1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
Drag to adjust the number of frozen columns
Name
Detector
Type
Status
Category
Amazon MWS Auth Token
^amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Regex
Global
Credentials
Arista network configuration
^via\ \d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3},\ \d{2}:\d{2}:\d{2}$
Regex
Global
Network
AWS Access Key ID
^AKIA[0-9A-Z]{16}$
Regex
Global
Credentials
AWS Secret Key
^[0-9a-zA-Z/+=]{40}$
Regex
Global
Credentials
aws_access_key
^((access[-_]?key[-_]?id)|(ACCESS[-_]?KEY[-_]?ID)|([Aa]ccessKeyId)|(access[_-]?id)).{0,20}AKIA[a-zA-Z0-9+/]{16}[^a-zA-Z0-9+/]$
Regex
Global
Credentials
aws_credentials_context
^access_key_id|secret_access_key|AssetSync.configure$
Regex
Global
Credentials
aws_secret_key
^((secret[-_]?access[-_]?key)|(SECRET[-_]?ACCESS[-_]?KEY|(private[-_]?key))|([Ss]ecretAccessKey)).{0,20}[^a-zA-Z0-9+/][a-zA-Z0-9+/]{40}\b$
Regex
Global
Credentials
Azure API Key
^(KEY|key|Key)*\s*(:|:=|=>|=)*\s*[A-F0-9]{32}$
Regex
Global
Credentials
Bank of America Routing Numbers - California
^(?:121|026)00(?:0|9)(?:358|593)$
Regex
California
Finance
BBVA Compass Routing Number - California
^321170538$
Regex
California
Finance
Box Links
^
https://app.box.com/
[s|l]/\S+$
Regex
Global
General
California Drivers License
^[A-Z]{1}\d{7}$
Regex
California
PII
Chase Routing Numbers - California
^322271627$
Regex
California
Finance
Cisco Router Config
^service\ timestamps\ [a-z]{3,5}\ datetime\ msec|boot-[a-z]{3,5}-marker|interface\ [A-Za-z0-9]{0,10}[E,e]thernet$
Regex
Global
Network
Citibank Routing Numbers - California
^32(?:11|22)71(?:18|72)4$
Regex
California
Finance
CVE Number
^CVE-\d{4}-\d{4,7}$
Regex
Global
General
Dropbox Links
^
https://www.dropbox.com/(?:s|l)/\S+$
Regex
Global
General
DSA Private Key
^-----BEGIN DSA PRIVATE KEY-----(?:[a-zA-Z0-9\+\=\/"']|\s)+?-----END DSA PRIVATE KEY-----$
Regex
Global
Credentials
EC Private Key
^-----BEGIN (?:EC|ECDSA) PRIVATE KEY-----(?:[a-zA-Z0-9\+\=\/"']|\s)+?-----END (?:EC|ECDSA) PRIVATE KEY-----$
Regex
Global
Credentials
EC Private Key
^-----BEGIN EC PRIVATE KEY----- [\r\n]+(?:\w+:.+)*[\s]* (?:[0-9a-zA-Z+\/=]{64,76}[\r\n]+)+ [0-9a-zA-Z+\/=]+[\r\n]+ -----END EC PRIVATE KEY-----$
Regex
Global
Credentials
Encrypted DSA Private Key
^-----BEGIN DSA PRIVATE KEY-----\s.*,ENCRYPTED(?:.|\s)+?-----END DSA PRIVATE KEY-----$
Regex
Global
Credentials
Encrypted EC Private Key
^-----BEGIN (?:EC|ECDSA) PRIVATE KEY-----\s.*,ENCRYPTED(?:.|\s)+?-----END (?:EC|ECDSA) PRIVATE KEY-----$
Regex
Global
Credentials
Encrypted Private Key
^-----BEGIN ENCRYPTED PRIVATE KEY-----(?:.|\s)+?-----END ENCRYPTED PRIVATE KEY-----$
Regex
Global
Credentials
Encrypted PuTTY SSH DSA Key
^PuTTY-User-Key-File-2: ssh-dss\s*Encryption: aes(?:.|\s?)*?Private-MAC:$
