|
1 | 1 | ---
|
2 | 2 | - Amazon:
|
3 | 3 | - Access Key: (?:A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA|ABIA|ACCA)[A-Z0-9]{16}
|
4 |
| - - Secret Access Key Variable: (?i)(amazon|amz|aws)[-_]{0,1}(secret)[-_]{0,1}((access)[-_]{0,1}){0,1}key |
5 | 4 | # - Cognito User Pool ID: (?i)us-[a-z]{2,}-[a-z]{4,}-\d{1,}
|
6 | 5 | - RDS Password: (?i)(rds\-master\-password|db\-password)
|
7 |
| - - S3 Private Key Variable: (?i)AWS_S3_PRIVATE_KEY|s3_key|S3_PRIVATE_KEY |
8 |
| - - Security Token Header Variable: (?i)X-Amz-Security-Token |
9 |
| - - API Gateway Key Source Header Variable: (?i)x-amazon-apigateway-api-key-source |
10 |
| - - S3 Bucket: (?i)AWS_S3_BUCKET|s3_bucket |
11 | 6 | - SNS Confirmation URL: (?i)https:\/\/sns\.[a-z0-9-]+\.amazonaws\.com\/?Action=ConfirmSubscription&Token=[a-zA-Z0-9-=_]+
|
12 |
| - - SES SMTP Password Variable: (?i)ses_smtp_password |
13 |
| - - AWS Private Key Variable: (?i)ec2\-private\-key|EC2_PRIVATE_KEY |
14 | 7 | - MWS Token: (amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})
|
15 | 8 | - AppSync GraphQL Key: \bda2-[a-z0-9]{26}
|
16 | 9 |
|
17 | 10 | - Microsoft:
|
18 |
| - - Azure API Key Variable: (?i)Ocp-Apim-Subscription-Key |
19 |
| - - Azure Functions Key Header Variable: (?i)x-functions-key |
20 | 11 | # - Azure account key
|
21 | 12 | # - Azure account name
|
22 | 13 | - Azure Connection String: (?i)(.*.windows.net).+(password)
|
23 | 14 | - Azure Endpoint Key: (?i)(defaultendpointsprotocol).+(key).+
|
24 | 15 | - Client Secret: (?i)(?:client_secret|ClientSecret)[\s:\"]{0,3}[a-zA-Z0-9\-_]{36,}
|
25 | 16 | - Graph API Key: (?i)MSGRAPH_[a-zA-Z0-9\-_]{20,40}
|
26 | 17 | - Outlook Webhook URL: (?i)https:\/\/outlook\.office\.com\/webhook\/[A-Za-z0-9\-]{60,}
|
27 |
| - - OneDrive Access Token Variable: (?i)onedrive_access_token |
28 |
| - - SQL Connection Password Variable: mssql.connection.password |
29 | 18 |
|
30 | 19 | - DigitalOcean:
|
31 | 20 | - API Key: (?i)do_[a-z0-9]{60}
|
32 |
| - - Environment Variable: (?i)\b(DO|DIGITALOCEAN).+(API|OAUTH|ACCESS)*(TOKEN|KEY)\b |
33 | 21 |
|
34 | 22 | - Shopify:
|
35 | 23 | - Custom App Token: (?i)shpca_[a-fA-F0-9]{32}
|
|
61 | 49 | - Cloud Service Account Private Key: (?i)"-----BEGIN PRIVATE KEY-----[A-Za-z0-9\/+=\n]+-----END PRIVATE KEY-----"
|
62 | 50 | - Cloud Service Account Key ID: (?i)"private_key_id":\s*"[a-f0-9]{32}"
|
63 | 51 | - Cloud Project Number: (?i)"project_number":\s*"\d{12}"
|
64 |
| - - API Key Header Variable: (?i)x-goog-api-key |
65 | 52 | - Client ID: "[0-9]+-[0-9A-Za-z_]{32}\\.apps\\.googleusercontent\\.com"
|
66 | 53 |
|
