CanReadCredential
Source can obtain a usable credential (instance metadata token, env var, key file).
Identity, Compute
── CanReadCredential ──▸
Credential, AccessKey, Token, SSHKey
Source types
IdentityComputeTarget types
States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | both |
|---|
Rules that emit CanReadCredential 19
awsderived
awsderived
redshift:GetClusterCredentials generates a temporary database username/password, enabling JDBC/ODBC authentication to the cluster as the requested DB user.
awsderived
registries/listCredentials/action allows a principal to retrieve the admin account's long-lived passwords.
azurederived
tokens/listPasswords/action returns long-lived passwords for a repository-scoped token - principal can retrieve static credential valid for the actions in the token's scope map.
azurederived
listKeys/action returns ADLS Gen2 account keys, bypassing all RBAC and ACLs.
azurederived
generateUserDelegationKey/action allows minting user-delegation SAS tokens (Token credential type) for external distribution.
azurederived
listClusterAdminCredential returns a static cluster-admin kubeconfig that bypasses AAD, giving unconditional cluster-admin access to the cluster.
azurederived
listClusterUserCredential returns a user-level kubeconfig (AAD-token-gated, lower privilege), providing authenticated access to the cluster API server.
azurederived
Retrieve authentication keys for linked services via listAuthKeys/action, directly accessing the plaintext credential without parsing typeProperties.
azurederived
listCredentials/action permission on ANF account grants CanReadCredential on the AD join AccessKey.
azurederived
A principal with listKeys/action permission can retrieve the Redis access key via ARM, gaining read access to the credential.
azurederived
listKeys/action returns storage account keys, bypassing all Azure RBAC and network controls for all sub-services (when SharedKey auth is enabled).
azurederived
listAccountSas/action generates a pre-formed account-level SAS token, providing scoped but key-equivalent data-plane access.
azurederived
generateUserDelegationKey/action returns user-delegation key material (not a pre-formed SAS token) - the caller can sign arbitrary user-delegation SAS URLs offline within the key's validity window.
azurederived
cloudsql.sslCerts.create returns a client SSL certificate private key (one-time, in the API response), which serves as a database authentication credential.
gcpderived
cloudfunctions.functions.sourceCodeGet returns the deployed source archive, which may embed hardcoded credentials.
gcpderived
cloudsql.sslCerts.create returns a client SSL certificate private key (one-time in the API response), which serves as a database authentication credential.
gcpexplicit
gcpexplicit
Exposure sites that emit CanReadCredential 22
batch.projects.locations.jobs.get.taskGroups[].taskSpec.runnables[].container.password
gcpcritical
cloudbuild.projects.locations.bitbucketServerConfigs.get.apiKey
gcpcritical
Apache Airflow REST API / metadata database.Connection passwords/extras and Variable values
gcpcritical
eventarc.projects.locations.channels.get.activationToken
gcpcritical
container.projects.zones.clusters.get.masterAuth.{username,password,clientCertificate,clientKey}
gcpcritical
iap.projects.brands.identityAwareProxyClients.get.secret
gcpcritical
redis.projects.locations.instances.getAuthString.authString
gcpcritical
redis.projects.locations.clusters.tokenAuthUsers.authTokens.get.token
gcpcritical
redis.projects.locations.aclPolicies.get.rules[].{username,rule}
gcpcritical
monitoring.projects.uptimeCheckConfigs.get.httpCheck.authInfo.{username,password}
gcpcritical
networkconnectivity.projects.locations.serviceConnectionTokens.get.token
gcpcritical
networkconnectivity.projects.locations.serviceConnectionMaps.get.token
gcpcritical
aiplatform.projects.locations.ragCorpora.get.vectorDbConfig.apiAuth.apiKeyConfig.apiKeyString
gcpcritical
compute.vpnTunnels.get.sharedSecret
gcpcritical
compute.publicAdvertisedPrefixes.get.sharedSecret
gcpcritical
Microsoft.Automation/automationAccounts/credentials get response.properties.{userName,password}
azurecritical
Azure DevOps service endpoint.authorization.parameters.*
azurecritical
Azure Pipelines secure file bytes
azurecritical
Key Vault certificate backing Secret.value
azurecritical
Microsoft.MachineLearningServices/workspaces/datastores/listSecrets response.{secrets,credentials}
azurecritical
Microsoft.MachineLearningServices/workspaces/connections/listSecrets response.credentials
azurecritical
Microsoft.NotificationHubs/namespaces/notificationHubs/pnsCredentials response.properties.{apnsCredential,gcmCredential,admCredential,baiduCredential,wnsCredential}
azurecritical