[ { "part": "filename", "type": "regex", "pattern": "\\A.*_rsa\\z", "caption": "Private SSH key", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A.*_dsa\\z", "caption": "Private SSH key", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A.*_ed25519\\z", "caption": "Private SSH key", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A.*_ecdsa\\z", "caption": "Private SSH key", "description": null }, { "part": "path", "type": "regex", "pattern": "\\.?ssh/config\\z", "caption": "SSH configuration file", "description": null }, { "part": "extension", "type": "match", "pattern": "pem", "caption": "Potential cryptographic private key", "description": null }, { "part": "extension", "type": "regex", "pattern": "\\Akey(pair)?\\z", "caption": "Potential cryptographic private key", "description": null }, { "part": "extension", "type": "match", "pattern": "pkcs12", "caption": "Potential cryptographic key bundle", "description": null }, { "part": "extension", "type": "match", "pattern": "pfx", "caption": "Potential cryptographic key bundle", "description": null }, { "part": "extension", "type": "match", "pattern": "p12", "caption": "Potential cryptographic key bundle", "description": null }, { "part": "extension", "type": "match", "pattern": "asc", "caption": "Potential cryptographic key bundle", "description": null }, { "part": "filename", "type": "match", "pattern": "otr.private_key", "caption": "Pidgin OTR private key", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?(bash_|zsh_|z)?history\\z", "caption": "Shell command history file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?mysql_history\\z", "caption": "MySQL client command history file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?psql_history\\z", "caption": "PostgreSQL client command history file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?pgpass\\z", "caption": "PostgreSQL password file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?irb_history\\z", "caption": "Ruby IRB console history file", "description": null }, { "part": "path", "type": "regex", "pattern": "\\.?purple\\/accounts\\.xml\\z", "caption": "Pidgin chat client account configuration file", "description": null }, { "part": "path", "type": "regex", "pattern": "\\.?xchat2?\\/servlist_?\\.conf\\z", "caption": "Hexchat/XChat IRC client server list configuration file", "description": null }, { "part": "path", "type": "regex", "pattern": "\\.?irssi\\/config\\z", "caption": "Irssi IRC client configuration file", "description": null }, { "part": "path", "type": "regex", "pattern": "\\.?recon-ng\\/keys\\.db\\z", "caption": "Recon-ng web reconnaissance framework API key database", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?dbeaver-data-sources.xml\\z", "caption": "DBeaver SQL database manager configuration file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?muttrc\\z", "caption": "Mutt e-mail client configuration file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?s3cfg\\z", "caption": "S3cmd configuration file", "description": null }, { "part": "path", "type": "regex", "pattern": "\\.?aws/credentials\\z", "caption": "AWS CLI credentials file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?trc\\z", "caption": "T command-line Twitter client configuration file", "description": null }, { "part": "extension", "type": "match", "pattern": "ovpn", "caption": "OpenVPN client configuration file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?gitrobrc\\z", "caption": "Well, this is awkward... Gitrob configuration file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?(bash|zsh)rc\\z", "caption": "Shell configuration file", "description": "Shell configuration files might contain information such as server hostnames, passwords and API keys." }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?(bash_|zsh_)?profile\\z", "caption": "Shell profile configuration file", "description": "Shell configuration files might contain information such as server hostnames, passwords and API keys." }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?(bash_|zsh_)?aliases\\z", "caption": "Shell command alias configuration file", "description": "Shell configuration files might contain information such as server hostnames, passwords and API keys." }, { "part": "filename", "type": "match", "pattern": "secret_token.rb", "caption": "Ruby On Rails secret token configuration file", "description": "If the Rails secret token is known, it can allow for remote code execution. (http://www.exploit-db.com/exploits/27527/)" }, { "part": "filename", "type": "match", "pattern": "omniauth.rb", "caption": "OmniAuth configuration file", "description": "The OmniAuth configuration file might contain client application secrets." }, { "part": "filename", "type": "match", "pattern": "carrierwave.rb", "caption": "Carrierwave configuration file", "description": "Can contain credentials for online storage systems such as Amazon S3 and Google Storage." }, { "part": "filename", "type": "match", "pattern": "schema.rb", "caption": "Ruby On Rails database schema file", "description": "Contains information on the database schema of a Ruby On Rails application." }, { "part": "filename", "type": "match", "pattern": "database.yml", "caption": "Potential Ruby On Rails database configuration file", "description": "Might contain database credentials." }, { "part": "filename", "type": "match", "pattern": "settings.py", "caption": "Django configuration file", "description": "Might contain database credentials, online storage system credentials, secret keys, etc." }, { "part": "filename", "type": "regex", "pattern": "\\A(.*)?config(\\.inc)?\\.php\\z", "caption": "PHP configuration file", "description": "Might contain credentials and keys." }, { "part": "extension", "type": "match", "pattern": "kdb", "caption": "KeePass password manager database file", "description": null }, { "part": "extension", "type": "match", "pattern": "agilekeychain", "caption": "1Password password manager database file", "description": null }, { "part": "extension", "type": "match", "pattern": "keychain", "caption": "Apple Keychain database file", "description": null }, { "part": "extension", "type": "regex", "pattern": "\\Akey(store|ring)\\z", "caption": "GNOME Keyring database file", "description": null }, { "part": "extension", "type": "match", "pattern": "log", "caption": "Log file", "description": "Log files might contain information such as references to secret HTTP endpoints, session IDs, user information, passwords and API keys." }, { "part": "extension", "type": "match", "pattern": "pcap", "caption": "Network traffic capture file", "description": null }, { "part": "extension", "type": "regex", "pattern": "\\Asql(dump)?