Sensitive Data and Secrets Coverage
Plerion Workload Scanner will report on exposed secrets, such as API keys and passwords, from plain text file types found on the workload.
The current supported sensitive data types are:
Vendor | Type(s) |
---|---|
Adobe | Client ID, Client Secret |
Age | Secret Key |
Alibaba | AccessKey ID, Secret Key |
Asana | Client ID, Asana Client Secret |
AsymmetricPrivateKey | private-key |
Atlassian | API Token |
AWS | Secret Access Key |
Beamer | API Token |
Bitbucket | Client ID, Client secret |
Clojars | API Token |
ContentfulDelivery | API Token |
Databricks | API Token |
Discord | Client ID, Client Secret, API Key |
Docker | Docker config secret |
Doppler | API Token |
Dropbox | API Key, API Secret, Short-lived API token, Long-lived API token |
Duffel | API Token |
Dynatrace | API Token |
Easypost | API Token |
API Token | |
Fastly | API Token |
Finicity | API Token, Client Secret |
Flutterwave | Public Key, Secret Key, Encrypted Key |
Frameio | API Token |
GitHub | PAT, OAuth Access Token, App Token, Refresh Token, Fine-grained PAT |
GitLab | Personal Access Token |
GoCardless | API Token |
Google (GCP) Service-account | |
Grafana | API Token |
HashiCorp | API Token |
Heroku | API Key |
HubSpot | API Token |
Intercom | Client ID, Client Secret |
Ionic | API Token |
JWT | JWT Token |
Linear | API Token, Client Secret, Client ID |
Client ID, Client Secret | |
Lob | API Key, Publishable API Key |
Mailchimp | API Key |
Mailgun | Webhook Signing Key, Private API Token |
Mapbox | API Token |
MessageBird | Client ID, API Token |
NewRelic | User API Key, User API ID, Ingest Browser API Token |
npm | Access Token |
Planetscale | API Token, Password |
Postman | API Token |
Pulumi | API Token |
PyPI | Upload Token |
RubyGems | API Token |
SendGrid | API Token |
Sendinblue | API Token |
Shippo | API Token |
Shopify | API Token |
Slack | Access Token |
Stripe | Secret Key, Publishable Key |
Twilio | API Key |
Twitch | API Token |
API Token | |
Typeform | API Token |