ChecklistCONSTRUCTEDUntested

First 15 minutes: a secret was pushed to a public repository

An API key, password or token is public. Scrapers find these within minutes, so revoke first and investigate second. Deleting the commit does not un-publish it.

high severityCredential AccessT1552.001T1078.004

The clock starts when

Secret scanning, a researcher, a colleague or a vendor reports an API key, password, token or private key in a public repository, gist, paste site or published package.

0 of 9 done
minutes 0 to 5

Make the secret worthless

minutes 5 to 10

Find out whether it was used

minutes 10 to 15

Clean up without pretending it never happened

Do not

  • Do not delete the repository or force-push and call it fixed. The secret works until it is revoked.
  • Do not wait to find out whether it was used before revoking it.
  • Do not paste the secret into a ticket or chat to discuss it. Refer to it by where it lives.

Escalate now if

  • It is a cloud administrator key, a root credential or a signing key.
  • The issuer's logs show use by somebody you cannot identify.
  • It could reach customer or personal data.

Minute sixteen. The checklist ends here and the response does not.

Open the exposed secret playbook

Why this order

It is tempting to investigate first, to find out whether the key was used before deciding how worried to be. That gets the order backwards. Revoking a key that was never abused costs a deploy. Waiting to revoke a key that is being abused costs whatever it can reach.

What this does not cover

Anything the key was used to create. If the logs show activity you cannot explain, the incident is now the account the key belonged to, and the playbook linked above takes it from there.

sources

  1. MITRE ATT&CK T1552.001, Unsecured Credentials: Credentials In Files · primary
  2. GitHub Docs: removing sensitive data from a repository
  3. GitHub Docs: about secret scanning

Tags: first-15 · secrets · github · credentials · cloud · supply-chain · T1552.001