aws-waf-byte-match-search-string

Byte-match search strings are base64-encoded customer content and can accidentally contain real credentials used to identify traffic.

awshigh service: aws:waf emits ContainsSecret

Where it sits

locationGetWebACL.WebACL.Rules[].Statement.*.ByteMatchStatement.SearchString
location kindconfig_field
data kindscredential password api_key bearer_token sensitive_data
emits edgeContainsSecret
serviceWAF/Shield (aws:waf)

Collection recipe

access moderead_api
operationGetWebACL
response pathWebACL.Rules[].Statement.*.ByteMatchStatement.SearchString
encodingbase64
params{"Id": "\u003cweb-acl-id\u003e", "Name": "\u003cweb-acl-name\u003e", "Scope": "\u003cREGIONAL|CLOUDFRONT\u003e"}

Required permissions

wafv2:GetWebACL

References

move · open · esc close