azure-storage-file-content-metadata

Azure Files may store configuration files, private keys, backups, and arbitrary sensitive records.

azurecritical service: azure:storage emits CanReadData

Where it sits

locationAzure File.{content,metadata}
location kinddata_record
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeCanReadData
serviceStorage Accounts (Blob/File/Queue/Table) (azure:storage)

Collection recipe

access modedata_plane
operationFile - Get
response path$value and response headers
encodingbinary
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Storage/storageAccounts/fileServices/fileshares/files/read

References

move · open · esc close