azure-storage-blob-content-metadata

Blob bodies, metadata, and index tags can contain arbitrary credentials or customer data.

azurecritical service: azure:storage emits CanReadData

Where it sits

locationBlob.{content,metadata,tags}
location kinddata_record
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeCanReadData
serviceStorage Accounts (Blob/File/Queue/Table) (azure:storage)

Collection recipe

access modedata_plane
operationBlob - Get
response path$value and response headers
encodingbinary
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read

References

move · open · esc close