{"repo":"chainguard-dev/ghscan","free":true,"listed":false,"github":"https://github.com/chainguard-dev/ghscan","clone":"git clone https://github.com/chainguard-dev/ghscan.git","description":"Scan GitHub Actions Workflow logs for IOCs","language":"Go","stars":19,"topics":["actions","logs","secrets","supply-chain","workflow","changed-files","detection","github-actions","ioc","scanner"],"license":"Apache-2.0","category":"workflow-automation","readme_excerpt":"ghscan Scan GitHub Workflow logs for IOCs via strings or regex. Notes: - This script should not be seen as a universal detector of compromise; rather, a single result likely indicates that other Workflow runs in the search window were also compromised - If the script detects base64 content in a Workflow's run logs as well as consecutive empty lines (no secrets leaked from the compromised action), then only the base64 data will be returned - This script will scan either an organization's or a repository's Workflow run logs for IOCs (double base64-encoded strings) and will attempt to decode them - This script was adapated from a mess of Python code that was built to scan the entirety of GitHub so there may be quirks or bugs - Since Workflows may no longer use the Action, this script just lists all Workflows and searches the logs during the period of time when the Action was compromised - This script is intended to be run using a short-lived GitHub Token from octo-sts Requirements - chainctl installed to handle ephemeral authentication Example octo-sts trust policy The ID required for the trust policy can be retrieved with: The policy file will look something like this: Usage For example: Custom IOC configuration can be provided with the flags documented above or added to config.yaml : name is a reference to the IOC content is the string or strings to search for in the Workflow logs pattern is an optional regex pattern to search for in the Workflow logs Results will be saved in ","default_branch":null,"files":null,"tree":[],"storefront":"/r/chainguard-dev","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/chainguard-dev/ghscan/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}