Regex
Global
Credentials
Encrypted PuTTY SSH RSA Key
^PuTTY-User-Key-File-2: ssh-rsa\s*Encryption: aes(?:.|\s?)*?Private-MAC:$
Regex
Global
Credentials
Encrypted RSA Private Key
^-----BEGIN RSA PRIVATE KEY-----\s.*,ENCRYPTED(?:.|\s)+?-----END RSA PRIVATE KEY-----$
Regex
Global
Credentials
Facebook Access Token
^EAACEdEose0cBA[0-9A-Za-z]+$
Regex
Global
Credentials
facebook_secret
^(facebook_secret|FACEBOOK_SECRET|facebook_app_secret|FACEBOOK_APP_SECRET)[a-z_ =\s"'\:]{0,5}[^a-zA-Z0-9][a-f0-9]{32}[^a-zA-Z0-9]$
Regex
Global
Credentials
General Private Key
^-----BEGIN PRIVATE KEY----- [\r\n]+(?:\w+:.+)*[\s]* (?:[0-9a-zA-Z+\/=]{64,76}[\r\n]+)+ [0-9a-zA-Z+\/=]+[\r\n]+ -----END PRIVATE KEY-----$
Regex
Global
Credentials
github_key
^(GITHUB_SECRET|GITHUB_KEY|github_secret|github_key|github_token|GITHUB_TOKEN|github_api_key|GITHUB_API_KEY)[a-z_ =\s"'\:]{0,10}[^a-zA-Z0-9][a-zA-Z0-9]{40}[^a-zA-Z0-9]$
Regex
Global
Credentials
Google Application Identifier
^[0-9]+-\w+.apps.googleusercontent.com$
Regex
Global
Credentials
Google Cloud Access Token Secret
^[0-9a-zA-Z]{45}$
Regex
Global
Credentials
Google Cloud API Key
^AIza[0-9A-Za-z\-_]{35}$
Regex
Global
Credentials
Google Cloud API Secret
^[0-9a-zA-Z]{32}$
Regex
Global
Credentials
Google Cloud Platform
(see YouTube)
Regex
Global
Credentials
Google Drive
(see YouTube)
Regex
Global
Credentials
Google Gmail
(see YouTube)
Regex
Global
Credentials
Google YouTube API Key
^AIza[0-9A-Za-z\-_]{35}$
Regex
Global
Credentials
Google YouTube OAuth ID
^[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com$
Regex
Global
Credentials
google_two_factor_backup
^(?:BACKUP VERIFICATION CODES|SAVE YOUR BACKUP CODES)[\s\S]{0,300}@$
Regex
Global
Credentials
heroku_key
^(heroku_api_key|HEROKU_API_KEY|heroku_secret|HEROKU_SECRET)[a-z_ =\s"'\:]{0,10}[^a-zA-Z0-9-]\w{8}(?:-\w{4}){3}-\w{12}[^a-zA-Z0-9\-]$
Regex
Global
Credentials
HIPAA PHI National Drug Code
^\d{4,5}-\d{3,4}-\d{1,2}$
Regex
United States
Health
Huawei config file
^sysname\ HUAWEI|set\ authentication\ password\ simple\ huawei$
Regex
Global
Network
Individual Taxpayer Identification Numbers (ITIN)
^9\d{2}(?:[ \-]?)[7,8]\d(?:[ \-]?)\d{4}$
Regex
United States
PII
John the Ripper
^[J,j]ohn\ [T,t]he\ [R,r]ipper|john-[1-9].[1-9].[1-9]|Many\ salts:|Only\ one\ salt:|
openwall.com/john/|List.External
:[0-9a-zA-Z]*|Loaded\ [0-9]*\ password hash|guesses:\ \d*\ \ time:\ \d*:\d{2}:\d{2}:\d{2}|john\.pot$
Regex
Global
Network
KeePass 1.x CSV Passwords
^"Account","Login Name","Password","Web Site","Comments"$
Regex
Global
Credentials
KeePass 1.x XML Passwords
^<pwlist>\s*?<pwentry>[\S\s]*?<password>[\S\s]*?<\/pwentry>\s*?<\/pwlist>$
Regex
Global
Credentials
Large number of US Phone Numbers
^\d{3}-\d{3}-\d{4}|\(\d{3}\)\ ?\d{3}-?\d{4}$
Regex
United States