67 | 54 | - GitHub:
|
|
77 | 64 | - GitLab:
|
78 | 65 | - Personal Access Token: (?i)glpat-[A-Za-z0-9\-_]{20}
|
79 | 66 | - OAuth Access Token: (?i)glOauth-[A-Za-z0-9\-_]{20,50}
|
80 |
| - - GitLab CI Token Variable: (?i)gitlab(?:-|_|.)(?:ci(?:-|_|.))?(?:job(?:-|_|.))?token |
81 | 67 | - Repository Access Token: (?i)glrepo-[A-Za-z0-9\-_]{20,50}
|
82 | 68 | - Secret File Token: (?i)(?:secret_token|CI_JOB_TOKEN)[^{}]{0,20}( ){0,1}[=:]( ){0,1}([A-Za-z0-9\-_]{20,50})
|
83 | 69 | - Project Secret Token: (?i)glproj-[A-Za-z0-9\-_]{20,50}
|
84 | 70 | #- Classic Token: (?i)(?:gitlab)[^{}()<>?*&:%@!\/= \n]{0,40}[\"\']?\s{0,50}(?::|=>|=)\s{0,50}[\"\']?([a-zA-Z0-9-_]{20})
|
85 | 71 |
|
86 |
| -- Cisco: |
87 |
| - - Meraki API Key Header Variable: (?i)X-Cisco-Meraki-API-Key |
88 |
| - |
89 |
| -- CoinMarketCap: |
90 |
| - - API Key Header Variable: (?i)X-CMC_PRO_API_KEY |
91 |
| - |
92 |
| -- Algolia: |
93 |
| - - API Key Header Variable: (?i)X-Algolia-API-Key |
94 |
| - |
95 | 72 | - Slack:
|
96 | 73 | - User Token: (xox[ps]-[0-9]{8,13}-[0-9]{8,13}-[0-9]{8,13}-[a-zA-Z0-9-]{10,32})
|
97 | 74 | - Bot Token: (xox[b]-[0-9]{8,13}-[0-9]{8,13}-[a-zA-Z0-9-]{20,30})
|
|
168 | 145 | - Telegram:
|
169 | 146 | - Bot API Key: (?:bot)*[0-9]{8,10}:AA[0-9A-Za-z\-_=]{33}
|
170 | 147 |
|
171 |
| -- SonarSource: |
172 |
| - - API Key Variable: sonar(qube|source)_(api_key|token|key) |
173 |
| - |
174 |
| -- Kakao: |
175 |
| - - API Key Variable: (?i)KAKAO(_|-){0,1}API(_|-){0,1}KEY |
176 |
| - |
177 | 148 | - Airtable:
|
178 | 149 | - API Key: (?i)(?:airtable).{0,40}[\"\'`]?\s{0,50}(?::|=>|=|,)\s{0,50}[\"\'`]?(key[a-zA-Z0-9_-]{14})
|
179 | 150 | - Table URL: https:\/\/api\.airtable\.com\/v0\/[\w]+\/[\w]+
|
|
184 | 155 | #- Clearbit:
|
185 | 156 | # - API Key: (?i)(?:clearbit)[^{}]{0,20}( ){0,1}[=:]( ){0,1}.{0,40}(sk_[0-9a-z_]{24,32})
|
186 | 157 |
|
187 |
| -- Flask: |
188 |
| - - App Secret Key Variable: APP_SECRET_KEY |
189 |
| - |
190 |
| -- Shodan: |
191 |
| - - API Key Variable: (?i)(shodan_key|shodan_api_key|shodan_token) |
192 |
| - |
193 |
| -- Homebrew: |
194 |
| - - API Token Variable: (?i)HOMEBREW_GITHUB_API_TOKEN |
195 |
| - |
196 |
| -- Jekyll: |
197 |
| - - GitHub API Token Variable: (?i)JEKYLL_GITHUB_TOKEN |
198 |
| - |
199 | 158 | - OpenAI:
|
200 | 159 | - Project API Key: (?i)sk-proj-[\w-]+T3BlbkFJ[\w-]+
|
201 | 160 | - User API Key: (?i)sk-[^proj]\w.+T3BlbkFJ[\w-]+
|
202 |
| - - API Key Variable: (?i)openai(.|_)api_key |
203 | 161 |
|
204 | 162 | - Groq:
|
205 | 163 | - API Key: (?i)gsk_[A-Za-z0-9]+
|
206 |
| - - API Key Variable: (?i)GROQ(_|-){0,1}API(_|-){0,1}KEY |
