{"repo":"synacktiv/nord-stream","free":true,"listed":false,"github":"https://github.com/synacktiv/nord-stream","clone":"git clone https://github.com/synacktiv/nord-stream.git","description":"Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab.","language":"Python","stars":371,"topics":["azuredevops","ci-cd","cicd","github","gitlab","gitlab-ci"],"license":"GPL-3.0","category":"deployment-docker-iac","readme_excerpt":"Nord Stream Nord Stream is a tool that allows you extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab. Find out more in the following blogpost: https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks Table of Contents - Nord Stream - Table of Contents - Installation - Usage - Shared arguments - Describe token - Build YAML - YAML - Clean logs - Signing commits - Azure DevOps - Service connections - SSH - Listing orgs - Help - GitHub - List protections - Disable protections - Force - Azure OIDC - AWS OIDC - Help - GitLab - List secrets - YAML - List protections - Help - TODO - Contact Installation git is also required (see https://git-scm.com/download/) and must exist in your PATH . Usage Here is a simple example on GitHub; initially, one can enumerate the various secrets. Then proceed to the exfiltration: Shared arguments Some arguments are shared between GitHub, Azure DevOps and GitLab here are some examples. Describe token The --describe-token option can be used to display general information about your token: Build YAML The --build-yaml option can be used to create a pipeline file without deploying it. It retrieves the various secret names to build the associated pipeline, which can be used to add custom steps: YAML The --yaml option can be used to deploy a custom pipeline: By default, it will display the output of the task named command of the init job, but everythin","default_branch":null,"files":null,"tree":[],"storefront":"/r/synacktiv","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/synacktiv/nord-stream/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}