Database
Large number of US Zip Codes
^(\d{5}-\d{4}|\d{5})$
Regex
United States
Database
Lightweight Directory Access Protocol
^(?:dn|cn|dc|sn):\s*[a-zA-Z0-9=, ]*$
Regex
Global
Credentials
MailChimp API Key
^[0-9a-f]{32}-us[0-9]{1,2}$
Regex
Global
Credentials
MailGun API Key
^key-[0-9a-zA-Z]{32}$
Regex
Global
Credentials
Metasploit Module
^require\ 'msf/core'|class\ Metasploit|include\ Msf::Exploit::\w+::\w+$
Regex
Global
Network
microsoft_office_365_oauth_context
^
https://login.microsoftonline.com/common/oauth2/v2.0/token|https://login.windows.net/common/oauth2/token$
Regex
Global
Credentials
MySQL database dump
^DROP DATABASE IF EXISTS(?:.|\n){5,200}CREATE DATABASE(?:.|\n){5,200}DROP TABLE IF EXISTS(?:.|\n){5,200}CREATE TABLE$
Regex
Global
Database
MySQLite database dump
^DROP\ TABLE\ IF\ EXISTS\ \[[a-zA-Z]*\];|CREATE\ TABLE\ \[[a-zA-Z]*\];$
Regex
Global
Database
Network Proxy Auto-Config
^proxy\.pac|function\ FindProxyForURL\(\w+,\ \w+\)$
Regex
Global
Network
Nmap Scan Report
^Nmap\ scan\ report\ for\ [a-zA-Z0-9.]+$
Regex
Global
Network
OAuth Access Token
^ya29\.[0-9A-Za-z\-_]+$
Regex
Global
Credentials
OAuth Auth Code
^4/[0-9A-Za-z\-_]+$
Regex
Global
Credentials
OAuth Refresh Token
^1/[0-9A-Za-z\-_]{43}| 1/[0-9A-Za-z\-_]{64}$
Regex
Global
Credentials
OAuth Secret
^[0-9a-zA-Z\-_]{24}$
Regex
Global
Credentials
Password etc passwd
^[a-zA-Z0-9\-]+:[x|\*]:\d+:\d+:[a-zA-Z0-9/\- "]*:/[a-zA-Z0-9/\-]*:/[a-zA-Z0-9/\-]+$
Regex
Global
Credentials
Password etc shadow
^[a-zA-Z0-9\-]+:(?:(?:!!?)|(?:\*LOCK\*?)|\*|(?:\*LCK\*?)|(?:\$.*\$.*\$.*?)?):\d*:\d*:\d*:\d*:\d*:\d*:$
Regex
Global
Credentials
PayPal Braintree Access Token
^access_token\$production\$[0-9a-z]{16}\$[0-9a-f]{32}$
Regex
Global
Credentials
PGP Header
^-{5}(?:BEGIN|END)\ PGP\ MESSAGE-{5}$
Regex
Global
Credentials
PGP Private Key
^-----BEGIN PGP PRIVATE KEY BLOCK----- [\r\n]+(?:\w+:.+)*[\s]* (?:[0-9a-zA-Z+\/=]{64,76}[\r\n]+)+ [0-9a-zA-Z+\/=]+[\r\n]+= [0-9a-zA-Z+\/=]{4}[\r\n]+ -----END PGP PRIVATE KEY BLOCK-----$
Regex
Global
Credentials
PGP Private Key Block
^-----BEGIN PGP PRIVATE KEY BLOCK-----(?:.|\s)+?-----END PGP PRIVATE KEY BLOCK-----$
Regex
Global
Credentials
pgSQL Connection Information
^(?:postgres|pgsql)\:\/\/$
Regex
Global
Credentials
Picatic API Key
^sk_live_[0-9a-z]{32}$
Regex
Global
Credentials
PKCS7 Encrypted Data
^(?:Signer|Recipient)Info(?:s)?\ ::=\ \w+|[D|d]igest(?:Encryption)?Algorithm|EncryptedKey\ ::= \w+$
Regex
Global
Credentials
PlainText Private Key
^-----BEGIN PRIVATE KEY-----(?:.|\s)+?-----END PRIVATE KEY-----$
Regex
Global
Credentials
Public encrypted key
^-----BEGIN PUBLIC KEY-----(?:.|\s)+?-----END PUBLIC KEY-----$
Regex
Global
Credentials
Public Key Cryptography System (PKCS)
^protocol="application/x-pkcs[0-9]{0,2}-signature"$
Regex
Global
