Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Enhancement] Use this to add/vote for new data sources/scans #15

Open
emtunc opened this issue Jan 10, 2019 · 8 comments
Open

[Enhancement] Use this to add/vote for new data sources/scans #15

emtunc opened this issue Jan 10, 2019 · 8 comments
Labels
enhancement New feature or request

Comments

@emtunc
Copy link
Owner

emtunc commented Jan 10, 2019

Let's use this ticket to add and vote on new scan types and data sources that can be added to the tool.

Most voted comments are prioritised first.

@emtunc emtunc added the enhancement New feature or request label Jan 10, 2019
@emtunc emtunc pinned this issue Jan 10, 2019
@emtunc
Copy link
Owner Author

emtunc commented Jan 10, 2019

Slack tokens - look for Slack tokens that may have been leaked within a Slack Workspace. This could allow an attacker to pivot to a more privileged user or someone whose account can be used to phish other users for example.

@emtunc
Copy link
Owner Author

emtunc commented Jan 10, 2019

Github tokens - unless there's a unique way to differentiate these from other 40 character strings then this might introduce some false positives. Worth a try though.

@emtunc
Copy link
Owner Author

emtunc commented Jan 10, 2019

Azure secret keys

@emtunc
Copy link
Owner Author

emtunc commented Jan 10, 2019

Google Cloud Platform secret keys

@emtunc
Copy link
Owner Author

emtunc commented Jan 10, 2019

Password and/or tokens in URLs

@ghost
Copy link

ghost commented Jan 10, 2019

Pull the content of pinned items in each channel. Often times these are solutions for recurring problems within a team ("what was the GOCD login?", "Where are the Chef credentials?")

@ghost
Copy link

ghost commented Jan 11, 2019

API Reference for listing pinned items: https://api.slack.com/methods/pins.list

May also require listing channels (https://api.slack.com/methods/channels.list) as the channel with the pinned items must be specified

@emtunc
Copy link
Owner Author

emtunc commented Jan 14, 2019

API Reference for listing pinned items: https://api.slack.com/methods/pins.list

May also require listing channels (https://api.slack.com/methods/channels.list) as the channel with the pinned items must be specified

This has been implemented in #4c28daf

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
1 participant