Secrets — Monitoring & Observability

Datadog, New Relic, Sentry, Grafana, PagerDuty and other observability keys.

All rules in this category are kind secrets. They run under vulnetix secrets and the secrets stage of vulnetix scan.

Rule IDNameSeverityDetection
VNX-SEC-095PagerDuty API tokenCriticalkeyword + regex + entropy
VNX-SEC-096Sentry DSN with secretHighkeyword + regex
VNX-SEC-603Datadog application key (app key)Highkeyword + regex + entropy
VNX-SEC-604Honeycomb API keyHighkeyword + regex + entropy
VNX-SEC-605Lightstep / Cloud Observability access tokenHighkeyword + regex + entropy
VNX-SEC-606Dynatrace API tokenCriticalkeyword + regex
VNX-SEC-607Splunk HEC tokenHighkeyword + regex
VNX-SEC-608Splunk session / authentication tokenHighkeyword + regex + entropy
VNX-SEC-609Rollbar project access tokenHighkeyword + regex + entropy
VNX-SEC-610Bugsnag API keyMediumkeyword + regex + entropy
VNX-SEC-611Honeybadger API keyHighkeyword + regex + entropy
VNX-SEC-612Logz.io shipping / API tokenHighkeyword + regex + entropy
VNX-SEC-613Loggly customer tokenMediumkeyword + regex
VNX-SEC-614Better Stack / Logtail source tokenHighkeyword + regex + entropy
VNX-SEC-615Grafana Cloud access policy tokenCriticalkeyword + regex
VNX-SEC-616Grafana service account tokenHighkeyword + regex
VNX-SEC-617New Relic user API key (NRAK)Highkeyword + regex
VNX-SEC-618New Relic REST API key (NRAA)Highkeyword + regex
VNX-SEC-619New Relic insert / ingest key (NRII)Highkeyword + regex
VNX-SEC-620AppDynamics access keyHighkeyword + regex + entropy
VNX-SEC-621Instana agent keyHighkeyword + regex + entropy
VNX-SEC-622Sumo Logic collector access keyHighkeyword + regex + entropy
VNX-SEC-623Prometheus remote-write basic-auth URLHighkeyword + regex
VNX-SEC-624Elastic APM secret tokenHighkeyword + regex + entropy
VNX-SEC-625Raygun API keyMediumkeyword + regex + entropy
VNX-SEC-626Datadog client token (pub)Mediumkeyword + regex
VNX-SEC-627Honeycomb ingest key (hcaik / hcxik)Highkeyword + regex
VNX-SEC-632Datadog API key (dd context)Highkeyword + regex + entropy
VNX-SEC-633Logtail / Better Stack ingesting host token (https)Highkeyword + regex
VNX-SEC-634Dynatrace platform token (dt0s)Criticalkeyword + regex
VNX-SEC-638Sentry organization auth token (sntrys)Highkeyword + regex
VNX-SEC-639Pyroscope / Grafana profiling ingest URL with tokenHighkeyword + regex
VNX-SEC-640Sumo Logic HTTP source collector URLHighkeyword + regex
VNX-SEC-1067GameAnalytics secret keyMediumkeyword + regex + entropy
VNX-SEC-1097Countly API keyMediumkeyword + regex + entropy
VNX-SEC-1098Plausible Analytics API keyMediumkeyword + regex + entropy
VNX-SEC-1099Fathom Analytics API tokenMediumkeyword + regex + entropy
VNX-SEC-1100Matomo API token_authHighkeyword + regex + entropy
VNX-SEC-1101Umami API key/tokenMediumkeyword + regex + entropy
VNX-SEC-1102Datadog RUM client token (pub)Mediumkeyword + regex
VNX-SEC-1124Statsig server secret key (secret-)Highkeyword + regex
VNX-SEC-1125Split.io server-side API keyHighkeyword + regex + entropy
VNX-SEC-1126Optimizely SDK datafile tokenMediumkeyword + regex + entropy
VNX-SEC-1134GameAnalytics game keyMediumkeyword + regex + entropy
VNX-SEC-1140ConfigCat SDK key (assignment context)Mediumkeyword + regex + entropy

Remediation

Rotate any exposed credential immediately, remove it from source, and load it from a secrets manager or environment variable instead. Purge it from git history with git filter-repo. See CWE-798 and the OWASP Secrets Management Cheat Sheet.