Env Variable Harvesting
High
- Category
- Data Exfiltration
- Content
**Parameter value - manual input**: fill in the concrete value directly. **Parameter value - KMS credential**: reference an existing credential in Key Management Service (KMS) to store sensitive data securely. The credential must be bound with a tag before it can be referenced by WAF: | Tag Key | Tag Value | | --- | --- |
- Confidence
- 24% confidence
- Finding
- Code accesses environment variables that may contain secrets (API keys, tokens). This is a common pattern for credential theft.
