Generic secret exposure
- Hardcoded API keys, API secrets, private keys, access tokens, authentication tokens, JWT secrets, and high-entropy secret strings.
- Hardcoded passwords, administrator credentials, bypass credentials, and Basic Auth credentials.
- Credentials embedded in PostgreSQL, MySQL, MongoDB, and Redis connection URLs.
- Base64 and hexadecimal high-entropy strings that resemble secret material.
- Public IP exposure candidates found in sensitive configuration contexts.