Multi-CloudHow-To & HardeningRetrospectives

How to Find and Vault Hardcoded Credentials Across Cloud Services

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.

Hardcoded credentials in scripts, configuration files and repositories are one of the easiest ways for attackers to escalate. Here is how to find them across your cloud environment and move them into a vault.

Step 1: Scan code repositories

  • Enable GitHub secret scanning and push protection (or equivalent in Azure DevOps and GitLab).
  • Scan full repository history with tools such as gitleaks or TruffleHog.

Step 2: Scan infrastructure and configuration

  • Defender for Cloud (Defender CSPM) includes agentless secrets scanning for VMs and can flag exposed secrets on cloud workloads.
  • Check CI/CD variables, deployment templates and container images (image scanners can detect embedded secrets).
  • Check Azure App Service and AWS Lambda environment variables for plain-text secrets.

Step 3: Scan file shares and collaboration

Search SharePoint, OneDrive and Teams for files likely to contain credentials (for example, "password", "credentials", .env, .pem). Microsoft Purview sensitive information types include credential detectors.

Step 4: Rotate everything you find

Treat any discovered credential as compromised. Rotate first, then remove it from the location.

Step 5: Move secrets to a vault

  • Azure Key Vault with managed identities for Azure workloads.
  • AWS Secrets Manager with IAM roles for AWS workloads.
  • Reference secrets at runtime instead of copying them into configuration.

Step 6: Prefer identity over secrets

The best secret is no secret: managed identities, IAM roles, workload identity federation and OIDC remove the need for stored credentials altogether.

Verify

Track the number of exposed secrets found per month. It should fall to near zero, with new detections blocked at commit time.

find hardcoded credentialsVerkada2021

More on this story