Rusty Hog 是一个用 Rust 构建的高性能秘密扫描器,基于用 Python 编写的 TruffleHog。Rusty Hog 提供以下二进制文件:
本项目提供一组扫描器,使用正则表达式来尝试检测敏感信息的存在,例如 API 密钥、密码和个人信息。它默认包含一组正则表达式,但也接受包含自定义正则表达式的 JSON 对象。
下载并解压发布标签页上的 最新 ZIP。然后,使用 -h 运行每个二进制文件以查看使用方法。```shell script
wget https://github.com/newrelic/rusty-hog/releases/download/v1.0.11/rustyhogs-darwin-choctaw_hog-1.0.11.zip
unzip rustyhogs-darwin-choctaw_hog-1.0.11.zip
darwin_releases/choctaw_hog -h
## 如何使用 DockerHub 运行
Rusty Hog Docker 镜像可以在作者的个人 DockerHub 页面 [这里](https://hub.docker.com/u/wetfeet2000) 找到
每个 Hog 和每个版本都会构建一个 Docker 镜像。因此,要使用 choctaw_hog,你可以运行以下命令:```shell script
docker pull wetfeet2000/choctaw_hog:1.0.10
docker run -it --rm wetfeet2000/choctaw_hog:1.0.10 --help
cargo build --release。二进制文件位于 target/release 目录中。cargo doc --no-deps --open。cargo test。## 如何在 Windows 上构建
您需要编译静态 OpenSSL 二进制文件,并告诉 Rust/Cargo 在哪里找到它们:```
mkdir \Tools
cd \Tools
git clone https://github.com/Microsoft/vcpkg.git
cd vcpkg
.\bootstrap-vcpkg.bat
.\vcpkg.exe install openssl:x64-windows-static
$env:OPENSSL_DIR = 'C:\Tools\vcpkg\installed\x64-windows-static'
$env:OPENSSL_STATIC = 'Yes'
[System.Environment]::SetEnvironmentVariable('OPENSSL_DIR', $env:OPENSSL_DIR, [System.EnvironmentVariableTarget]::User)
[System.Environment]::SetEnvironmentVariable('OPENSSL_STATIC', $env:OPENSSL_STATIC, [System.EnvironmentVariableTarget]::User)
现在你可以按照上面列出的主要构建说明进行操作。
使用 Homebrew 获取依赖项:``` brew install rpm2cpio FiloSottile/musl-cross/musl-cross
然后运行 `./build_lambda_macos.sh`。
构建脚本将基于 OpenSSL 3.0.12 进行构建。使用 `export OPENSSL_BUILD_VER=3.0.12` 进行覆盖。
构建脚本将基于 Amazon Linux 内核头文件(由其 RPM 提供)进行构建;使用 `export AMAZON_KERNEL_HEADERS_RPM_URL=...` 覆盖 RPM 的下载位置。(不禁止使用其他发行版的 linux-headers RPM,我们只需要 linux-headers 来为 Linux 构建 openssl)
构建脚本将在当前源码根目录创建一个 build-deps 目录。你可以安全地 `rm -rf` 该目录,但下次运行构建脚本时会重新创建。它还会进行各种一致性检查,确保构建能够正常进行,如果检查失败,可能会要求你 `rm -rf` 该目录以重新尝试。
### Linux
确保已安装 `cross`(`cargo install cross`),然后只需运行 `./build_lambda.sh`。
# 命令
## Anakamali Hog(GDoc 扫描器)用法```
USAGE:
ankamali_hog [FLAGS] [OPTIONS] <GDRIVEID>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--oauthsecret Path to an OAuth secret file (JSON) ./clientsecret.json by default
--oauthtoken Path to an OAuth token storage file ./temp_token by default
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-a, --allowlist <ALLOWLIST> Sets a custom allowlist JSON file
--default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default)
-o, --outputfile <OUTPUT> Sets the path to write the scanner results to (stdout by default)
--regex <REGEX> Sets a custom regex JSON file
ARGS:
<GDRIVEID> The ID of the Google drive file you want to scan
USAGE: berkshire_hog [FLAGS] [OPTIONS]
FLAGS: --caseinsensitive Sets the case insensitive flag for all regexes --entropy Enables entropy scanning --prettyprint Outputs the JSON in human readable format -r, --recursive Recursively scans files under the prefix -v, --verbose Sets the level of debugging information -h, --help Prints help information -V, --version Prints version information
OPTIONS: -a, --allowlist Sets a custom allowlist JSON file --default_entropy_threshold <DEFAULT_ENTROPY_THRESHOLD> Default entropy threshold (0.6 by default) -o, --outputfile Sets the path to write the scanner results to (stdout by default)
--profile <PROFILE> When using a configuration file, enables a non-default profile
--regex <REGEX> Sets a custom regex JSON file
ARGS: The location of a S3 bucket and optional prefix or filename to scan. This must be written in the form s3://mybucket[/prefix_or_file] Sets the region of the S3 bucket to scan
## Berkshire Hog(S3 扫描器 - Lambda)使用说明
Berkshire Hog 目前设计为作为 Lambda 函数使用。以下是基本数据流:
<pre>
┌───────────┐ ┌───────┐ ┌────────────────┐ ┌────────────┐
│ S3 bucket │ ┌────────┐ │ │ │ Berkshire Hog │ │ S3 bucket │
│ (input) ─┼─┤S3 event├──▶│ SQS │────▶│ (Lambda) │────▶│ (output) │
│ │ └────────┘ │ │ │ │ │ │
└───────────┘ └───────┘ └────────────────┘ └────────────┘
</pre>
若要按此方式运行 Berkshire Hog,请设置以下内容:
1) 配置输入存储桶,使其针对每个 PUSH/PUT 事件向 SQS 发送“事件”。
2) 设置 SQS 主题以接受来自 S3 的事件,包括 IAM 权限。
3) 使用对 SQS 和 S3 具有 IAM 访问权限的方式运行 Berkshire Hog。
## Choctaw Hog(Git 扫描器)使用说明```
USAGE:
choctaw_hog [FLAGS] [OPTIONS] <GITPATH>
FLAGS:
--caseinsensitive Sets the case insensitive flag for all regexes
--entropy Enables entropy scanning
--prettyprint Outputs the JSON in human readable format
-v, --verbose Sets the level of debugging information
-h, --help Prints help information
-V, --version Prints version information