Credential Access
- Category
- Privilege Escalation
- Confidence
- 70% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
When you need to verify what sshx would do before touching a server, pass
--dry-run --json. It prints a local execution plan and does not connect, execute, read keyring secrets, mutateknown_hosts, or write settings.bash sshx -h=prod-web --dry-run --json "sudo systemctl restart nginx"
