Update js-analyse.yaml

add extractors.
correct some regex to prevent false results.
add word in regex
patch-1
m ayadi 2024-02-17 17:18:34 +01:00 committed by GitHub
parent 11ee01d7b9
commit 2c375882ee
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 7 additions and 3 deletions

View File

@ -18,7 +18,7 @@ file:
- type: regex - type: regex
name: extracted-token name: extracted-token
regex: regex:
- "(?i)(([a-z0-9]+)[-|_])?(key|password|passwd|pass|pwd|private|credential|auth|cred|creds|secret|access|token)([-|_][a-z]+)?(\\s)*(:|=)+" - "(?i)(([a-z0-9]+)[-|_])?(key|password|passwd|pass|pwd|private|credential|auth|cred|creds|secret|access|token|secretaccesskey)([-|_][a-z]+)?(\\s)*(:|=)+"
- type: regex - type: regex
name: extracted-endpoints name: extracted-endpoints
@ -30,5 +30,9 @@ file:
- type: regex - type: regex
name: extracted-uri name: extracted-uri
regex: regex:
- "(?i)([a-z]{0,10}):(//|/)[a-z0-9\\./?&-_=:]+" - "(?i)([a-z]{2,10}):(//|/)[a-z0-9\\./?&-_=:]+"
- type: regex
name: AMAZON-ACCES-KEY
regex:
- "(?i)(A3T[A-Z0-9]|AKIA|AGPA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}"
# digest: 4a0a00473045022074fd41f8b59517248d39216756a55be729fe598400825417fc9ab281c4c626d6022100f3a770bad05731314a45020b4a94b393b96dfae3590e0e526327ac84fa760aa2:922c64590222798bb761d5b6d8e72950 # digest: 4a0a00473045022074fd41f8b59517248d39216756a55be729fe598400825417fc9ab281c4c626d6022100f3a770bad05731314a45020b4a94b393b96dfae3590e0e526327ac84fa760aa2:922c64590222798bb761d5b6d8e72950