ChecklistCONSTRUCTEDUntested
First 15 minutes: a secret was pushed to a public repository
An API key, password or token is public. Scrapers find these within minutes, so revoke first and investigate second. Deleting the commit does not un-publish it.
high severityCredential AccessT1552.001T1078.004
The clock starts when
Secret scanning, a researcher, a colleague or a vendor reports an API key, password, token or private key in a public repository, gist, paste site or published package.
Make the secret worthless
Find out whether it was used
Clean up without pretending it never happened
Do not
- Do not delete the repository or force-push and call it fixed. The secret works until it is revoked.
- Do not wait to find out whether it was used before revoking it.
- Do not paste the secret into a ticket or chat to discuss it. Refer to it by where it lives.
Escalate now if
- It is a cloud administrator key, a root credential or a signing key.
- The issuer's logs show use by somebody you cannot identify.
- It could reach customer or personal data.
Minute sixteen. The checklist ends here and the response does not.
Open the exposed secret playbookWhy this order
It is tempting to investigate first, to find out whether the key was used before deciding how worried to be. That gets the order backwards. Revoking a key that was never abused costs a deploy. Waiting to revoke a key that is being abused costs whatever it can reach.
What this does not cover
Anything the key was used to create. If the logs show activity you cannot explain, the incident is now the account the key belonged to, and the playbook linked above takes it from there.