azure-disks-mounted-filesystem-content

A mounted or exported disk can contain operating-system credentials, configuration, source code, and customer files. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:disks emits CanReadData

Where it sits

locationGuest-mounted managed disk filesystem blocks/files
location kinddata_record
data kindscredential password api_key access_key secret_key oauth_token connection_string private_key source_code_secret sensitive_data pii customer_data
emits edgeCanReadData
serviceManaged Disks (azure:disks)

Collection recipe

access modedata_plane
operationDisk data access through attached VM or SAS URL
response path$value
encodingbinary
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close