Skip to main content
bagel
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

Cloud Probe

The cloud probe scans cloud provider configuration and credential files for exposed secrets.

What It Checks

The probe examines cloud configuration files and uses the Cloud Credentials Detector to find exposed credentials:

ProviderFiles Scanned
AWS~/.aws/config, ~/.aws/credentials
GCP~/.config/gcloud/*
Azure~/.azure/*

Finding Types

Secrets found by this probe will be tagged with the Cloud Credentials Detector findings:

Finding IDDescription
cloud-credential-aws-access-key-idAWS Access Key ID
cloud-credential-azure-storage-keyAzure Storage Account Key
cloud-credential-gcp-api-keyGoogle Cloud API Key

All findings have Critical severity.

Best Practices

Prefer using Short Lived credentials instead of long-lived static credentials. Use IAM roles, Workload Identity Federation, or Managed Identities to provide temporary access to cloud resources.

Short lived credentials should use as short as possible session durations and ideally require a second factor to refresh.