From 175b1e4242a054072df6513d71f7de7e8f024662 Mon Sep 17 00:00:00 2001 From: HAHWUL Date: Thu, 14 Nov 2024 23:10:23 +0900 Subject: [PATCH] feat: Add detection rules for SSH RSA keys Signed-off-by: HAHWUL --- secrets/ssh-rsa-key.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 secrets/ssh-rsa-key.yaml diff --git a/secrets/ssh-rsa-key.yaml b/secrets/ssh-rsa-key.yaml new file mode 100644 index 0000000..2f60c9c --- /dev/null +++ b/secrets/ssh-rsa-key.yaml @@ -0,0 +1,18 @@ +id: ssh-rsa-key +info: + name: Detect SSH_RSA_KEY + author: [hahwul] + severity: critical + description: Detects the presence of SSH RSA keys in the code + reference: [''] +matchers-condition: or +matchers: + - type: word + patterns: ['ssh-rsa'] + condition: or + - type: regex + patterns: + - 'ssh-rsa\s+[A-Za-z0-9+/=]{100,}' + condition: or +category: secret +techs: ['*'] \ No newline at end of file