207 |
| - |
208 |
| -- Pinecone: |
209 |
| - - API Key Variable: (?i)PINECONE(_|-){0,1}API(_|-){0,1}KEY |
210 |
| - |
211 |
| -- LangChain: |
212 |
| - - API Key Variable: (?i)LANGCHAIN(_|-){0,1}API(_|-){0,1}KEY |
213 |
| - |
214 |
| -- ElevenLabs: |
215 |
| - - API Key Variable: (?i)ELEVENLABS(_|-){0,1}API(_|-){0,1}KEY |
216 |
| - |
217 |
| -- CartesiaAI: |
218 |
| - - API Key Variable: (?i)CARTESIA(_|-){0,1}API(_|-){0,1}KEY |
219 | 164 |
|
220 | 165 | - OpenWeatherMap:
|
221 | 166 | - API Key URL: (?i)(?:https?://api\.openweathermap\.org/data/[a-z0-9.+?\/]+=)([a-z0-9]{32})
|
|
231 | 176 | - API Key: (?i)key-[0-9a-zA-Z]{32}
|
232 | 177 | - Domain Sending Key: "[a-f0-9]{32}-[a-f0-9]{8}-[a-f0-9]{8}"
|
233 | 178 |
|
234 |
| -- Okta: |
235 |
| - - API Key Variable: (?i)(?:okta_api_key) |
236 |
| - |
237 | 179 | - Hashicorp:
|
238 | 180 | - Terraform API Token: (?i)([A-Za-z0-9]{14}.atlasv1.[A-Za-z0-9]{67})
|
239 | 181 | - Vault Unseal Key: (?i)unseal.?(?:key|token)[^)(|\s"\'<>,&#]?.{0,40}([a-fA-F0-9\/_\-=][^|\s"\'<>,&#]{43})
|
|
255 | 197 |
|
256 | 198 | - Figma:
|
257 | 199 | - Personal Access Token: (figd_[a-zA-Z0-9-_]{14,32}_[a-zA-Z0-9-_]{14,32})
|
258 |
| - - Token Header Variable: (?i)X-Figma-Token |
259 | 200 |
|
260 | 201 | - Adafruit.io:
|
261 | 202 | - API Key: aio_[a-zA-Z0-9]{28}
|
|
269 | 210 | #- IBM:
|
270 | 211 | # - Cloud User Key: (?i)(?:ibm)[^{}]{0,20}( ){0,1}[=:]( ){0,1}(-_[A-Za-z0-9_-]{42})
|
271 | 212 |
|
272 |
| -- Heroku: |
273 |
| - - API Key Variable: (?i)heroku_api_key |
274 |
| - - App Name Variable: (?i)heroku_app_name |
275 |
| - |
276 | 213 | - Freshdesk:
|
277 | 214 | - API Token: (?i)(?:freshdesk)[^{}()<>?*&:%@.\-!\/\n]{0,40}\b([0-9A-Za-z]{16,24})
|
278 | 215 |
|
|
304 | 241 | - Access Token: (sq0atp-[0-9A-Za-z\-_]{22})
|
305 | 242 |
|
306 | 243 | - Saucelabs:
|
307 |
| - - TestFairy Key Variable: (?i)testfairy_{0,}(access_key|key|secret|token|shared_secret|sharedsecret) |
308 | 244 | - TestFairy OAuth Token URL: https://testfairy\.atlassian\.net/plugins/servlet/oauth/authorize\?oauth_token-\w{32}
|
309 |
| - - Key Variable: (?i)sauce_token |
310 |
| - |
311 |
| -- Hockeyapp: |
312 |
| - - Key Variable: (?i)(?:hockeyapp_key) |
313 | 245 |
|
314 | 246 | - NuGet:
|
315 | 247 | - API Key: (?i)(?:nuget).{0,40}(oy2[a-z0-9]{43})
|
316 | 248 |
|
317 | 249 | - Cloudinary:
|
318 | 250 | - API URL: cloudinary://.+/
|
319 |
| - |
320 |
| -- CodeClimate: |
321 |
| - - Key Variable: (?i)(?:codeclimate_key) |
322 |
| - |
323 |
| -- Pingdom: |
324 |
| - - Token Variable: (?i)(?:pingdom_token) |
325 | 251 |
|
326 | 252 | - Ngrok:
|
327 |
