azure_scan_azure_devops
Scan Azure DevOps organizations and projects to detect exposed secrets, over-privileged service connections, insecure pipeline configurations, and leaked credentials.
Instructions
Azure DevOps security scanner. Enumerates: organizations, projects, repositories, pipelines, service connections, variable groups, PAT tokens. Checks for: exposed secrets in repos, over-privileged service connections, insecure pipeline configurations, leaked credentials. OFFENSIVE USE: Find deployment credentials, API keys in source code, service principal secrets in pipelines.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| organizationUrl | Yes | Azure DevOps organization URL (e.g., https://dev.azure.com/yourorg) | |
| personalAccessToken | Yes | Personal Access Token (PAT) for authentication - requires Read access to Code, Build, Release | |
| scanRepositories | No | Scan repositories for hardcoded secrets (default: true) | |
| scanPipelines | No | Scan pipelines for exposed credentials (default: true) | |
| format | No | Output format: 'markdown' (default, human-readable) or 'json' (machine-readable) |