Add SAF-T1506: Infrastructure Token Theft - #219
mironovisa wants to merge 1 commit into
Conversation
Signed-off-by: mironovisa <119300058+mironovisa@users.noreply.github.com>
|
Hi — quick maintainer check on SAF-T1506. The contribution is scoped to infrastructure-token exposure through logs, traces, proxies, crash dumps, support exports, and persistent agent memory, with separate client, MCP-policy, and upstream-credential boundaries. DCO is passing and the PR is mergeable. Happy to revise the technique structure or evidence references if needed. |
|
Heads up before this waits any longer on review: #182 ( It also carries review feedback that probably applies here too: @bishnubista asked for a version history section on 2026-03-04, and left a review on 2026-03-07 with seven inline comments, three flagged critical, including a citation that doesn't support the claim attached to it. Probably faster to reconcile the two than to wait for a maintainer to spot the collision — either fold your content into #182, or state in this PR why it supersedes it. The "confirmed no open PR or issue currently targets SAF-T1506" line in the description is the first thing a reviewer will check. Context for the drive-by: I work on MCP tool-call policy enforcement — Norviq, https://norviq.dev / https://github.com/norviq-dev/norviq — and hit #182 while reading through the SAF-T15xx range. |
Summary
Validation
detection-rule.ymlsuccessfully as YAMLgit diff --check