | MapboxSecretAccessToken | |||
MessageBird | MessageBirdApiKey | |||
Microsoft | AadClientAppIdentifiableCredentials | |||
Microsoft | AdoPat | |||
Microsoft | AzureApimDirectManagementSas | |||
Microsoft | AzureApimGatewaySas | |||
Microsoft | AzureApimIdentifiableDirectManagementKey | |||
Microsoft | AzureApimIdentifiableGatewayKey | |||
Microsoft | AzureApimIdentifiableRepositoryKey | |||
Microsoft | AzureApimIdentifiableSubscriptionKey | |||
Microsoft | AzureApimLegacyDirectManagementKey | |||
Microsoft | AzureApimLegacyGatewayKey | |||
Microsoft | AzureApimLegacyRepositoryKey | |||
Microsoft | AzureApimLegacySubscriptionKey | |||
Microsoft | AzureApimRepositorySas | |||
Microsoft | AzureAppConfigurationCredentials | |||
Microsoft | AzureApplicationInsightsCredentials | |||
Microsoft | AzureBatchIdentifiableKey | |||
Microsoft | AzureBatchLegacyKey | |||
Microsoft | AzureBlockchainCredentials | |||
Microsoft | AzureCacheForRedisIdentifiableKey | |||
Microsoft | AzureCacheForRedisIdentifiablePrivateServiceKey | |||
Microsoft | AzureCacheForRedisLegacyKey | |||
Microsoft | AzureCdnSas | |||
Microsoft | AzureCognitiveServicesKey | |||
Microsoft | AzureCognitiveServicesTranslatorKey | |||
Microsoft | AzureCommunicationServicesKey | |||
Microsoft | AzureContainerRegistryIdentifiableKey | |||
Microsoft | AzureContainerRegistryLegacyKey | |||
Microsoft | AzureCosmosDBIdentifiableKey | |||
Microsoft | AzureCosmosDBIdentifiablePrivateServiceKey | |||
Microsoft | AzureCosmosDBLegacyKey | |||
Microsoft | AzureDatabricksPat | |||
Microsoft | AzureDevOpsOAuthToken | |||
Microsoft | AzureEventGridKey | |||
Microsoft | AzureEventHubIdentifiableKey | |||
Microsoft | AzureEventHubIdentifiablePrivateServiceSystemKey | |||
Microsoft | AzureFluidRelayKey | |||
Microsoft | AzureFunctionIdentifiableKey | |||
Microsoft | AzureFunctionLegacyKey | |||
Microsoft | AzureGenomicsKey | |||
Microsoft | AzureHDInsightCredentials | |||
Microsoft | AzureIotDeviceIdentifiableKey | |||
Microsoft | AzureIotDeviceLegacyCredentials | |||
Microsoft | AzureIotDeviceProvisioningIdentifiableKey | |||
Microsoft | AzureIotDeviceProvisioningLegacyCredentials | |||
Microsoft | AzureIotHubIdentifiableKey | |||
Microsoft | AzureIotHubLegacyCredentials | |||
Microsoft | AzureLogicAppSas | |||
Microsoft | AzureManagementCertificate | |||
Microsoft | AzureMapsKey | |||
Microsoft | AzureMixedRealityCredentials | |||
Microsoft | AzureMLIdentifiablePrivateServicePrincipalCredentials | |||
Microsoft | AzureMLWebServiceClassicIdentifiableKey | |||
Microsoft | AzureMLWebServiceKey | |||
Microsoft | AzureOpenAIKey | |||
Microsoft | AzureRelayIdentifiableKey | |||
Microsoft | AzureSearchIdentifiableAdminKey | |||
Microsoft | AzureSearchIdentifiablePrivateServiceAdminKey | |||
Microsoft | AzureSearchIdentifiableQueryKey | |||
Microsoft | AzureSearchLegacyKey | |||
Microsoft | AzureServiceBusIdentifiableKey | |||
Microsoft | AzureServiceBusIdentifiablePrivateServiceSystemKey | |||
