
여러 소스에서 비밀 키를 스캔하는 도구로, API 키, 비밀번호, PII를 Git 리포지토리, S3 버킷, 파일시스템, Confluence, JIRA, Slack, Google Docs에서 정규식 및 엔트로피 분석을 통해 탐지합니다.
Rusty Hog는 Rust로 구축된 성능 중심의 비밀 스캐너이며, Python으로 작성된 TruffleHog를 기반으로 합니다. Rusty Hog는 다음과 같은 바이너리를 제공합니다:
이 프로젝트는 API 키, 비밀번호, 개인 정보와 같은 민감한 정보의 존재를 감지하기 위해 정규 표현식을 사용하는 스캐너 세트를 제공합니다. 기본적으로 정규 표현식 세트가 포함되어 있지만, 사용자 정의 정규 표현식을 포함한 JSON 객체도 허용합니다.
릴리스 탭에서 최신 ZIP을 다운로드하여 압축을 풉니다. 그런 다음 각 바이너리를 -h와 함께 실행하여 사용법을 확인합니다.```shell script
wget https://github.com/newrelic/rusty-hog/releases/download/v1.0.11/rustyhogs-darwin-choctaw_hog-1.0.11.zip
unzip rustyhogs-darwin-choctaw_hog-1.0.11.zip
darwin_releases/choctaw_hog -h
## DockerHub를 사용하여 실행하는 방법
Rusty Hog Docker 이미지는 작성자의 개인 DockerHub 페이지 [여기](https://hub.docker.com/u/wetfeet2000)에서 찾을 수 있습니다.
각 Hog 및 각 릴리스에 대해 Docker 이미지가 빌드됩니다. 따라서 choctaw_hog를 사용하려면 다음 명령을 실행하면 됩니다:```shell script
docker pull wetfeet2000/choctaw_hog:1.0.10
docker run -it --rm wetfeet2000/choctaw_hog:1.0.10 --help
cargo build --release를 실행하세요. 바이너리는 target/release에 위치합니다.cargo doc --no-deps --open을 실행하세요.cargo test를 실행하세요.## Windows에서 빌드하는 방법
정적 OpenSSL 바이너리를 컴파일하고 Rust/Cargo에 해당 위치를 알려주어야 합니다:```
mkdir \Tools
cd \Tools
git clone https://github.com/Microsoft/vcpkg.git
cd vcpkg
.\bootstrap-vcpkg.bat
.\vcpkg.exe install openssl:x64-windows-static
$env:OPENSSL_DIR = 'C:\Tools\vcpkg\installed\x64-windows-static'
$env:OPENSSL_STATIC = 'Yes'
[System.Environment]::SetEnvironmentVariable('OPENSSL_DIR', $env:OPENSSL_DIR, [System.EnvironmentVariableTarget]::User)
[System.Environment]::SetEnvironmentVariable('OPENSSL_STATIC', $env:OPENSSL_STATIC, [System.EnvironmentVariableTarget]::User)
이제 위에 나열된 주요 빌드 지침을 따를 수 있습니다.
의존성을 얻으려면 Homebrew를 사용하세요:``` brew install rpm2cpio FiloSottile/musl-cross/musl-cross
그런 다음 `./build_lambda_macos.sh`를 실행하세요.
빌드 스크립트는 OpenSSL 3.0.12에 대해 빌드됩니다. 재정의하려면 `export OPENSSL_BUILD_VER=3.0.12`를 사용하세요.
빌드 스크립트는 Amazon Linux 커널 헤더(Amazon Linux의 RPM에서 제공)에 대해 빌드됩니다. `export AMAZON_KERNEL_HEADERS_RPM_URL=...`로 RPM 다운로드 위치를 재정의할 수 있습니다. (다른 배포판의 linux-headers RPM을 사용하는 데 아무런 제약이 없습니다. Linux용 openssl을 빌드하려면 linux-headers만 필요합니다.)
빌드 스크립트는 현재 소스 루트에 build-deps 디렉토리를 생성합니다. 이 디렉토리는 `rm -rf`로 안전하게 삭제할 수 있지만, 다음 빌드 스크립트 실행 시 다시 생성됩니다. 또한 빌드가 정상 작동하는지 확인하기 위해 다양한 일관성 검사를 수행하며, 검사에 실패하면 다시 시도하기 위해 해당 디렉토리를 `rm -rf`하라고 요청할 수 있습니다.
### Linux
`cross`가 설치되어 있는지 확인한 후(`cargo install cross`), `./build_lambda.sh`를 실행하면 됩니다.
# 명령
## Anakamali Hog (GDoc Scanner) 사용법```
USAGE:
ankamali_hog [FLAGS] [OPTIONS] <GDRIVEID>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--oauthsecret Path to an OAuth secret file (JSON) ./clientsecret.json by default
--oauthtoken Path to an OAuth token storage file ./temp_token by default
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-a, --allowlist <ALLOWLIST> Sets a custom allowlist JSON file
--default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default)
-o, --outputfile <OUTPUT> Sets the path to write the scanner results to (stdout by default)
--regex <REGEX> Sets a custom regex JSON file
ARGS:
<GDRIVEID> The ID of the Google drive file you want to scan
USAGE: berkshire_hog [FLAGS] [OPTIONS]
FLAGS: --caseinsensitive Sets the case insensitive flag for all regexes --entropy Enables entropy scanning --prettyprint Outputs the JSON in human readable format -r, --recursive Recursively scans files under the prefix -v, --verbose Sets the level of debugging information -h, --help Prints help information -V, --version Prints version information
OPTIONS: -a, --allowlist Sets a custom allowlist JSON file --default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default) -o, --outputfile Sets the path to write the scanner results to (stdout by default)
--profile <PROFILE> When using a configuration file, enables a non-default profile
--regex <REGEX> Sets a custom regex JSON file
ARGS: The location of a S3 bucket and optional prefix or filename to scan. This must be written in the form s3://mybucket[/prefix_or_file] Sets the region of the S3 bucket to scan
## Berkshire Hog (S3 Scanner - Lambda) 사용법
Berkshire Hog는 현재 Lambda 함수로 사용하도록 설계되었습니다. 기본 데이터 흐름은 다음과 같습니다:
<pre>
┌───────────┐ ┌───────┐ ┌────────────────┐ ┌────────────┐
│ S3 bucket │ ┌────────┐ │ │ │ Berkshire Hog │ │ S3 bucket │
│ (input) ─┼─┤S3 event├──▶│ SQS │────▶│ (Lambda) │────▶│ (output) │
│ │ └────────┘ │ │ │ │ │ │
└───────────┘ └───────┘ └────────────────┘ └────────────┘
</pre>
이 방식으로 Berkshire Hog를 실행하려면 다음을 설정하십시오:
1) 입력 버킷이 PUSH/PUT 이벤트마다 SQS에 "이벤트"를 보내도록 구성하십시오.
2) IAM 권한을 포함하여 S3의 이벤트를 수락하도록 SQS 주제를 설정하십시오.
3) SQS 및 S3에 대한 IAM 액세스 권한으로 Berkshire Hog를 실행하십시오.