3 citations · 3 across the 2 of their papers we have counts for
4 papers · 1 filter
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
Setu Kumar Basak, Tanmay Pardeshi, Bradley Reaves +1
Since 2020, GitGuardian has been detecting checked-in hard-coded secrets in GitHub repositories. During 2020-2023, GitGuardian has observed an upward annual trend and a four-fold i…
AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts
Setu Kumar Basak, K. Virgil English, Ken Ogura +3
GitGuardian monitored secrets exposure in public GitHub repositories and reported that developers leaked over 12 million secrets (database and other credentials) in 2023, indicatin…
Attackers reveal their arsenal: An investigation of adversarial techniques in CTI reports
Md Rayhanur Rahman, Setu Kumar Basak, Rezvan Mahdavi Hezaveh +1
Context: Cybersecurity vendors often publish cyber threat intelligence (CTI) reports, referring to the written artifacts on technical and forensic analysis of the techniques used b…
A Comparative Study of Software Secrets Reporting by Secret Detection Tools
Setu Kumar Basak, Jamison Cox, Bradley Reaves +1
Background: According to GitGuardian's monitoring of public GitHub repositories, secrets sprawl continued accelerating in 2022 by 67% compared to 2021, exposing over 10 million sec…