Filesystem
Filesystem
Edition: Enterprise + Open Source
The Filesystem integration scans local files and directories for credentials and other sensitive data. It can also scan data piped in via stdin.
Configuration
The Filesystem integration is configured via a local configuration file. Web configuration is not available for this source.
Local configuration
Scan scope
Scan scope is controlled with includePathsFile and excludePathsFile. Each field references a file containing newline-separated regular expressions. Files matching the patterns are included or excluded from the scan, respectively.
- includePathsFile — path to a file with newline-separated regex patterns. Files matching these patterns are included.
- excludePathsFile — path to a file with newline-separated regex patterns. Files matching these patterns are excluded.
Symlinks
By default, the filesystem scan does not follow symlinks. To follow them, set maxSymlinkDepth to a value between 1 and 40.
Scanning stdin
The filesystem scanner can also scan data piped in via stdin. Invoke the scanner with the file subcommand and no path argument:
To scan a path instead, pass it as an argument:
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
paths | list | No | List of paths to scan. |
includePathsFile | string | No | Path to a file containing newline-separated regex patterns. Files matching these patterns are included in the scan. |
excludePathsFile | string | No | Path to a file containing newline-separated regex patterns. Files matching these patterns are excluded from the scan. |
skipBinaries | boolean | No | Skip binary files. |
maxSymlinkDepth | integer | No | Maximum symlink depth to follow. Defaults to 0 (no symlinks followed). Maximum value is 40. |
Capabilities
Feature | Supported |
|---|---|
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Scan Microsoft Office documents | ✅ |
Include / exclude filters | ✅ |
Stdin scanning | ✅ |