daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

secrets-enumeration.md (2331B)


      1 ---
      2 title: "Hardcoded Secrets Enumeration"
      3 section: "DevOps"
      4 sectionSlug: "devops"
      5 sourcePath: "docs/devops/secrets-enumeration.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/devops/secrets-enumeration.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Hardcoded Secrets Enumeration
     12 
     13 ## Tools
     14 
     15 * [synacktiv/nord-stream](https://github.com/synacktiv/nord-stream) - List the secrets stored inside CI/CD environments and extract them by deploying malicious pipelines
     16 * [xforcered/SCMKit](https://github.com/xforcered/SCMKit) - Source Code Management Attack Toolkit
     17 
     18 ## Search inside Repositories, Files and Codes
     19 
     20 * Discover repositories being used in a particular SCM system
     21 
     22     ```ps1
     23     SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local
     24     SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local
     25     ```
     26 
     27 * Search for repositories by repository name in a particular SCM system
     28 
     29     ```ps1
     30     SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"
     31     SCMKit.exe -s gitlab -m searchrepo -c apikey -u https://gitlab.something.local -o "some search term"
     32     ```
     33 
     34 * Search for code containing a given keyword in a particular SCM system
     35 
     36     ```ps1
     37     SCMKit.exe -s github -m searchcode -c userName:password -u https://github.something.local -o "some search term"
     38     SCMKit.exe -s github -m searchcode -c apikey -u https://github.something.local -o "some search term"
     39     ```
     40 
     41 * Search for files in repositories containing a given keyword in the file name in a particular SCM system
     42 
     43     ```ps1
     44     SCMKit.exe -s gitlab -m searchfile -c userName:password -u https://gitlab.something.local -o "some search term"
     45     SCMKit.exe -s gitlab -m searchfile -c apikey -u https://gitlab.something.local -o "some search term"
     46     ```
     47 
     48 * List snippets owned by the current user in GitLab
     49 
     50     ```ps1
     51     SCMKit.exe -s gitlab -m listsnippet -c userName:password -u https://gitlab.something.local
     52     SCMKit.exe -s gitlab -m listsnippet -c apikey -u https://gitlab.something.local
     53     ```
     54 
     55 ## References
     56 
     57 * [CI/CD SECRETS EXTRACTION, TIPS AND TRICKS - Hugo Vincent, Théo Louis-Tisserand - 01/03/2023](https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks.html)