01Introduction
An access key committed to a repository is a master key left under the doormat. Attackers scan public code for them within minutes of a push, and private repositories leak too.
02What is Secrets detection?
Secrets detection is the practice of scanning source code, git history, configuration, CI logs and other artifacts for exposed credentials, such as API keys, cloud access keys, database passwords, tokens and private keys, and revoking and rotating any that are found.
It is a core AppSec and shift left control, and a common starting point for cloud security breaches.
03How Secrets detection works
Detection covers the present and the past.
- 1.
Scan history
Check every branch and commit, because a deleted secret is still in git history.
- 2.
Detect
Match known credential formats and high-entropy strings, then validate against the provider where possible.
- 3.
Assess impact
Determine which resource or service the credential unlocks.
- 4.
Revoke and prevent
Rotate the secret, then block new ones at the pull request.
04Threats and risks
A leaked secret skips every other control.
Cloud takeover
Leaked cloud keys used to spin up resources, exfiltrate data or delete backups.
Lingering history
A key removed from HEAD but never rotated remains valid and discoverable.
Third-party pivot
Payment, email and SaaS tokens used to act as your company.
CI leakage
Secrets printed to build logs or baked into container images.
05How Parameter helps
Parameter's secrets detection looks everywhere and tells you what's at stake. Read the Secrets Detection solution brief.
History, not just HEAD
Every branch and every commit, so a key deleted last year is still found.
Context on impact
Which cloud resource, data store or third-party service the credential unlocks.
Caught at the PR
New secrets are flagged inline by Sentinel before they merge.