\\z", "caption": "SQL dump file", "description": null }, { "part": "extension", "type": "match", "pattern": "gnucash", "caption": "GnuCash database file", "description": null }, { "part": "filename", "type": "regex", "pattern": "backup", "caption": "Contains word: backup", "description": null }, { "part": "filename", "type": "regex", "pattern": "dump", "caption": "Contains word: dump", "description": null }, { "part": "filename", "type": "regex", "pattern": "password", "caption": "Contains word: password", "description": null }, { "part": "filename", "type": "regex", "pattern": "credential", "caption": "Contains word: credential", "description": null }, { "part": "filename", "type": "regex", "pattern": "secret", "caption": "Contains word: secret", "description": null }, { "part": "filename", "type": "regex", "pattern": "private.*key", "caption": "Contains words: private, key", "description": null }, { "part": "filename", "type": "match", "pattern": "jenkins.plugins.publish_over_ssh.BapSshPublisherPlugin.xml", "caption": "Jenkins publish over SSH plugin file", "description": null }, { "part": "filename", "type": "match", "pattern": "credentials.xml", "caption": "Potential Jenkins credentials file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?htpasswd\\z", "caption": "Apache htpasswd file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A(\\.|_)?netrc\\z", "caption": "Configuration file for auto-login process", "description": "Might contain username and password." }, { "part": "extension", "type": "match", "pattern": "kwallet", "caption": "KDE Wallet Manager database file", "description": null }, { "part": "filename", "type": "match", "pattern": "LocalSettings.php", "caption": "Potential MediaWiki configuration file", "description": null }, { "part": "extension", "type": "match", "pattern": "tblk", "caption": "Tunnelblick VPN configuration file", "description": null }, { "part": "path", "type": "regex", "pattern": "\\.?gem/credentials\\z", "caption": "Rubygems credentials file", "description": "Might contain API key for a rubygems.org account." }, { "part": "filename", "type": "regex", "pattern": "\\A*\\.pubxml(\\.user)?\\z", "caption": "Potential MSBuild publish profile", "description": null }, { "part": "filename", "type": "match", "pattern": "Favorites.plist", "caption": "Sequel Pro MySQL database manager bookmark file", "description": null }, { "part": "filename", "type": "match", "pattern": "configuration.user.xpl", "caption": "Little Snitch firewall configuration file", "description": "Contains traffic rules for applications" }, { "part": "extension", "type": "match", "pattern": "dayone", "caption": "Day One journal file", "description": null }, { "part": "filename", "type": "match", "pattern": "journal.txt", "caption": "Potential jrnl journal file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?tugboat\\z", "caption": "Tugboat DigitalOcean management tool configuration", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?git-credentials\\z", "caption": "git-credential-store helper credentials file", "description": null }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?gitconfig\\z", "caption": "Git configuration file", "description": null }, { "part": "filename", "type": "match", "pattern": "knife.rb", "caption": "Chef Knife configuration file", "description": "Might contain references to Chef servers" }, { "part": "path", "type": "regex", "pattern": "\\.?chef/(.*)\\.pem\\z", "caption": "Chef private key", "description": "Can be used to authenticate against Chef servers" }, { "part": "filename", "type": "match", "pattern": "proftpdpasswd", "caption": "cPanel backup ProFTPd credentials file", "description": "Contains usernames and password hashes for FTP accounts" }, { "part": "filename", "type": "match", "pattern": "robomongo.json", "caption": "Robomongo MongoDB manager configuration file", "description": "Might contain credentials for MongoDB databases" }, { "part": "filename", "type": "match", "pattern": "filezilla.xml", "caption": "FileZilla FTP configuration file", "description": "Might contain credentials for FTP servers" }, { "part": "filename", "type": "match", "pattern": "recentservers.xml", "caption": "FileZilla FTP recent servers file", "description": "Might contain credentials for FTP servers" }, { "part": "filename", "type": "match", "pattern": "ventrilo_srv.ini", "caption": "Ventrilo server configuration file", "description": "Might contain passwords" }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?dockercfg\\z", "caption": "Docker configuration file", "description": "Might contain credentials for public or private Docker registries" }, { "part": "filename", "type": "regex", "pattern": "\\A\\.?npmrc\\z", "caption": "NPM configuration file", "description": "Might contain credentials for NPM registries" } ] filename:.npmrc _auth filename:.dockercfg auth extension:pem private extension:ppk private filename:id_rsa or filename:id_dsa extension:sql mysql dump extension:sql mysql dump password filename:credentials aws_access_key_id filename:.s3cfg filename:wp-config.php filename:.htpasswd filename:.env DB_USERNAME NOT homestead filename:.env MAIL_HOST=smtp.gmail.com filename:.git-credentials PT_TOKEN language:bash filename:.bashrc password filename:.bashrc mailchimp filename:.bash_profile aws rds.amazonaws.com password extension:json api.forecast.io extension:json mongolab.com extension:yaml mongolab.com jsforce extension:js conn.login SF_USERNAME "salesforce" filename:.tugboat NOT "_tugboat" HEROKU_API_KEY language:shell HEROKU_API_KEY language:json filename:.netrc password filename:_netrc password filename:hub oauth_token filename:robomongo.json filename:filezilla.xml Pass filename:recentservers.xml Pass filename:config.json auths filename:idea14.key filename:config irc_pass filename:connections.xml filename:express.conf path:.openshift filename:.pgpass filename:proftpdpasswd filename:ventrilo_srv.ini [WFClient] Password= extension:ica filename:server.cfg rcon password JEKYLL_GITHUB_TOKEN filename:.bash_history filename:.cshrc filename:.history filename:.sh_history filename:sshd_config filename:dhcpd.conf