aws-macie-allow-list-regex-s3-words

Allow-list regexes or word-list objects may contain real identifiers or secrets copied to suppress findings.

awshigh service: aws:macie emits ContainsSecret

Where it sits

locationGetAllowList.Criteria.Regex / Criteria.S3WordsList.ObjectKey -> S3 object
location kindconfig_field
data kindscredential password api_key sensitive_data
emits edgeContainsSecret
serviceMacie (aws:macie)

Collection recipe

access modeindirect_destination
operationGetAllowList then optional s3:GetObject
response pathCriteria.Regex / S3WordsList.ObjectKey -> Body
encodingstring
params{"Id": "\u003callow-list-id\u003e"}

Required permissions

macie2:GetAllowList
s3:GetObject

References

move · open · esc close