
複数のソースからのシークレットスキャナー。Gitリポジトリ、S3バケット、ファイルシステム、Confluence、JIRA、Slack、Google Docs全体で、正規表現とエントロピー分析を使用してAPIキー、パスワード、PIIを検出します。
Rusty Hogは、パフォーマンスのためにRustで構築されたシークレットスキャナーであり、Pythonで書かれたTruffleHogをベースにしています。Rusty Hogは以下のバイナリを提供します:
このプロジェクトは、正規表現を使用してAPIキー、パスワード、個人情報などの機密情報の存在を検出するスキャナーのセットを提供します。デフォルトで正規表現のセットを含んでいますが、カスタム正規表現を含むJSONオブジェクトも受け付けます。
リリースタブから最新のZIPをダウンロードして解凍します。その後、各バイナリを-hオプション付きで実行して使用方法を確認してください。```shell script
wget https://github.com/newrelic/rusty-hog/releases/download/v1.0.11/rustyhogs-darwin-choctaw_hog-1.0.11.zip
unzip rustyhogs-darwin-choctaw_hog-1.0.11.zip
darwin_releases/choctaw_hog -h
## DockerHub を使用した実行方法
Rusty Hog の Docker イメージは、作者の個人 DockerHub ページで見つけることができます [here](https://hub.docker.com/u/wetfeet2000)
各 Hog および各リリースに対して Docker イメージがビルドされています。したがって、choctaw_hog を使用するには、次のコマンドを実行します:```shell script
docker pull wetfeet2000/choctaw_hog:1.0.10
docker run -it --rm wetfeet2000/choctaw_hog:1.0.10 --help
cargo build --releaseを実行してください。バイナリはtarget/releaseに格納されます。cargo doc --no-deps --openを実行してください。cargo testを実行してください。## Windows上でのビルド方法
静的OpenSSLバイナリをコンパイルし、Rust/Cargoにその場所を教える必要があります:```
mkdir \Tools
cd \Tools
git clone https://github.com/Microsoft/vcpkg.git
cd vcpkg
.\bootstrap-vcpkg.bat
.\vcpkg.exe install openssl:x64-windows-static
$env:OPENSSL_DIR = 'C:\Tools\vcpkg\installed\x64-windows-static'
$env:OPENSSL_STATIC = 'Yes'
[System.Environment]::SetEnvironmentVariable('OPENSSL_DIR', $env:OPENSSL_DIR, [System.EnvironmentVariableTarget]::User)
[System.Environment]::SetEnvironmentVariable('OPENSSL_STATIC', $env:OPENSSL_STATIC, [System.EnvironmentVariableTarget]::User)
これで、上記のメインのビルド手順に従うことができます。
依存関係を取得するにはHomebrewを使用します:``` brew install rpm2cpio FiloSottile/musl-cross/musl-cross
その後、`./build_lambda_macos.sh` を実行してください。
ビルドスクリプトは OpenSSL 3.0.12 に対してビルドします。上書きするには `export OPENSSL_BUILD_VER=3.0.12` を使用してください。
ビルドスクリプトは、Amazon Linux の RPM が提供するカーネルヘッダに対してビルドします。RPM のダウンロード元を上書きするには `export AMAZON_KERNEL_HEADERS_RPM_URL=...` を使用してください。(別のディストリビューションの linux-headers RPM を使用することも可能です。Linux 向けに openssl をビルドするには linux-headers が必要なだけです。)
ビルドスクリプトは、現在のソースルートに build-deps ディレクトリを作成します。このディレクトリは `rm -rf` で安全に削除できますが、次回のビルドスクリプト実行時に再作成されます。また、ビルドが正常に動作することを確認するための各種整合性チェックを実行し、それらが失敗した場合は、再試行のためにそのディレクトリを `rm -rf` するよう要求される可能性があります。
### Linux
`cross` がインストールされていることを確認し (`cargo install cross`)、その後 `./build_lambda.sh` を実行してください。
# コマンド
## Anakamali Hog (GDoc Scanner) の使用方法```
USAGE:
ankamali_hog [FLAGS] [OPTIONS] <GDRIVEID>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--oauthsecret Path to an OAuth secret file (JSON) ./clientsecret.json by default
--oauthtoken Path to an OAuth token storage file ./temp_token by default
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-a, --allowlist <ALLOWLIST> Sets a custom allowlist JSON file
--default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default)
-o, --outputfile <OUTPUT> Sets the path to write the scanner results to (stdout by default)
--regex <REGEX> Sets a custom regex JSON file
ARGS:
<GDRIVEID> The ID of the Google drive file you want to scan
USAGE: berkshire_hog [FLAGS] [OPTIONS]
FLAGS: --caseinsensitive Sets the case insensitive flag for all regexes --entropy Enables entropy scanning --prettyprint Outputs the JSON in human readable format -r, --recursive Recursively scans files under the prefix -v, --verbose Sets the level of debugging information -h, --help Prints help information -V, --version Prints version information
OPTIONS: -a, --allowlist Sets a custom allowlist JSON file --default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default) -o, --outputfile Sets the path to write the scanner results to (stdout by default)
--profile <PROFILE> When using a configuration file, enables a non-default profile
--regex <REGEX> Sets a custom regex JSON file
ARGS: The location of a S3 bucket and optional prefix or filename to scan. This must be written in the form s3://mybucket[/prefix_or_file] Sets the region of the S3 bucket to scan
## Berkshire Hog (S3 Scanner - Lambda) の使用方法
Berkshire Hog は現在、Lambda 関数として使用するように設計されています。以下が基本的なデータフローです:
<pre>
┌───────────┐ ┌───────┐ ┌────────────────┐ ┌────────────┐
│ S3 bucket │ ┌────────┐ │ │ │ Berkshire Hog │ │ S3 bucket │
│ (input) ─┼─┤S3 event├──▶│ SQS │────▶│ (Lambda) │────▶│ (output) │
│ │ └────────┘ │ │ │ │ │ │
└───────────┘ └───────┘ └────────────────┘ └────────────┘
</pre>