feat: more cloud credential discovery #3018
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Adding support for Azure, GCP, and OCI
Also fixed AWS check
Details:
Added file system searches for Azure, GCP, and OCI credentials:
#{file_path}/.azure
with files named eithermsal_token_cache.json
oraccessTokens.json
#{file_path}/.config/gcloud
with files named eithercredentials.db
oraccess_tokens.json
#{file_path}/.oci/sessions
with files namedtoken
Also adjusted the
find
command for the AWS credential search as it would look outside of expected locationsTesting:
Here is the output of me performing all four searches on my local system (macOS):
AWS
Azure
GCP
OCI
Associated Issues:
Previous version of T1552.001-1 exits with code
1
even if credentials are present. This PR fixes thefind
command to return0
.