ContainsSecret

Resource stores secret material (drives ExposesCredential).

data CREDENTIAL nature: explicit walkable weight 1
Storage, Data, Compute, Messaging  ── ContainsSecret ──▸  Secret, Credential

Source types

StorageDataComputeMessaging

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit ContainsSecret 35

CodeBuild project env vars of type SECRETS_MANAGER or PARAMETER_STORE reference secret material injected into every build's environment.
awsderived
An EventBridge Connection with API_KEY, OAUTH_CLIENT_CREDENTIALS, or BASIC auth contains a stored credential used to authenticate API destination calls.
awsderived
An SNS topic without a DataProtectionPolicy may carry messages embedding secrets; any subscriber can read them (POTENTIAL - content heuristic, not confirmed).
awsderived
A Step Functions activity task state embeds the current execution data context as the task payload returned by GetActivityTask; if upstream states processed sensitive data, the payload may contain secrets.
awsderived
A snapshot of an OS-type disk inherits the OS-disk ContainsSecret classification when the source disk is identified.
azurederived
A Service Bus queue with active entity-level SAS authorization rules embeds queue-scoped connection-string credentials usable at data-plane without Entra RBAC.
azurederived
A Service Bus topic with active entity-level SAS authorization rules embeds topic-scoped connection-string credentials usable at data-plane without Entra RBAC.
azurederived
A Service Bus namespace with active SAS authorization rules embeds connection-string credentials usable at data-plane without Entra RBAC.
azurederived
A Cloud Scheduler job's HTTP body (httpTarget.body) or Pub/Sub payload (pubsubTarget.data) may embed credentials. Any principal with cloudscheduler.jobs.get / fullView can read the job definition and recover the embedded credential.
gcpderived
Function env vars / mounted Secret Manager bindings carry connection strings / API keys.
gcpderived
A Cloud Tasks task body (httpRequest.body, base64-encoded) contains credential material (API keys, passwords, SA key JSON, connection strings) readable by any principal with cloudtasks.tasks.fullView on the queue.
gcpderived
A workflow execution's argument payload may carry secrets passed by the caller; visible in execution metadata to anyone with executions.get.
gcpderived
Explicit extraction: pipeline definition contains plaintext credential material in activity fields.
awsexplicit
DocumentDB cluster stores its master MongoDB user password in a Secrets Manager secret when ManageMasterUserPassword is enabled.
awsexplicit
A snapshot of a volume from an instance with an instance profile (IAM role) may contain credentials, SSH keys, or other secrets on the disk. This edge is ONLY emitted when forensic evidence confirms credential material on the disk image, not from structural probability alone. The preconditions are: (1) the volume was attached to an instance with an ExecutesAs role, (2) a snapshot exists of that volume, and (3) forensic scanning or manual inspection has detected credential patterns on the disk.
awsexplicit
OpsWorks App secure environment variables are credentials accessible to all deployment code on the stack.
awsexplicit
An OS-type managed disk (Windows or Linux) is heuristically classified as containing credential material: SAM/NTDS hive, /etc/shadow, SSH private keys, or application credential files.
azureexplicit
A Cloud SQL instance may store application secrets (API keys, SA keys, connection strings, tokens) in its databases based on schema/table metadata heuristics.
gcpexplicit
A Firestore database contains collections or document field names whose names indicate credential material (API keys, SA keys, OAuth tokens, database passwords).
gcpexplicit

Exposure sites that emit ContainsSecret 560

GetArchiveRule.archiveRule.filter.<criterion>.contains / eq / neq
awsmedium
ListTagsForResource.tags.<value>
awsmedium
GetPrimaryEmail.PrimaryEmail
awshigh
GetContactInformation.ContactInformation
awshigh
GetAlternateContact.AlternateContact
awshigh
DescribeCertificate.Certificate.DomainName / Subject / SubjectAlternativeNames
awsmedium
ListTagsForCertificate.Tags[].Value
awsmedium
GetCertificate.Certificate / CertificateChain
awsmedium
GetCertificateAuthorityCsr.Csr
awsmedium
ListTags.Tags[].Value
awsmedium
GetApp.app.tags.<value>
awsmedium
CloudWatch Logs API Gateway execution/access log event.message
awscritical
awsmedium
DescribeFlow.sourceFlowConfig.connectorProfileName / sourceConnectorProperties / destinationFlowConfigList[].destinationConnectorProperties / tasks[].taskProperties
awshigh
ListTagsForResource.tags.<value>
awsmedium
DescribeRoute.route.spec.httpRoute.match.headers[].match.{exact,prefix,regex,suffix}
awshigh
ListTagsForResource.tags[].value
awsmedium
ListTagsForResource.Tags[].Value
awsmedium
GetQueryExecution.QueryExecution.Query
awshigh
GetNamedQuery.NamedQuery.QueryString
awshigh
GetPreparedStatement.PreparedStatement.QueryStatement
awshigh
ListTagsForResource.Tags[].Value
awsmedium
DescribeAutoScalingGroups.AutoScalingGroups[].Tags[].Value
awsmedium
GetRecoveryPointRestoreMetadata.RestoreMetadata.<value>
awshigh
GetBackupVaultAccessPolicy.Policy
awsmedium
awsmedium
ListTagsForResource.tags.<value>
awsmedium
ListTagsForResource.Tags[].Value
awsmedium
Configured S3/CloudWatch Bedrock model invocation log record
awscritical
ListTagsForResource.tags[].value
awsmedium
DescribeStackEvents.StackEvents[].ResourceStatusReason
awshigh
DescribeStacks.Stacks[].Tags[].Value
awsmedium
S3 CloudFront standard or real-time log record
awshigh
ListTagsForResource.Tags.Items[].Value
awsmedium
awsmedium
StartQuery request.QueryStatement
awshigh
ListTags.ResourceTagList[].TagsList[].Value
awsmedium
logs:DescribeQueries.queries[].queryString
awshigh
DescribeAlarms.MetricAlarms[].AlarmDescription / CompositeAlarms[].AlarmDescription
awsmedium
ListMetrics.Metrics[].Dimensions[].Value
awshigh

All 560 sites

move · open · esc close