Skip to content

AI Secrets

Evidence: AI Secrets
Description: Hunt credentials exposed in AI prompts, responses, tool output, and configs
Category: AI
Platform: windows
Short Name: aisec
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Developers paste tokens, keys, and credentials into AI prompts. Agents can also echo secrets back or receive them from tool output and config stores. Those findings are a credential-exposure lead, not proof of theft.

This collector gathers structured data about redacted credential findings, including detector, category, surface, location, and links back to the originating session or event. Cleartext is not stored in Case.db.

This collector reuses the AI artifact scanner and transcript/config parsers. A two-stage detector emits redacted findings with their surface and location. Cleartext is never written to Case.db.

Reveals secrets a developer pasted into an AI tool, that an agent echoed back, or that a tool returned. Findings link to the originating session, event, and preserved raw source for follow-up.