| - - Auth Token Variable: (?i)ngrok.set_auth_token |
328 | 253 | - API Key Block: (?i)add-api-key
|
329 | 254 | - Authentication Token Block: (?i)add-authtoken
|
330 | 255 | - Connection URL Block: (?i)add-connect-url
|
331 | 256 |
|
332 |
| -- Line: |
333 |
| - - Token Variable: (?i)line_(channel|secret|token) |
334 |
| - |
335 |
| -- Crunchbase: |
336 |
| - - API Key Header Variable: (?i)X-Cb-User-Key |
337 |
| - |
338 |
| -- RapidAPI: |
339 |
| - - Key Header Variable: (?i)x-rapidapi-key |
340 |
| - |
341 | 257 | - WeChat:
|
342 | 258 | - App Key: (?:^|['\"`])(wx[a-f0-9]{16})(?:$|['\"`])
|
343 | 259 |
|
|
347 | 263 | - Vercel:
|
348 | 264 | - Blob Read/Write Token: vercel_blob_rw_\w{47,49}
|
349 | 265 | - Project ID: \bprj_.{28}\b
|
350 |
| - - Project ID Variable: (?i)PROJECT_ID_VERCEL |
351 |
| - - Turbo Build Token Variable: (?i)TURBO_TOKEN |
352 |
| - - Access Token Variable: (?i)VERCEL_ACCESS_TOKEN |
353 |
| - |
354 |
| -- PuTTY: |
355 |
| - - Private Lines Variable: Private-Lines |
356 |
| - - Private MAC Variable: Private-MAC |
357 | 266 |
|
358 | 267 | - Postgresql:
|
359 | 268 | - URL: (?i)(?:pgsql:|postgres:|postgresql:)//[\S]{1,256}:[\S]{1,256}@[-.%\w\/:]+\.[\S]+
|
360 |
| - - Password Variable: (?i)POSTGRES_PASSWORD |
361 | 269 |
|
362 | 270 | - GitHub:
|
363 | 271 | - Access Token: (?i)\bghp_[A-Za-z0-9]{36}\b
|
|
382 | 290 | - Bearer Token: "(Authorization: )*((b|B)earer [a-zA-Z0-9+\\/._=-]{16,512})(={0,2})"
|
383 | 291 | - Basic Token: "(Authorization: )*((b|B)asic [a-zA-Z0-9+\\/._=-]{16,512})(={0,2})"
|
384 | 292 | - JSON Web Token: \beyJ[a-zA-Z0-9]{3,}\.eyJ[A-Za-z0-9_\\/+-]{3,}\.[A-Za-z0-9_\\/+-]{3,}\b
|
385 |
| - - JSON Web Token Variable: (?i)JWT_SECRET |
386 | 293 | # Tokens
|
387 | 294 | #- Refresh Token Variable: (?i)refresh[_-]{0,1}token
|
388 |
| - - Access Token Variable: (?i)access[_-]{0,1}token |
389 |
| - - Token Variable: (?i)token |
390 |
| - - Password Variable: (?i)password |
391 |
| - - API Key Variable: (?i)_api_key |
392 |
| - - API Key Header Variable: X-Api-Key |
393 |
| - - Secret Key Variable: (?i)secret_key |
394 |
| - - User Key Variable: (?i)user_key |
395 |
| - - Secret Variable: (?i).+secret\b |
396 |
| - - Consumer Key Variable: (?i)consumer(\.|_)?key |
397 |
| - - Consumer Secret Variable: (?i)consumer(\.|_)?secret |
398 | 295 | # URLs
|
399 | 296 | - Auth URL: (?i)((https?|ftps?|ssh|sftp)://[^":@>\]\[\n\s*/]+:[^:@/>\]\[\n\s*/]+([^>\]\[\n\s*:][@]{1})\w+(\.\w+)+)
|
400 | 297 | - Redis URL: (?i)((redis?)://[^":@>\]\[\n\s*/]+:[^:@/>\]\[\n\s*/]+([^>\]\[\n\s*:][@]{1})\w+(\.\w+)+)
|
|
0 commit comments