Rule Format

How LOLPaths YAML rules are structured.

Each rule represents one logical sensitive artifact. Platform-specific paths belong inside each path matcher.

schema_version: 1
id: cloud.aws.credentials
name: AWS CLI Credentials
category: cloud
subcategory: aws
artifact_types:
  - credential
  - configuration
sensitivity: critical
match:
  paths:
    - path: '%USERPROFILE%\.aws\credentials'
      kind: file
      platforms: [windows]
    - path: "$HOME/.aws/credentials"
      kind: file
      platforms: [linux, macos]
  content:
    contains:
      - aws_access_key_id
    regex:
      - '(?i)aws_secret_access_key\s*='

Required Fields

  • schema_version
  • id
  • name
  • category
  • sensitivity
  • match

At least one match.paths entry is required. match.content.contains and match.content.regex may add evidence, but cannot stand alone.

Path Kinds

LOLPaths v1 supports:

  • file
  • directory
  • glob

Path regex is intentionally not part of schema version 1. Use recursive globs such as **/.env.*, **/*.pem, or **/.github/workflows/*.y?ml.

On this page