
Scanner di segreti multi-fonte che rileva chiavi API, password e PII attraverso repository Git, bucket S3, filesystem, Confluence, JIRA, Slack e Google Docs utilizzando regex e analisi di entropia.
Rusty Hog è uno scanner di segreti sviluppato in Rust per le prestazioni, basato su TruffleHog che è scritto in Python. Rusty Hog fornisce i seguenti binari:
Questo progetto fornisce una serie di scanner che utilizzano espressioni regolari per cercare di rilevare la presenza di informazioni sensibili, come chiavi API, password e informazioni personali. Include un insieme di espressioni regolari predefinite, ma accetta anche un oggetto JSON contenente le tue espressioni regolari personalizzate.
Scarica e decomprimi l'ultimo ZIP nella scheda dei rilasci. Quindi, esegui ogni binario con -h per vedere l'utilizzo.```shell script
wget https://github.com/newrelic/rusty-hog/releases/download/v1.0.11/rustyhogs-darwin-choctaw_hog-1.0.11.zip
unzip rustyhogs-darwin-choctaw_hog-1.0.11.zip
darwin_releases/choctaw_hog -h
## Come eseguire utilizzando DockerHub
Le immagini Docker di Rusty Hog sono disponibili sulla pagina DockerHub personale dell'autore [qui](https://hub.docker.com/u/wetfeet2000)
Per ogni Hog e per ogni rilascio viene creata un'immagine Docker. Quindi per utilizzare choctaw_hog eseguirai i seguenti comandi:```shell script
docker pull wetfeet2000/choctaw_hog:1.0.10
docker run -it --rm wetfeet2000/choctaw_hog:1.0.10 --help
cargo build --release. I binari si trovano in target/release.cargo doc --no-deps --open.cargo test.## Come compilare su Windows
Dovrai compilare i binari statici di OpenSSL e dire a Rust/Cargo dove trovarli:```
mkdir \Tools
cd \Tools
git clone https://github.com/Microsoft/vcpkg.git
cd vcpkg
.\bootstrap-vcpkg.bat
.\vcpkg.exe install openssl:x64-windows-static
$env:OPENSSL_DIR = 'C:\Tools\vcpkg\installed\x64-windows-static'
$env:OPENSSL_STATIC = 'Yes'
[System.Environment]::SetEnvironmentVariable('OPENSSL_DIR', $env:OPENSSL_DIR, [System.EnvironmentVariableTarget]::User)
[System.Environment]::SetEnvironmentVariable('OPENSSL_STATIC', $env:OPENSSL_STATIC, [System.EnvironmentVariableTarget]::User)
Ora puoi seguire le istruzioni principali di build elencate sopra.
Usa Homebrew per ottenere le dipendenze:``` brew install rpm2cpio FiloSottile/musl-cross/musl-cross
Quindi esegui `./build_lambda_macos.sh`.
Il build script compilerà contro OpenSSL 3.0.12. Usa `export OPENSSL_BUILD_VER=3.0.12` per sovrascrivere.
Il build script compilerà contro gli header del kernel Amazon Linux forniti dal loro RPM; `export AMAZON_KERNEL_HEADERS_RPM_URL=...` per sovrascrivere da dove viene scaricato l'RPM. (Non c'è nulla che impedisca l'uso dell'RPM linux-headers di una distribuzione diversa, abbiamo solo bisogno dei linux-headers per compilare openssl per Linux)
Il build script creerà una directory build-deps nella root del tuo sorgente corrente. Puoi eliminare in sicurezza questa directory con `rm -rf`, ma verrà ricreata al successivo avvio del build script. Effettuerà anche vari controlli di consistenza per assicurarsi che il build funzioni e, in caso di fallimento, potrebbe chiederti di eseguire `rm -rf` su quella directory per riprovare.
### Linux
Assicurati che `cross` sia installato (`cargo install cross`), poi esegui semplicemente `./build_lambda.sh`.
# Comandi
## Utilizzo di Anakamali Hog (GDoc Scanner)```
USAGE:
ankamali_hog [FLAGS] [OPTIONS] <GDRIVEID>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--oauthsecret Path to an OAuth secret file (JSON) ./clientsecret.json by default
--oauthtoken Path to an OAuth token storage file ./temp_token by default
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-a, --allowlist <ALLOWLIST> Sets a custom allowlist JSON file
--default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default)
-o, --outputfile <OUTPUT> Sets the path to write the scanner results to (stdout by default)
--regex <REGEX> Sets a custom regex JSON file
ARGS:
<GDRIVEID> The ID of the Google drive file you want to scan
USAGE: berkshire_hog [FLAGS] [OPTIONS]
FLAGS: --caseinsensitive Sets the case insensitive flag for all regexes --entropy Enables entropy scanning --prettyprint Outputs the JSON in human readable format -r, --recursive Recursively scans files under the prefix -v, --verbose Sets the level of debugging information -h, --help Prints help information -V, --version Prints version information