Microsoft | AzureServiceBusLegacyCredentials | |||
Microsoft | AzureServiceDeploymentCredentials | |||
Microsoft | AzureSignalRKey | |||
Microsoft | AzureStorageAccountIdentifiableKey | |||
Microsoft | AzureStorageAccountLegacyCredentials | |||
Microsoft | AzureStorageIdentifiablePrivateServiceKey | |||
Microsoft | AzureStorageLooseSas | |||
Microsoft | AzureStorageSas | |||
Microsoft | AzureWebAppBotCredentials | |||
Microsoft | AzureWebAppBotKey | |||
Microsoft | AzureWebPubSubCredentials | |||
Microsoft | BingApiKey | |||
Microsoft | BingMapsKey | |||
Microsoft | BingSearchKey | |||
Microsoft | OfficeIncomingWebhook | |||
Microsoft | Sas | |||
Microsoft | SqlIdentifiableCredentials | |||
Microsoft | VisualStudioAppCenterKey | |||
Midtrans | MidtransServerKey | |||
New Relic | NewRelicInsightsQueryKey | |||
New Relic | NewRelicLicenseKey | |||
New Relic | NewRelicPersonalApiKey | |||
New Relic | NewRelicRestApiKey | |||
Notion | NotionIntegrationToken | |||
Notion | NotionOAuthClientCredentials | |||
npm | NpmAuthorIdentifiableToken | |||
npm | NpmCredentials | |||
npm | NpmLegacyAuthorToken | |||
NuGet | NuGetApiKey | |||
NuGet | NuGetCredentials | |||
Octopus Deploy | OctopusDeployApiKey | |||
Onfido | OnfidoApiToken | |||
OpenAI | OpenAIApiKeyV2 | |||
Palantir | PalantirJwt | |||
PayPal | PayPalBraintreeAccessToken | |||
Utilisateur | PersonaProductionApiKey | |||
Utilisateur | PersonaSandboxApiKey | |||
PineCone | PineconeApiKey | |||
PlanetScale | PlanetScaleDatabasePassword | |||
PlanetScale | PlanetScaleOAuthToken | |||
PlanetScale | PlanetScaleServiceToken | |||
Plivo | PlivoCredentials | |||
Prefect | PrefectServerApiToken | |||
Prefect | PrefectUserApiToken | |||
Proctorio | ProctorioConsumerKey | |||
Proctorio | ProctorioLinkageKey | |||
Proctorio | ProctorioRegistrationKey | |||
Proctorio | ProctorioSecretKeyV2 | |||
Pulumi | PulumiAccessToken | |||
PyPI | PyPiApiToken | |||
ReadMe | ReadMeApiKey | |||
redirect.pizza | RedirectPizzaApiToken | |||
Rubygems | RubyGemsApiKey | |||
SAMPLE | SecretScanningSampleToken | |||
Samsara | SamsaraApiAccessToken | |||
Samsara | SamsaraOAuth2AccessToken | |||
Segment.io | SegmentPublicApiToken | |||
SendGrid | SendGridApiKey | |||
Shippo | ShippoLiveApiToken | |||
Shippo | ShippoTestApiToken | |||
Shopify | ShopifyAccessToken | |||
Shopify | ShopifyAppClientCredentials | |||
Shopify | ShopifyAppClientSecret | |||
Shopify | ShopifyAppOAuthAccessToken | |||
Shopify | ShopifyCustomAppAccessToken | |||
Shopify | ShopifyMarketplaceToken | |||
Shopify | ShopifyMerchantToken | |||
Shopify | ShopifyPartnerApiToken | |||
Shopify | ShopifyPrivateAppPassword | |||
Shopify | ShopifySharedSecret | |||
Slack | SlackApiKey | |||
Slack | SlackAppLevelToken | |||
Slack | SlackWebhook | |||
Slack | SlackWorkflowKey | |||
Splunk | SplunkHecApiKey | |||
Splunk | SplunkJwtToken | |||
Splunk | SplunkSessionKey | |||
Carré | SquareApplicationSecret | |||
Carré | SquareCredentials | |||
Carré | SquarePat | |||
SSLMate | SSLMateApiKey | |||
SSLMAte | SSLMateClusterSecret | |||
Stripe | StripeLiveApiKey | |||
Stripe | StripeLiveRestrictedApiKey | |||
Stripe | StripeTestApiKey | |||
Stripe | StripeTestRestrictedApiKey | |||
Stripe | StripeWebhookSigningSecret | |||
Supabase | SupabaseServiceKey | |||
Tableau | TableauPersonalAccessToken | |||
Telegram | TelegramBotToken | |||
Telnyx | TelnyxApiV2Key | |||
Tencent Cloud | TencentCloudCredentials | |||
Tencent Cloud | TencentCloudSecretId | |||
Twilio | TwilioApiKeyCredentials | |||
Twilio | TwilioCredentials | |||
Typeform | TypeformPat | |||
Uniwise | WISEFlowApiKey | |||
WakaTime | WakaTimeAppCredentials | |||
WakaTime | WakaTimeOAuthAccessToken | |||
WakaTime | WakaTimeOAuthRefreshToken | |||
WorkOS | WorkOSProductionApiKey | |||
WorkOS | WorkOSStagingApiKey | |||
Yandex | YandexCloudApiKey | |||
Yandex | YandexCloudIamAccessSecret | |||
Yandex | YandexCloudIamCookie | |||
Yandex | YandexCloudIamToken | |||
Yandex | YandexDictionaryApiKey | |||
Yandex | YandexPassportOAuthToken | |||
Yandex | YandexPredictorApiKey | |||
Yandex | YandexTranslateApiKey | |||
Zuplo | ZuploConsumerApiKey |
Modèles non fournisseurs
Le tableau suivant répertorie les secrets générés par des non-fournisseurs détectés par l’analyse des secrets. Les secrets de non-fournisseurs sont visibles en sélectionnant « Autre » dans la liste déroulante Confiance de l’onglet Analyse des secrets. Pour plus d’informations, consultez Gérer les alertes d’analyse des secrets.
Conseil
La détection des modèles de non-fournisseurs est actuellement en version bêta et susceptible d’être modifiée.
Fournisseur | Secret pris en charge | Token Name (Nom du jeton) |
---|---|---|
Générique | Clé de machine ASP.NET | AspNetMachineKey |
Générique | Clé privée encodée DER | DerPrivateKey |
Générique | Jeton Dynatrace | DynatraceToken |
Générique | Informations d'identification GPG | GpgCredentials |
Générique | En-têtes de requête HTTP | HttpAuthorizationRequestHeader |
Générique | Jeton web JavaScript | GenericJwt |
Générique | Informations d’identification LinkedIn | LinkedInCredentials |
Générique | Chaîne de connexion MongoDB | MongoDbCredentials |
Générique | Chaîne de connexion MySQL/MariaDB | MySqlCredentials |
Générique | Clé privée codée par PEM | PemPrivateKey |
Générique | Clé privée PGP | PgpPrivateKey |
Générique | Clé privée formatée PKCS12 | Pkcs12PrivateKey |
Générique | Chaîne de connexion PostgreSQL | PostgreSqlCredentials |
Générique | Clé privée Putty | PuttyPrivateKey |
Générique | Informations d’identification RabbitMQ | RabbitMqCredentials |
Générique | Clé privée RSA | RsaPrivateKey |
Générique | Chaîne de connexion SQL Server | SqlLegacyCredentials |
Générique | Clé privée SSH | OpenSshPrivateKey |
Générique | Clé privée SSH | GitHubSshPrivateKey |
Générique | Informations d’identification codées par URL | UrlCredentials |