Secrets & keys
API keys, cloud secrets and connection strings our scanner pulled from the downloaded files — categorized and risk-rated. AD/LDAP & database connections are flagged critical. Every source links to its file and machine.
| Risk | Category | Secret | Host / user | Ownership | Source | Status |
|---|---|---|---|---|---|---|
| medium | 🗄️ Database connections | 🏢 corporate | 🖥️ machine · 📄 config.env | invalid | ||
| medium | 🗄️ Database connections | 🏢 corporate | 🖥️ machine · 📄 config.env | invalid | ||
| medium | 🗄️ Database connections | 🏢 corporate | 🖥️ machine · 📄 config.env | invalid |
⚖️ Validation runs client-side, never from this server. Click validate ⚡: for provider API keys (Google/AWS/Stripe/SendGrid/Slack/GitHub) the check runs in your browser where CORS allows; for raw-socket services (AD/LDAP, DB, FTP, SMTP, MQTT) and remote-access "connect" files (RDP/VNC/SSH/AnyDesk/TeamViewer) — which a browser can't open — you get the exact command to run from an authorized position on the client network, then record the outcome. Only validate targets you are authorized to test. Results (live / rejected / unreachable) are saved with a timestamp and the method used.