Credentials
PuTTY SSH DSA Key
^PuTTY-User-Key-File-2: ssh-dss\s*Encryption: none(?:.|\s?)*?Private-MAC:$
Regex
Global
Credentials
PuTTY SSH RSA Key
^PuTTY-User-Key-File-2: ssh-rsa\s*Encryption: none(?:.|\s?)*?Private-MAC:$
Regex
Global
Credentials
RSA Private Key
^-----BEGIN RSA PRIVATE KEY----- [\r\n]+(?:\w+:.+)*[\s]* (?:[0-9a-zA-Z+\/=]{64,76}[\r\n]+)+ [0-9a-zA-Z+\/=]+[\r\n]+ -----END RSA PRIVATE KEY----$
Regex
Global
Credentials
RSA Private Key
^-----BEGIN RSA PRIVATE KEY-----(?:[a-zA-Z0-9\+\=\/"']|\s)+?-----END RSA PRIVATE KEY-----$
Regex
Global
Credentials
Samba Password config file
^[a-z]*:\d{3}:[0-9a-zA-Z]*:[0-9a-zA-Z]*:\[U\ \]:.*$
Regex
Global
Credentials
Simple Network Management Protocol Object Identifier
^(?:\d\.\d\.\d\.\d\.\d\.\d{3}\.\d\.\d\.\d\.\d\.\d\.\d\.\d\.\d\.\d{4}\.\d)|[a-zA-Z]+[)(0-9]+\.[a-zA-Z]+[)(0-9]+\.[a-zA-Z]+[)(0-9]+\.[a-zA-Z]+[)(0-9]+\.[a-zA-Z]+[)(0-9]+\.[a-zA-Z]+[)(0-9]+\.[a-zA-Z0-9)(]+\.[a-zA-Z0-9)(]+\.[a-zA-Z0-9)(]+\.[a-zA-Z0-9)(]+$
Regex
Global
Network
Slack 2FA Backup Codes
^Two-Factor\s*\S*Authentication\s*\S*Backup\s*\S*Codes(?:.|\n)*[Ss]lack(?:.|\n)*\d{9}$
Regex
Global
Credentials
Slack API key
^(slack_api_key|SLACK_API_KEY|slack_key|SLACK_KEY)[a-z_ =\s"'\:]{0,10}[^a-f0-9][a-f0-9]{32}[^a-f0-9]$
Regex
Global
Credentials
Slack API token
^(xox[pb](?:-[a-zA-Z0-9]+){4,})$
Regex
Global
Credentials
Square Access Token
^sq0atp-[0-9A-Za-z\-_]{22}$
Regex
Global
Credentials
Square OAuth Secret
^sq0csp-[0-9A-Za-z\-_]{43}$
Regex
Global
Credentials
SSH DDS Public
^ssh-dss [0-9A-Za-z+/]+[=]{2}$
Regex
Global
Credentials
SSH RSA Public
^ssh-rsa AAAA[0-9A-Za-z+/]+[=]{0,3} [^@]+@[^@]+$
Regex
Global
Credentials
SSL Certificate
^-----BEGIN CERTIFICATE-----(?:.|\n)+?\s-----END CERTIFICATE-----$
Regex
Global
Credentials
Stripe Restricted API Key
^rk_live_[0-9a-zA-Z]{24}$
Regex
Global
Credentials
Stripe Standard API Key
^sk_live_[0-9a-zA-Z]{24}$
Regex
Global
Credentials
SWIFT Codes
^[A-Za-z]{4}(?:GB|US|DE|RU|CA|JP|CN)[0-9a-zA-Z]{2,5}$
Regex
Global
Finance
Twilio API Key
^SK[0-9a-fA-F]{32}$
Regex
Global
Credentials
Twitter Access Token
^[1-9][0-9]+-[0-9a-zA-Z]{40}$
Regex
Global
Credentials
UK Drivers License Numbers
^[A-Z]{5}\d{6}[A-Z]{2}\d{1}[A-Z]{2}$
Regex
United Kingdom
PII
UK Passport Number
^\d{10}GB[RP]\d{7}[UMF]{1}\d{9}$
Regex
United Kingdom
PII
United Bank Routing Number - California
^122243350$
Regex
California
Finance
USBank Routing Numbers - California
^12(?:1122676|2235821)$
Regex
California
Finance
Wells Fargo Routing Numbers - California
^121042882$
Regex
California
Finance
98 records
Summary
Summary
Summary
Summary
Summary
Alert
Lorem ipsum
Okay
Google Cloud Platform
Loaded
Name
Google Cloud Platform
Detector
(see YouTube)
Type
Regex
Status
Global
Category
Credentials
View larger version
Download CSV