Rule Format
How LOLPaths YAML rules are structured.
Each rule represents one logical sensitive artifact. Platform-specific paths belong inside each path matcher.
schema_version: 1
id: cloud.aws.credentials
name: AWS CLI Credentials
category: cloud
subcategory: aws
artifact_types:
- credential
- configuration
sensitivity: critical
match:
paths:
- path: '%USERPROFILE%\.aws\credentials'
kind: file
platforms: [windows]
- path: "$HOME/.aws/credentials"
kind: file
platforms: [linux, macos]
content:
contains:
- aws_access_key_id
regex:
- '(?i)aws_secret_access_key\s*='Required Fields
schema_versionidnamecategorysensitivitymatch
At least one match.paths entry is required. match.content.contains and
match.content.regex may add evidence, but cannot stand alone.
Path Kinds
LOLPaths v1 supports:
filedirectoryglob
Path regex is intentionally not part of schema version 1. Use recursive globs
such as **/.env.*, **/*.pem, or **/.github/workflows/*.y?ml.