azure-automation-runbook-source

Runbook source code can hard-code credentials or retrieve and print protected assets.

azurecritical service: azure:automation emits ContainsSecret

Where it sits

locationMicrosoft.Automation/automationAccounts/runbooks/content
location kindcode_artifact
data kindscredential password api_key access_key secret_key oauth_token connection_string source_code_secret
emits edgeContainsSecret
serviceAzure Automation (azure:automation)

Collection recipe

access moderead_api
operationRunbook - Get Content
response path$value
encodingstring
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Automation/automationAccounts/runbooks/content/read

References

move · open · esc close