Testing For Sensitive Data Exposure
Overview
Cybersecurity skill for testing for sensitive data exposure. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"testing for sensitive data exposure"
"Identifying sensitive data exposure vulnerabilities including API key leakage, P"
During authorized penetration tests when assessing data protection controls
When evaluating applications for GDPR, PCI DSS, HIPAA, or other data protection compliance
For identifying leaked API keys, credentials, tokens, and secrets in application responses
When testing whether sensitive data is properly encrypted in transit and at rest
During security assessments of APIs that handle PII, financial data, or health records
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Authorization: Written penetration testing agreement with data handling scope
- Burp Suite Professional: For intercepting and analyzing responses for sensitive data
- trufflehog: Secret scanning tool (
pip install trufflehog)
- gitleaks: Git repository secret scanner (
go install github.com/gitleaks/gitleaks/v8@latest)
- curl/httpie: For manual endpoint testing
- Browser DevTools: For examining local storage, session storage, and cached data
- testssl.sh: TLS configuration testing tool
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Reconnaissance — Gather information about the target related to . Identify attack surface.
- Vulnerability Identification — Enumerate potential weaknesses using automated and manual techniques.
- Exploit Development/Selection — Use sensitive data exposure to identify and test vulnerabilities.
- Execution — Execute the test in a controlled manner with proper authorization.
- Post-Exploitation — Document the impact and extent of successful exploitation.
- Reporting — Write detailed findings with reproduction steps, impact assessment, and remediation guidance.
Tools
- sensitive data exposure — Primary tool for this skill
- Vulnerability Scanner — Automated weakness identification
- Exploitation Framework — Controlled exploitation testing
- Reporting Tool — Findings documentation and tracking
Process
- Design — Define interface, identify patterns, plan implementation
- Implement — Write code following existing conventions, add tests
- Verify — Run tests, check integration, validate behavior
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: testing-for-sensitive-data-exposure3description: Use when identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments. Use when working with testing for sensitive data exposure.4license: Apache-2.05---67# Testing For Sensitive Data Exposure89## Overview1011Cybersecurity skill for testing for sensitive data exposure. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "testing for sensitive data exposure"16- "Identifying sensitive data exposure vulnerabilities including API key leakage, P"171819- During authorized penetration tests when assessing data protection controls20- When evaluating applications for GDPR, PCI DSS, HIPAA, or other data protection compliance21- For identifying leaked API keys, credentials, tokens, and secrets in application responses22- When testing whether sensitive data is properly encrypted in transit and at rest23- During security assessments of APIs that handle PII, financial data, or health records242526## When NOT to Use2728- When you lack proper authorization for testing29- For production systems without change management30- When the task requires legal or compliance expertise beyond technical scope313233## Prerequisites3435- **Authorization**: Written penetration testing agreement with data handling scope36- **Burp Suite Professional**: For intercepting and analyzing responses for sensitive data37- **trufflehog**: Secret scanning tool (`pip install trufflehog`)38- **gitleaks**: Git repository secret scanner (`go install github.com/gitleaks/gitleaks/v8@latest`)39- **curl/httpie**: For manual endpoint testing40- **Browser DevTools**: For examining local storage, session storage, and cached data41- **testssl.sh**: TLS configuration testing tool4243## Workflow4445```python46# Example: IOC detection47import re4849IOC_PATTERNS = {50 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",51 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",52 "hash_md5": r"\b[a-f0-9]{32}\b",53 "hash_sha256": r"\b[a-f0-9]{64}\b",54}5556def extract_iocs(text: str) -> dict:57 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}58```59601. **Reconnaissance** — Gather information about the target related to . Identify attack surface.612. **Vulnerability Identification** — Enumerate potential weaknesses using automated and manual techniques.623. **Exploit Development/Selection** — Use sensitive data exposure to identify and test vulnerabilities.634. **Execution** — Execute the test in a controlled manner with proper authorization.645. **Post-Exploitation** — Document the impact and extent of successful exploitation.656. **Reporting** — Write detailed findings with reproduction steps, impact assessment, and remediation guidance.6667## Tools6869- **sensitive data exposure** — Primary tool for this skill70- **Vulnerability Scanner** — Automated weakness identification71- **Exploitation Framework** — Controlled exploitation testing72- **Reporting Tool** — Findings documentation and tracking737475## Process76771. **Design** — Define interface, identify patterns, plan implementation781. **Implement** — Write code following existing conventions, add tests791. **Verify** — Run tests, check integration, validate behavior8081## Verification8283- [ ] All procedures executed completely and documented84- [ ] Findings validated against multiple data sources85- [ ] False positives identified and filtered86- [ ] Results documented with evidence and timestamps87- [ ] Recommendations provided with risk-based prioritization8889## Anti-Rationalization Table9091| Rationalization | Reality |92|---|---|93| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |94| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |95| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |