Skip to content

Latest commit

History

153 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

PowerShell-CYA

Ciphertext Your Assets

Storing credentials in plain text is generally considered a bad idea. But chances are, if you work in DevOps, you have a few credential files on your system. Or perhaps you store your secrets as environment variables.

A significant vector in supply chain attacks leverages credential stealing malware to gain access to your development pipeline. Keeping your secrets in a "protected by default" mode significantly reduces the likelihood of a successful attack.

CYA aims to protect the config files and environment variables you use. It does so by encrypting the files and environment variable values you want to protect. Then you can simply encrypt and decrypt using Protect-CyaConfig and Unprotect-CyaConfig.

CYA also helps you manage different credentials for different environments.

PS > New-CyaConfig AWSTest
[...]
PS > New-CyaConfig AWSProd
[...]
PS > Unprotect-CyaConfig AWSTest
Enter password for CyaPassword "Default": *********

Quick start

Install CYA

Install-Module CYA

Once installed the following functions are exported and available.

  • New-CyaConfig
  • Get-CyaConfig
  • Protect-CyaConfig (alias pcya)
  • Unprotect-CyaConfig (alias ucya)
  • Rename-CyaConfig
  • Remove-CyaConfig
  • New-CyaPassword
  • Get-CyaPassword
  • Rename-CyaPassword
  • Remove-CyaPassword

Create a config

CYA makes protecting environment variables easy. One big problem with secrets as environment variables is setting them without exposing them in your command history. CYA accomplishes this by using PowerShell's Read-Host -AsSecureString To create a new CyaConfig use New-CyaConfig and follow the prompts.

PS > New-CyaConfig
cmdlet New-CyaConfig at command pipeline position 1
Supply values for the following parameters:
Name: sample
WARNING: CyaPassword "Default" not found, creating now with New-CyaPassword.
Enter new password: ********
Confirm new password: ********
Config type
[E] EnvVar [F] File [?] Help (default is "E"):
Variable 1 name (Enter when done): MYVAR
MYVAR value: *****
Variable 2 name (Enter when done): MYOTHERVAR
MYOTHERVAR value: *****
Variable 3 name (Enter when done):
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYVAR
Status : Protected
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYOTHERVAR
Status : Protected

You can configure CYA to automatically delete unencrypted files when you exit PowerShell by setting the -ProtectOnExit parameter to $True. When you exit PowerShell, or remove the Module, the file will be deleted. Keep in mind, you have to exit cleanly using the exit command or ctrl + d (Linux) for this to work.

PS > Get-ChildItem | New-CyaConfig -Name sample -ProtectOnExit $true
Enter password for CyaPassword "Default": ********
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file1.conf
Status : Unprotected
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file2.json
Status : Unprotected

Use your config

Protect (delete) and unprotect (decrypt) your secrets.

Unprotect-CyaConfig
[... do what you need to do ...]
Protect-CyaConfig

The aliases ucya and pcya are available for convenience.

ucya
[... do what you need to do ...]
pcya

Automatic warnings

CYA presents a warning if any config items are unprotected when the CYA module loads. You can choose to see this warning every time you open a shell by adding Import-Module CYA to your PowerShell Profile.

You can also suppress these warnings by setting the environment variable CYA_DISABLE_UNPROTECTED_MESSAGE to $True.

Different passwords

CYA supports using different passwords on different CyaConfigs using the -CyaPassword parameter. The New-CyaConfig and New-CyaPassword functions use "Default" by default.

Security

CyaConfigs and CyaPasswords are encrypted using AES-256-CBC and can be moved to any system. Your password is all that's needed to decrypt (so make it a good one).

The contents of files and environment variable values are validated using a salted SHA256 hash. If you unprotect a file and modify it, the file's hash will no longer match the hash stored in the config. CYA will not delete the file and will instead show a warning that the file path conflicts. If you wish to protect a modified file, use New-CyaConfig again.

CYAPATH and backups

By Default CYA will store configs, passwords, and encrypted files in a .cya folder in your $Home (~). You can change this location to wherever you like by setting the environment variable CYAPATH to you desired location. You may want to use a cloud synced folder or any location that you can backup. Or you can just backup the defualt .cya folder.

The .cya folder contains three subfolders:

  • configs stores the configs, either EnvVar (environment variable) or File.
  • passwords stores the encrypted keys to the configs you decrypt with your password.
  • bins stores the encrypted files

Modifying CyaConfigs

Configs and Passwords in CYA are largely immutable but that doesn't mean you can't change things. For example, if you want to change your password, you can follow these steps to create a new CyaPassword, new CyaConfig, and remove the old.

Rename-CyaPassword -Name Default -NewName OldDefault
Rename-CyaConfig -Name MyConfig -NewName OldMyConfig
New-CyaPassword -Name Default
Unprotect-CyaConfig -Name OldMyConfig
New-CyaConfig -Name MyConfig -CyaPassword Default
[... Add the files or environment variables from OldMyConfig ...]
Protect-CyaConfig MyConfig
Remove-CyaConfig -Name OldMyConfig
Remove-CyaPassword -Name OldDefault

Or, if you're comfortable, you could make some trivial changes to the config files directly, they are just JSON files. Changing the path to a file, or name of a variable won't break anything.

More help

Help documentation is available for each function in CYA.

Help New-CyaConfig

Development

Running tests

Tests are written in the pester test framework.

Install-Module pester
git clone https://github.com/nickadam/powershell-cya.git
cd powershell-cya
Invoke-Pester

Static code analysis

Install-Module PSScriptAnalyzer
Invoke-ScriptAnalyzer -Recurse .\CYA\

Code coverage reports

Install ReportGenerator.

Find-Package ReportGenerator -ProviderName "nuget" -Source "https://nuget.org/api/v2" | Install-Package -Scope CurrentUser

Identify the location of the relevant ReportGenerator.exe. In my case:

$RG="$LOCALAPPDATA\PackageManagement\NuGet\Packages\ReportGenerator.5.0.4\tools\net6.0\ReportGenerator.exe"

Generate a coverage.xml file with pester.

Invoke-Pester -CodeCoverage ".\CYA\*" -CodeCoverageOutputFileFormat JaCoCo

Generate code coverage report pages.

& $RG -reports:coverage.xml -targetdir:.\Coverage -sourcedirs:.\CYA

Review the beautiful report.

start .\Coverage\index.html

About

Ciphertext Your Assets

Resources

Stars

9 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - nickadam/powershell-cya: Ciphertext Your Assets · GitHub
Skip to content

Latest commit

History

153 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

PowerShell-CYA

Ciphertext Your Assets

Storing credentials in plain text is generally considered a bad idea. But chances are, if you work in DevOps, you have a few credential files on your system. Or perhaps you store your secrets as environment variables.

A significant vector in supply chain attacks leverages credential stealing malware to gain access to your development pipeline. Keeping your secrets in a "protected by default" mode significantly reduces the likelihood of a successful attack.

CYA aims to protect the config files and environment variables you use. It does so by encrypting the files and environment variable values you want to protect. Then you can simply encrypt and decrypt using Protect-CyaConfig and Unprotect-CyaConfig.

CYA also helps you manage different credentials for different environments.

PS > New-CyaConfig AWSTest
[...]
PS > New-CyaConfig AWSProd
[...]
PS > Unprotect-CyaConfig AWSTest
Enter password for CyaPassword "Default": *********

Quick start

Install CYA

Install-Module CYA

Once installed the following functions are exported and available.

  • New-CyaConfig
  • Get-CyaConfig
  • Protect-CyaConfig (alias pcya)
  • Unprotect-CyaConfig (alias ucya)
  • Rename-CyaConfig
  • Remove-CyaConfig
  • New-CyaPassword
  • Get-CyaPassword
  • Rename-CyaPassword
  • Remove-CyaPassword

Create a config

CYA makes protecting environment variables easy. One big problem with secrets as environment variables is setting them without exposing them in your command history. CYA accomplishes this by using PowerShell's Read-Host -AsSecureString To create a new CyaConfig use New-CyaConfig and follow the prompts.

PS > New-CyaConfig
cmdlet New-CyaConfig at command pipeline position 1
Supply values for the following parameters:
Name: sample
WARNING: CyaPassword "Default" not found, creating now with New-CyaPassword.
Enter new password: ********
Confirm new password: ********
Config type
[E] EnvVar [F] File [?] Help (default is "E"):
Variable 1 name (Enter when done): MYVAR
MYVAR value: *****
Variable 2 name (Enter when done): MYOTHERVAR
MYOTHERVAR value: *****
Variable 3 name (Enter when done):
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYVAR
Status : Protected
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYOTHERVAR
Status : Protected

You can configure CYA to automatically delete unencrypted files when you exit PowerShell by setting the -ProtectOnExit parameter to $True. When you exit PowerShell, or remove the Module, the file will be deleted. Keep in mind, you have to exit cleanly using the exit command or ctrl + d (Linux) for this to work.

PS > Get-ChildItem | New-CyaConfig -Name sample -ProtectOnExit $true
Enter password for CyaPassword "Default": ********
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file1.conf
Status : Unprotected
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file2.json
Status : Unprotected

Use your config

Protect (delete) and unprotect (decrypt) your secrets.

Unprotect-CyaConfig
[... do what you need to do ...]
Protect-CyaConfig

The aliases ucya and pcya are available for convenience.

ucya
[... do what you need to do ...]
pcya

Automatic warnings

CYA presents a warning if any config items are unprotected when the CYA module loads. You can choose to see this warning every time you open a shell by adding Import-Module CYA to your PowerShell Profile.

You can also suppress these warnings by setting the environment variable CYA_DISABLE_UNPROTECTED_MESSAGE to $True.

Different passwords

CYA supports using different passwords on different CyaConfigs using the -CyaPassword parameter. The New-CyaConfig and New-CyaPassword functions use "Default" by default.

Security

CyaConfigs and CyaPasswords are encrypted using AES-256-CBC and can be moved to any system. Your password is all that's needed to decrypt (so make it a good one).

The contents of files and environment variable values are validated using a salted SHA256 hash. If you unprotect a file and modify it, the file's hash will no longer match the hash stored in the config. CYA will not delete the file and will instead show a warning that the file path conflicts. If you wish to protect a modified file, use New-CyaConfig again.

CYAPATH and backups

By Default CYA will store configs, passwords, and encrypted files in a .cya folder in your $Home (~). You can change this location to wherever you like by setting the environment variable CYAPATH to you desired location. You may want to use a cloud synced folder or any location that you can backup. Or you can just backup the defualt .cya folder.

The .cya folder contains three subfolders:

  • configs stores the configs, either EnvVar (environment variable) or File.
  • passwords stores the encrypted keys to the configs you decrypt with your password.
  • bins stores the encrypted files

Modifying CyaConfigs

Configs and Passwords in CYA are largely immutable but that doesn't mean you can't change things. For example, if you want to change your password, you can follow these steps to create a new CyaPassword, new CyaConfig, and remove the old.

Rename-CyaPassword -Name Default -NewName OldDefault
Rename-CyaConfig -Name MyConfig -NewName OldMyConfig
New-CyaPassword -Name Default
Unprotect-CyaConfig -Name OldMyConfig
New-CyaConfig -Name MyConfig -CyaPassword Default
[... Add the files or environment variables from OldMyConfig ...]
Protect-CyaConfig MyConfig
Remove-CyaConfig -Name OldMyConfig
Remove-CyaPassword -Name OldDefault

Or, if you're comfortable, you could make some trivial changes to the config files directly, they are just JSON files. Changing the path to a file, or name of a variable won't break anything.

More help

Help documentation is available for each function in CYA.

Help New-CyaConfig

Development

Running tests

Tests are written in the pester test framework.

Install-Module pester
git clone https://github.com/nickadam/powershell-cya.git
cd powershell-cya
Invoke-Pester

Static code analysis

Install-Module PSScriptAnalyzer
Invoke-ScriptAnalyzer -Recurse .\CYA\

Code coverage reports

Install ReportGenerator.

Find-Package ReportGenerator -ProviderName "nuget" -Source "https://nuget.org/api/v2" | Install-Package -Scope CurrentUser

Identify the location of the relevant ReportGenerator.exe. In my case:

$RG="$LOCALAPPDATA\PackageManagement\NuGet\Packages\ReportGenerator.5.0.4\tools\net6.0\ReportGenerator.exe"

Generate a coverage.xml file with pester.

Invoke-Pester -CodeCoverage ".\CYA\*" -CodeCoverageOutputFileFormat JaCoCo

Generate code coverage report pages.

& $RG -reports:coverage.xml -targetdir:.\Coverage -sourcedirs:.\CYA

Review the beautiful report.

start .\Coverage\index.html

About

Ciphertext Your Assets

Resources

Stars

9 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - nickadam/powershell-cya: Ciphertext Your Assets · GitHub
Skip to content

Latest commit

History

153 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

PowerShell-CYA

Ciphertext Your Assets

Storing credentials in plain text is generally considered a bad idea. But chances are, if you work in DevOps, you have a few credential files on your system. Or perhaps you store your secrets as environment variables.

A significant vector in supply chain attacks leverages credential stealing malware to gain access to your development pipeline. Keeping your secrets in a "protected by default" mode significantly reduces the likelihood of a successful attack.

CYA aims to protect the config files and environment variables you use. It does so by encrypting the files and environment variable values you want to protect. Then you can simply encrypt and decrypt using Protect-CyaConfig and Unprotect-CyaConfig.

CYA also helps you manage different credentials for different environments.

PS > New-CyaConfig AWSTest
[...]
PS > New-CyaConfig AWSProd
[...]
PS > Unprotect-CyaConfig AWSTest
Enter password for CyaPassword "Default": *********

Quick start

Install CYA

Install-Module CYA

Once installed the following functions are exported and available.

  • New-CyaConfig
  • Get-CyaConfig
  • Protect-CyaConfig (alias pcya)
  • Unprotect-CyaConfig (alias ucya)
  • Rename-CyaConfig
  • Remove-CyaConfig
  • New-CyaPassword
  • Get-CyaPassword
  • Rename-CyaPassword
  • Remove-CyaPassword

Create a config

CYA makes protecting environment variables easy. One big problem with secrets as environment variables is setting them without exposing them in your command history. CYA accomplishes this by using PowerShell's Read-Host -AsSecureString To create a new CyaConfig use New-CyaConfig and follow the prompts.

PS > New-CyaConfig
cmdlet New-CyaConfig at command pipeline position 1
Supply values for the following parameters:
Name: sample
WARNING: CyaPassword "Default" not found, creating now with New-CyaPassword.
Enter new password: ********
Confirm new password: ********
Config type
[E] EnvVar [F] File [?] Help (default is "E"):
Variable 1 name (Enter when done): MYVAR
MYVAR value: *****
Variable 2 name (Enter when done): MYOTHERVAR
MYOTHERVAR value: *****
Variable 3 name (Enter when done):
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYVAR
Status : Protected
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYOTHERVAR
Status : Protected

You can configure CYA to automatically delete unencrypted files when you exit PowerShell by setting the -ProtectOnExit parameter to $True. When you exit PowerShell, or remove the Module, the file will be deleted. Keep in mind, you have to exit cleanly using the exit command or ctrl + d (Linux) for this to work.

PS > Get-ChildItem | New-CyaConfig -Name sample -ProtectOnExit $true
Enter password for CyaPassword "Default": ********
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file1.conf
Status : Unprotected
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file2.json
Status : Unprotected

Use your config

Protect (delete) and unprotect (decrypt) your secrets.

Unprotect-CyaConfig
[... do what you need to do ...]
Protect-CyaConfig

The aliases ucya and pcya are available for convenience.

ucya
[... do what you need to do ...]
pcya

Automatic warnings

CYA presents a warning if any config items are unprotected when the CYA module loads. You can choose to see this warning every time you open a shell by adding Import-Module CYA to your PowerShell Profile.

You can also suppress these warnings by setting the environment variable CYA_DISABLE_UNPROTECTED_MESSAGE to $True.

Different passwords

CYA supports using different passwords on different CyaConfigs using the -CyaPassword parameter. The New-CyaConfig and New-CyaPassword functions use "Default" by default.

Security

CyaConfigs and CyaPasswords are encrypted using AES-256-CBC and can be moved to any system. Your password is all that's needed to decrypt (so make it a good one).

The contents of files and environment variable values are validated using a salted SHA256 hash. If you unprotect a file and modify it, the file's hash will no longer match the hash stored in the config. CYA will not delete the file and will instead show a warning that the file path conflicts. If you wish to protect a modified file, use New-CyaConfig again.

CYAPATH and backups

By Default CYA will store configs, passwords, and encrypted files in a .cya folder in your $Home (~). You can change this location to wherever you like by setting the environment variable CYAPATH to you desired location. You may want to use a cloud synced folder or any location that you can backup. Or you can just backup the defualt .cya folder.

The .cya folder contains three subfolders:

  • configs stores the configs, either EnvVar (environment variable) or File.
  • passwords stores the encrypted keys to the configs you decrypt with your password.
  • bins stores the encrypted files

Modifying CyaConfigs

Configs and Passwords in CYA are largely immutable but that doesn't mean you can't change things. For example, if you want to change your password, you can follow these steps to create a new CyaPassword, new CyaConfig, and remove the old.

Rename-CyaPassword -Name Default -NewName OldDefault
Rename-CyaConfig -Name MyConfig -NewName OldMyConfig
New-CyaPassword -Name Default
Unprotect-CyaConfig -Name OldMyConfig
New-CyaConfig -Name MyConfig -CyaPassword Default
[... Add the files or environment variables from OldMyConfig ...]
Protect-CyaConfig MyConfig
Remove-CyaConfig -Name OldMyConfig
Remove-CyaPassword -Name OldDefault

Or, if you're comfortable, you could make some trivial changes to the config files directly, they are just JSON files. Changing the path to a file, or name of a variable won't break anything.

More help

Help documentation is available for each function in CYA.

Help New-CyaConfig

Development

Running tests

Tests are written in the pester test framework.

Install-Module pester
git clone https://github.com/nickadam/powershell-cya.git
cd powershell-cya
Invoke-Pester

Static code analysis

Install-Module PSScriptAnalyzer
Invoke-ScriptAnalyzer -Recurse .\CYA\

Code coverage reports

Install ReportGenerator.

Find-Package ReportGenerator -ProviderName "nuget" -Source "https://nuget.org/api/v2" | Install-Package -Scope CurrentUser

Identify the location of the relevant ReportGenerator.exe. In my case:

$RG="$LOCALAPPDATA\PackageManagement\NuGet\Packages\ReportGenerator.5.0.4\tools\net6.0\ReportGenerator.exe"

Generate a coverage.xml file with pester.

Invoke-Pester -CodeCoverage ".\CYA\*" -CodeCoverageOutputFileFormat JaCoCo

Generate code coverage report pages.

& $RG -reports:coverage.xml -targetdir:.\Coverage -sourcedirs:.\CYA

Review the beautiful report.

start .\Coverage\index.html

About

Ciphertext Your Assets

Resources

Stars

9 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - nickadam/powershell-cya: Ciphertext Your Assets · GitHub
Skip to content

Latest commit

History

153 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

PowerShell-CYA

Ciphertext Your Assets

Storing credentials in plain text is generally considered a bad idea. But chances are, if you work in DevOps, you have a few credential files on your system. Or perhaps you store your secrets as environment variables.

A significant vector in supply chain attacks leverages credential stealing malware to gain access to your development pipeline. Keeping your secrets in a "protected by default" mode significantly reduces the likelihood of a successful attack.

CYA aims to protect the config files and environment variables you use. It does so by encrypting the files and environment variable values you want to protect. Then you can simply encrypt and decrypt using Protect-CyaConfig and Unprotect-CyaConfig.

CYA also helps you manage different credentials for different environments.

PS > New-CyaConfig AWSTest
[...]
PS > New-CyaConfig AWSProd
[...]
PS > Unprotect-CyaConfig AWSTest
Enter password for CyaPassword "Default": *********

Quick start

Install CYA

Install-Module CYA

Once installed the following functions are exported and available.

  • New-CyaConfig
  • Get-CyaConfig
  • Protect-CyaConfig (alias pcya)
  • Unprotect-CyaConfig (alias ucya)
  • Rename-CyaConfig
  • Remove-CyaConfig
  • New-CyaPassword
  • Get-CyaPassword
  • Rename-CyaPassword
  • Remove-CyaPassword

Create a config

CYA makes protecting environment variables easy. One big problem with secrets as environment variables is setting them without exposing them in your command history. CYA accomplishes this by using PowerShell's Read-Host -AsSecureString To create a new CyaConfig use New-CyaConfig and follow the prompts.

PS > New-CyaConfig
cmdlet New-CyaConfig at command pipeline position 1
Supply values for the following parameters:
Name: sample
WARNING: CyaPassword "Default" not found, creating now with New-CyaPassword.
Enter new password: ********
Confirm new password: ********
Config type
[E] EnvVar [F] File [?] Help (default is "E"):
Variable 1 name (Enter when done): MYVAR
MYVAR value: *****
Variable 2 name (Enter when done): MYOTHERVAR
MYOTHERVAR value: *****
Variable 3 name (Enter when done):
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYVAR
Status : Protected
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYOTHERVAR
Status : Protected

You can configure CYA to automatically delete unencrypted files when you exit PowerShell by setting the -ProtectOnExit parameter to $True. When you exit PowerShell, or remove the Module, the file will be deleted. Keep in mind, you have to exit cleanly using the exit command or ctrl + d (Linux) for this to work.

PS > Get-ChildItem | New-CyaConfig -Name sample -ProtectOnExit $true
Enter password for CyaPassword "Default": ********
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file1.conf
Status : Unprotected
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file2.json
Status : Unprotected

Use your config

Protect (delete) and unprotect (decrypt) your secrets.

Unprotect-CyaConfig
[... do what you need to do ...]
Protect-CyaConfig

The aliases ucya and pcya are available for convenience.

ucya
[... do what you need to do ...]
pcya

Automatic warnings

CYA presents a warning if any config items are unprotected when the CYA module loads. You can choose to see this warning every time you open a shell by adding Import-Module CYA to your PowerShell Profile.

You can also suppress these warnings by setting the environment variable CYA_DISABLE_UNPROTECTED_MESSAGE to $True.

Different passwords

CYA supports using different passwords on different CyaConfigs using the -CyaPassword parameter. The New-CyaConfig and New-CyaPassword functions use "Default" by default.

Security

CyaConfigs and CyaPasswords are encrypted using AES-256-CBC and can be moved to any system. Your password is all that's needed to decrypt (so make it a good one).

The contents of files and environment variable values are validated using a salted SHA256 hash. If you unprotect a file and modify it, the file's hash will no longer match the hash stored in the config. CYA will not delete the file and will instead show a warning that the file path conflicts. If you wish to protect a modified file, use New-CyaConfig again.

CYAPATH and backups

By Default CYA will store configs, passwords, and encrypted files in a .cya folder in your $Home (~). You can change this location to wherever you like by setting the environment variable CYAPATH to you desired location. You may want to use a cloud synced folder or any location that you can backup. Or you can just backup the defualt .cya folder.

The .cya folder contains three subfolders:

  • configs stores the configs, either EnvVar (environment variable) or File.
  • passwords stores the encrypted keys to the configs you decrypt with your password.
  • bins stores the encrypted files

Modifying CyaConfigs

Configs and Passwords in CYA are largely immutable but that doesn't mean you can't change things. For example, if you want to change your password, you can follow these steps to create a new CyaPassword, new CyaConfig, and remove the old.

Rename-CyaPassword -Name Default -NewName OldDefault
Rename-CyaConfig -Name MyConfig -NewName OldMyConfig
New-CyaPassword -Name Default
Unprotect-CyaConfig -Name OldMyConfig
New-CyaConfig -Name MyConfig -CyaPassword Default
[... Add the files or environment variables from OldMyConfig ...]
Protect-CyaConfig MyConfig
Remove-CyaConfig -Name OldMyConfig
Remove-CyaPassword -Name OldDefault

Or, if you're comfortable, you could make some trivial changes to the config files directly, they are just JSON files. Changing the path to a file, or name of a variable won't break anything.

More help

Help documentation is available for each function in CYA.

Help New-CyaConfig

Development

Running tests

Tests are written in the pester test framework.

Install-Module pester
git clone https://github.com/nickadam/powershell-cya.git
cd powershell-cya
Invoke-Pester

Static code analysis

Install-Module PSScriptAnalyzer
Invoke-ScriptAnalyzer -Recurse .\CYA\

Code coverage reports

Install ReportGenerator.

Find-Package ReportGenerator -ProviderName "nuget" -Source "https://nuget.org/api/v2" | Install-Package -Scope CurrentUser

Identify the location of the relevant ReportGenerator.exe. In my case:

$RG="$LOCALAPPDATA\PackageManagement\NuGet\Packages\ReportGenerator.5.0.4\tools\net6.0\ReportGenerator.exe"

Generate a coverage.xml file with pester.

Invoke-Pester -CodeCoverage ".\CYA\*" -CodeCoverageOutputFileFormat JaCoCo

Generate code coverage report pages.

& $RG -reports:coverage.xml -targetdir:.\Coverage -sourcedirs:.\CYA

Review the beautiful report.

start .\Coverage\index.html

About

Ciphertext Your Assets

Resources

Stars

9 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - nickadam/powershell-cya: Ciphertext Your Assets · GitHub
Skip to content

Latest commit

History

153 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

PowerShell-CYA

Ciphertext Your Assets

Storing credentials in plain text is generally considered a bad idea. But chances are, if you work in DevOps, you have a few credential files on your system. Or perhaps you store your secrets as environment variables.

A significant vector in supply chain attacks leverages credential stealing malware to gain access to your development pipeline. Keeping your secrets in a "protected by default" mode significantly reduces the likelihood of a successful attack.

CYA aims to protect the config files and environment variables you use. It does so by encrypting the files and environment variable values you want to protect. Then you can simply encrypt and decrypt using Protect-CyaConfig and Unprotect-CyaConfig.

CYA also helps you manage different credentials for different environments.

PS > New-CyaConfig AWSTest
[...]
PS > New-CyaConfig AWSProd
[...]
PS > Unprotect-CyaConfig AWSTest
Enter password for CyaPassword "Default": *********

Quick start

Install CYA

Install-Module CYA

Once installed the following functions are exported and available.

  • New-CyaConfig
  • Get-CyaConfig
  • Protect-CyaConfig (alias pcya)
  • Unprotect-CyaConfig (alias ucya)
  • Rename-CyaConfig
  • Remove-CyaConfig
  • New-CyaPassword
  • Get-CyaPassword
  • Rename-CyaPassword
  • Remove-CyaPassword

Create a config

CYA makes protecting environment variables easy. One big problem with secrets as environment variables is setting them without exposing them in your command history. CYA accomplishes this by using PowerShell's Read-Host -AsSecureString To create a new CyaConfig use New-CyaConfig and follow the prompts.

PS > New-CyaConfig
cmdlet New-CyaConfig at command pipeline position 1
Supply values for the following parameters:
Name: sample
WARNING: CyaPassword "Default" not found, creating now with New-CyaPassword.
Enter new password: ********
Confirm new password: ********
Config type
[E] EnvVar [F] File [?] Help (default is "E"):
Variable 1 name (Enter when done): MYVAR
MYVAR value: *****
Variable 2 name (Enter when done): MYOTHERVAR
MYOTHERVAR value: *****
Variable 3 name (Enter when done):
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYVAR
Status : Protected
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYOTHERVAR
Status : Protected

You can configure CYA to automatically delete unencrypted files when you exit PowerShell by setting the -ProtectOnExit parameter to $True. When you exit PowerShell, or remove the Module, the file will be deleted. Keep in mind, you have to exit cleanly using the exit command or ctrl + d (Linux) for this to work.

PS > Get-ChildItem | New-CyaConfig -Name sample -ProtectOnExit $true
Enter password for CyaPassword "Default": ********
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file1.conf
Status : Unprotected
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file2.json
Status : Unprotected

Use your config

Protect (delete) and unprotect (decrypt) your secrets.

Unprotect-CyaConfig
[... do what you need to do ...]
Protect-CyaConfig

The aliases ucya and pcya are available for convenience.

ucya
[... do what you need to do ...]
pcya

Automatic warnings

CYA presents a warning if any config items are unprotected when the CYA module loads. You can choose to see this warning every time you open a shell by adding Import-Module CYA to your PowerShell Profile.

You can also suppress these warnings by setting the environment variable CYA_DISABLE_UNPROTECTED_MESSAGE to $True.

Different passwords

CYA supports using different passwords on different CyaConfigs using the -CyaPassword parameter. The New-CyaConfig and New-CyaPassword functions use "Default" by default.

Security

CyaConfigs and CyaPasswords are encrypted using AES-256-CBC and can be moved to any system. Your password is all that's needed to decrypt (so make it a good one).

The contents of files and environment variable values are validated using a salted SHA256 hash. If you unprotect a file and modify it, the file's hash will no longer match the hash stored in the config. CYA will not delete the file and will instead show a warning that the file path conflicts. If you wish to protect a modified file, use New-CyaConfig again.

CYAPATH and backups

By Default CYA will store configs, passwords, and encrypted files in a .cya folder in your $Home (~). You can change this location to wherever you like by setting the environment variable CYAPATH to you desired location. You may want to use a cloud synced folder or any location that you can backup. Or you can just backup the defualt .cya folder.

The .cya folder contains three subfolders:

  • configs stores the configs, either EnvVar (environment variable) or File.
  • passwords stores the encrypted keys to the configs you decrypt with your password.
  • bins stores the encrypted files

Modifying CyaConfigs

Configs and Passwords in CYA are largely immutable but that doesn't mean you can't change things. For example, if you want to change your password, you can follow these steps to create a new CyaPassword, new CyaConfig, and remove the old.

Rename-CyaPassword -Name Default -NewName OldDefault
Rename-CyaConfig -Name MyConfig -NewName OldMyConfig
New-CyaPassword -Name Default
Unprotect-CyaConfig -Name OldMyConfig
New-CyaConfig -Name MyConfig -CyaPassword Default
[... Add the files or environment variables from OldMyConfig ...]
Protect-CyaConfig MyConfig
Remove-CyaConfig -Name OldMyConfig
Remove-CyaPassword -Name OldDefault

Or, if you're comfortable, you could make some trivial changes to the config files directly, they are just JSON files. Changing the path to a file, or name of a variable won't break anything.

More help

Help documentation is available for each function in CYA.

Help New-CyaConfig

Development

Running tests

Tests are written in the pester test framework.

Install-Module pester
git clone https://github.com/nickadam/powershell-cya.git
cd powershell-cya
Invoke-Pester

Static code analysis

Install-Module PSScriptAnalyzer
Invoke-ScriptAnalyzer -Recurse .\CYA\

Code coverage reports

Install ReportGenerator.

Find-Package ReportGenerator -ProviderName "nuget" -Source "https://nuget.org/api/v2" | Install-Package -Scope CurrentUser

Identify the location of the relevant ReportGenerator.exe. In my case:

$RG="$LOCALAPPDATA\PackageManagement\NuGet\Packages\ReportGenerator.5.0.4\tools\net6.0\ReportGenerator.exe"

Generate a coverage.xml file with pester.

Invoke-Pester -CodeCoverage ".\CYA\*" -CodeCoverageOutputFileFormat JaCoCo

Generate code coverage report pages.

& $RG -reports:coverage.xml -targetdir:.\Coverage -sourcedirs:.\CYA

Review the beautiful report.

start .\Coverage\index.html

About

Ciphertext Your Assets

Resources

Stars

9 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - nickadam/powershell-cya: Ciphertext Your Assets · GitHub
Skip to content

Latest commit

History

153 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

PowerShell-CYA

Ciphertext Your Assets

Storing credentials in plain text is generally considered a bad idea. But chances are, if you work in DevOps, you have a few credential files on your system. Or perhaps you store your secrets as environment variables.

A significant vector in supply chain attacks leverages credential stealing malware to gain access to your development pipeline. Keeping your secrets in a "protected by default" mode significantly reduces the likelihood of a successful attack.

CYA aims to protect the config files and environment variables you use. It does so by encrypting the files and environment variable values you want to protect. Then you can simply encrypt and decrypt using Protect-CyaConfig and Unprotect-CyaConfig.

CYA also helps you manage different credentials for different environments.

PS > New-CyaConfig AWSTest
[...]
PS > New-CyaConfig AWSProd
[...]
PS > Unprotect-CyaConfig AWSTest
Enter password for CyaPassword "Default": *********

Quick start

Install CYA

Install-Module CYA

Once installed the following functions are exported and available.

  • New-CyaConfig
  • Get-CyaConfig
  • Protect-CyaConfig (alias pcya)
  • Unprotect-CyaConfig (alias ucya)
  • Rename-CyaConfig
  • Remove-CyaConfig
  • New-CyaPassword
  • Get-CyaPassword
  • Rename-CyaPassword
  • Remove-CyaPassword

Create a config

CYA makes protecting environment variables easy. One big problem with secrets as environment variables is setting them without exposing them in your command history. CYA accomplishes this by using PowerShell's Read-Host -AsSecureString To create a new CyaConfig use New-CyaConfig and follow the prompts.

PS > New-CyaConfig
cmdlet New-CyaConfig at command pipeline position 1
Supply values for the following parameters:
Name: sample
WARNING: CyaPassword "Default" not found, creating now with New-CyaPassword.
Enter new password: ********
Confirm new password: ********
Config type
[E] EnvVar [F] File [?] Help (default is "E"):
Variable 1 name (Enter when done): MYVAR
MYVAR value: *****
Variable 2 name (Enter when done): MYOTHERVAR
MYOTHERVAR value: *****
Variable 3 name (Enter when done):
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYVAR
Status : Protected
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYOTHERVAR
Status : Protected

You can configure CYA to automatically delete unencrypted files when you exit PowerShell by setting the -ProtectOnExit parameter to $True. When you exit PowerShell, or remove the Module, the file will be deleted. Keep in mind, you have to exit cleanly using the exit command or ctrl + d (Linux) for this to work.

PS > Get-ChildItem | New-CyaConfig -Name sample -ProtectOnExit $true
Enter password for CyaPassword "Default": ********
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file1.conf
Status : Unprotected
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file2.json
Status : Unprotected

Use your config

Protect (delete) and unprotect (decrypt) your secrets.

Unprotect-CyaConfig
[... do what you need to do ...]
Protect-CyaConfig

The aliases ucya and pcya are available for convenience.

ucya
[... do what you need to do ...]
pcya

Automatic warnings

CYA presents a warning if any config items are unprotected when the CYA module loads. You can choose to see this warning every time you open a shell by adding Import-Module CYA to your PowerShell Profile.

You can also suppress these warnings by setting the environment variable CYA_DISABLE_UNPROTECTED_MESSAGE to $True.

Different passwords

CYA supports using different passwords on different CyaConfigs using the -CyaPassword parameter. The New-CyaConfig and New-CyaPassword functions use "Default" by default.

Security

CyaConfigs and CyaPasswords are encrypted using AES-256-CBC and can be moved to any system. Your password is all that's needed to decrypt (so make it a good one).

The contents of files and environment variable values are validated using a salted SHA256 hash. If you unprotect a file and modify it, the file's hash will no longer match the hash stored in the config. CYA will not delete the file and will instead show a warning that the file path conflicts. If you wish to protect a modified file, use New-CyaConfig again.

CYAPATH and backups

By Default CYA will store configs, passwords, and encrypted files in a .cya folder in your $Home (~). You can change this location to wherever you like by setting the environment variable CYAPATH to you desired location. You may want to use a cloud synced folder or any location that you can backup. Or you can just backup the defualt .cya folder.

The .cya folder contains three subfolders:

  • configs stores the configs, either EnvVar (environment variable) or File.
  • passwords stores the encrypted keys to the configs you decrypt with your password.
  • bins stores the encrypted files

Modifying CyaConfigs

Configs and Passwords in CYA are largely immutable but that doesn't mean you can't change things. For example, if you want to change your password, you can follow these steps to create a new CyaPassword, new CyaConfig, and remove the old.

Rename-CyaPassword -Name Default -NewName OldDefault
Rename-CyaConfig -Name MyConfig -NewName OldMyConfig
New-CyaPassword -Name Default
Unprotect-CyaConfig -Name OldMyConfig
New-CyaConfig -Name MyConfig -CyaPassword Default
[... Add the files or environment variables from OldMyConfig ...]
Protect-CyaConfig MyConfig
Remove-CyaConfig -Name OldMyConfig
Remove-CyaPassword -Name OldDefault

Or, if you're comfortable, you could make some trivial changes to the config files directly, they are just JSON files. Changing the path to a file, or name of a variable won't break anything.

More help

Help documentation is available for each function in CYA.

Help New-CyaConfig

Development

Running tests

Tests are written in the pester test framework.

Install-Module pester
git clone https://github.com/nickadam/powershell-cya.git
cd powershell-cya
Invoke-Pester

Static code analysis

Install-Module PSScriptAnalyzer
Invoke-ScriptAnalyzer -Recurse .\CYA\

Code coverage reports

Install ReportGenerator.

Find-Package ReportGenerator -ProviderName "nuget" -Source "https://nuget.org/api/v2" | Install-Package -Scope CurrentUser

Identify the location of the relevant ReportGenerator.exe. In my case:

$RG="$LOCALAPPDATA\PackageManagement\NuGet\Packages\ReportGenerator.5.0.4\tools\net6.0\ReportGenerator.exe"

Generate a coverage.xml file with pester.

Invoke-Pester -CodeCoverage ".\CYA\*" -CodeCoverageOutputFileFormat JaCoCo

Generate code coverage report pages.

& $RG -reports:coverage.xml -targetdir:.\Coverage -sourcedirs:.\CYA

Review the beautiful report.

start .\Coverage\index.html

About

Ciphertext Your Assets

Resources

Stars

9 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - nickadam/powershell-cya: Ciphertext Your Assets · GitHub
Skip to content

Latest commit

History

153 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

PowerShell-CYA

Ciphertext Your Assets

Storing credentials in plain text is generally considered a bad idea. But chances are, if you work in DevOps, you have a few credential files on your system. Or perhaps you store your secrets as environment variables.

A significant vector in supply chain attacks leverages credential stealing malware to gain access to your development pipeline. Keeping your secrets in a "protected by default" mode significantly reduces the likelihood of a successful attack.

CYA aims to protect the config files and environment variables you use. It does so by encrypting the files and environment variable values you want to protect. Then you can simply encrypt and decrypt using Protect-CyaConfig and Unprotect-CyaConfig.

CYA also helps you manage different credentials for different environments.

PS > New-CyaConfig AWSTest
[...]
PS > New-CyaConfig AWSProd
[...]
PS > Unprotect-CyaConfig AWSTest
Enter password for CyaPassword "Default": *********

Quick start

Install CYA

Install-Module CYA

Once installed the following functions are exported and available.

  • New-CyaConfig
  • Get-CyaConfig
  • Protect-CyaConfig (alias pcya)
  • Unprotect-CyaConfig (alias ucya)
  • Rename-CyaConfig
  • Remove-CyaConfig
  • New-CyaPassword
  • Get-CyaPassword
  • Rename-CyaPassword
  • Remove-CyaPassword

Create a config

CYA makes protecting environment variables easy. One big problem with secrets as environment variables is setting them without exposing them in your command history. CYA accomplishes this by using PowerShell's Read-Host -AsSecureString To create a new CyaConfig use New-CyaConfig and follow the prompts.

PS > New-CyaConfig
cmdlet New-CyaConfig at command pipeline position 1
Supply values for the following parameters:
Name: sample
WARNING: CyaPassword "Default" not found, creating now with New-CyaPassword.
Enter new password: ********
Confirm new password: ********
Config type
[E] EnvVar [F] File [?] Help (default is "E"):
Variable 1 name (Enter when done): MYVAR
MYVAR value: *****
Variable 2 name (Enter when done): MYOTHERVAR
MYOTHERVAR value: *****
Variable 3 name (Enter when done):
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYVAR
Status : Protected
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYOTHERVAR
Status : Protected

You can configure CYA to automatically delete unencrypted files when you exit PowerShell by setting the -ProtectOnExit parameter to $True. When you exit PowerShell, or remove the Module, the file will be deleted. Keep in mind, you have to exit cleanly using the exit command or ctrl + d (Linux) for this to work.

PS > Get-ChildItem | New-CyaConfig -Name sample -ProtectOnExit $true
Enter password for CyaPassword "Default": ********
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file1.conf
Status : Unprotected
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file2.json
Status : Unprotected

Use your config

Protect (delete) and unprotect (decrypt) your secrets.

Unprotect-CyaConfig
[... do what you need to do ...]
Protect-CyaConfig

The aliases ucya and pcya are available for convenience.

ucya
[... do what you need to do ...]
pcya

Automatic warnings

CYA presents a warning if any config items are unprotected when the CYA module loads. You can choose to see this warning every time you open a shell by adding Import-Module CYA to your PowerShell Profile.

You can also suppress these warnings by setting the environment variable CYA_DISABLE_UNPROTECTED_MESSAGE to $True.

Different passwords

CYA supports using different passwords on different CyaConfigs using the -CyaPassword parameter. The New-CyaConfig and New-CyaPassword functions use "Default" by default.

Security

CyaConfigs and CyaPasswords are encrypted using AES-256-CBC and can be moved to any system. Your password is all that's needed to decrypt (so make it a good one).

The contents of files and environment variable values are validated using a salted SHA256 hash. If you unprotect a file and modify it, the file's hash will no longer match the hash stored in the config. CYA will not delete the file and will instead show a warning that the file path conflicts. If you wish to protect a modified file, use New-CyaConfig again.

CYAPATH and backups

By Default CYA will store configs, passwords, and encrypted files in a .cya folder in your $Home (~). You can change this location to wherever you like by setting the environment variable CYAPATH to you desired location. You may want to use a cloud synced folder or any location that you can backup. Or you can just backup the defualt .cya folder.

The .cya folder contains three subfolders:

  • configs stores the configs, either EnvVar (environment variable) or File.
  • passwords stores the encrypted keys to the configs you decrypt with your password.
  • bins stores the encrypted files

Modifying CyaConfigs

Configs and Passwords in CYA are largely immutable but that doesn't mean you can't change things. For example, if you want to change your password, you can follow these steps to create a new CyaPassword, new CyaConfig, and remove the old.

Rename-CyaPassword -Name Default -NewName OldDefault
Rename-CyaConfig -Name MyConfig -NewName OldMyConfig
New-CyaPassword -Name Default
Unprotect-CyaConfig -Name OldMyConfig
New-CyaConfig -Name MyConfig -CyaPassword Default
[... Add the files or environment variables from OldMyConfig ...]
Protect-CyaConfig MyConfig
Remove-CyaConfig -Name OldMyConfig
Remove-CyaPassword -Name OldDefault

Or, if you're comfortable, you could make some trivial changes to the config files directly, they are just JSON files. Changing the path to a file, or name of a variable won't break anything.

More help

Help documentation is available for each function in CYA.

Help New-CyaConfig

Development

Running tests

Tests are written in the pester test framework.

Install-Module pester
git clone https://github.com/nickadam/powershell-cya.git
cd powershell-cya
Invoke-Pester

Static code analysis

Install-Module PSScriptAnalyzer
Invoke-ScriptAnalyzer -Recurse .\CYA\

Code coverage reports

Install ReportGenerator.

Find-Package ReportGenerator -ProviderName "nuget" -Source "https://nuget.org/api/v2" | Install-Package -Scope CurrentUser

Identify the location of the relevant ReportGenerator.exe. In my case:

$RG="$LOCALAPPDATA\PackageManagement\NuGet\Packages\ReportGenerator.5.0.4\tools\net6.0\ReportGenerator.exe"

Generate a coverage.xml file with pester.

Invoke-Pester -CodeCoverage ".\CYA\*" -CodeCoverageOutputFileFormat JaCoCo

Generate code coverage report pages.

& $RG -reports:coverage.xml -targetdir:.\Coverage -sourcedirs:.\CYA

Review the beautiful report.

start .\Coverage\index.html

About

Ciphertext Your Assets

Resources

Stars

9 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - nickadam/powershell-cya: Ciphertext Your Assets · GitHub
Skip to content

Latest commit

History

153 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

PowerShell-CYA

Ciphertext Your Assets

Storing credentials in plain text is generally considered a bad idea. But chances are, if you work in DevOps, you have a few credential files on your system. Or perhaps you store your secrets as environment variables.

A significant vector in supply chain attacks leverages credential stealing malware to gain access to your development pipeline. Keeping your secrets in a "protected by default" mode significantly reduces the likelihood of a successful attack.

CYA aims to protect the config files and environment variables you use. It does so by encrypting the files and environment variable values you want to protect. Then you can simply encrypt and decrypt using Protect-CyaConfig and Unprotect-CyaConfig.

CYA also helps you manage different credentials for different environments.

PS > New-CyaConfig AWSTest
[...]
PS > New-CyaConfig AWSProd
[...]
PS > Unprotect-CyaConfig AWSTest
Enter password for CyaPassword "Default": *********

Quick start

Install CYA

Install-Module CYA

Once installed the following functions are exported and available.

  • New-CyaConfig
  • Get-CyaConfig
  • Protect-CyaConfig (alias pcya)
  • Unprotect-CyaConfig (alias ucya)
  • Rename-CyaConfig
  • Remove-CyaConfig
  • New-CyaPassword
  • Get-CyaPassword
  • Rename-CyaPassword
  • Remove-CyaPassword

Create a config

CYA makes protecting environment variables easy. One big problem with secrets as environment variables is setting them without exposing them in your command history. CYA accomplishes this by using PowerShell's Read-Host -AsSecureString To create a new CyaConfig use New-CyaConfig and follow the prompts.

PS > New-CyaConfig
cmdlet New-CyaConfig at command pipeline position 1
Supply values for the following parameters:
Name: sample
WARNING: CyaPassword "Default" not found, creating now with New-CyaPassword.
Enter new password: ********
Confirm new password: ********
Config type
[E] EnvVar [F] File [?] Help (default is "E"):
Variable 1 name (Enter when done): MYVAR
MYVAR value: *****
Variable 2 name (Enter when done): MYOTHERVAR
MYOTHERVAR value: *****
Variable 3 name (Enter when done):
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYVAR
Status : Protected
Name : sample
Type : EnvVar
CyaPassword : Default
ProtectOnExit : True
Item : MYOTHERVAR
Status : Protected

You can configure CYA to automatically delete unencrypted files when you exit PowerShell by setting the -ProtectOnExit parameter to $True. When you exit PowerShell, or remove the Module, the file will be deleted. Keep in mind, you have to exit cleanly using the exit command or ctrl + d (Linux) for this to work.

PS > Get-ChildItem | New-CyaConfig -Name sample -ProtectOnExit $true
Enter password for CyaPassword "Default": ********
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file1.conf
Status : Unprotected
Name : sample
Type : File
CyaPassword : Default
ProtectOnExit : True
Item : C:\Users\nickadam\sample\file2.json
Status : Unprotected

Use your config

Protect (delete) and unprotect (decrypt) your secrets.

Unprotect-CyaConfig
[... do what you need to do ...]
Protect-CyaConfig

The aliases ucya and pcya are available for convenience.

ucya
[... do what you need to do ...]
pcya

Automatic warnings

CYA presents a warning if any config items are unprotected when the CYA module loads. You can choose to see this warning every time you open a shell by adding Import-Module CYA to your PowerShell Profile.

You can also suppress these warnings by setting the environment variable CYA_DISABLE_UNPROTECTED_MESSAGE to $True.

Different passwords

CYA supports using different passwords on different CyaConfigs using the -CyaPassword parameter. The New-CyaConfig and New-CyaPassword functions use "Default" by default.

Security

CyaConfigs and CyaPasswords are encrypted using AES-256-CBC and can be moved to any system. Your password is all that's needed to decrypt (so make it a good one).

The contents of files and environment variable values are validated using a salted SHA256 hash. If you unprotect a file and modify it, the file's hash will no longer match the hash stored in the config. CYA will not delete the file and will instead show a warning that the file path conflicts. If you wish to protect a modified file, use New-CyaConfig again.

CYAPATH and backups

By Default CYA will store configs, passwords, and encrypted files in a .cya folder in your $Home (~). You can change this location to wherever you like by setting the environment variable CYAPATH to you desired location. You may want to use a cloud synced folder or any location that you can backup. Or you can just backup the defualt .cya folder.

The .cya folder contains three subfolders:

  • configs stores the configs, either EnvVar (environment variable) or File.
  • passwords stores the encrypted keys to the configs you decrypt with your password.
  • bins stores the encrypted files

Modifying CyaConfigs

Configs and Passwords in CYA are largely immutable but that doesn't mean you can't change things. For example, if you want to change your password, you can follow these steps to create a new CyaPassword, new CyaConfig, and remove the old.

Rename-CyaPassword -Name Default -NewName OldDefault
Rename-CyaConfig -Name MyConfig -NewName OldMyConfig
New-CyaPassword -Name Default
Unprotect-CyaConfig -Name OldMyConfig
New-CyaConfig -Name MyConfig -CyaPassword Default
[... Add the files or environment variables from OldMyConfig ...]
Protect-CyaConfig MyConfig
Remove-CyaConfig -Name OldMyConfig
Remove-CyaPassword -Name OldDefault

Or, if you're comfortable, you could make some trivial changes to the config files directly, they are just JSON files. Changing the path to a file, or name of a variable won't break anything.

More help

Help documentation is available for each function in CYA.

Help New-CyaConfig

Development

Running tests

Tests are written in the pester test framework.

Install-Module pester
git clone https://github.com/nickadam/powershell-cya.git
cd powershell-cya
Invoke-Pester

Static code analysis

Install-Module PSScriptAnalyzer
Invoke-ScriptAnalyzer -Recurse .\CYA\

Code coverage reports

Install ReportGenerator.

Find-Package ReportGenerator -ProviderName "nuget" -Source "https://nuget.org/api/v2" | Install-Package -Scope CurrentUser

Identify the location of the relevant ReportGenerator.exe. In my case:

$RG="$LOCALAPPDATA\PackageManagement\NuGet\Packages\ReportGenerator.5.0.4\tools\net6.0\ReportGenerator.exe"

Generate a coverage.xml file with pester.

Invoke-Pester -CodeCoverage ".\CYA\*" -CodeCoverageOutputFileFormat JaCoCo

Generate code coverage report pages.

& $RG -reports:coverage.xml -targetdir:.\Coverage -sourcedirs:.\CYA

Review the beautiful report.

start .\Coverage\index.html

About

Ciphertext Your Assets

Resources

Stars

9 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages