EC Private Key Header
Detects SEC1 elliptic-curve private-key armor. The BEGIN marker is discovery-only, a SEC1-like Base64 body supports medium confidence, and a complete container with curve or signing context reaches high confidence.
- Type
- regex
- Engine
- universal
- Confidence
- high
- Confidence justification
- High confidence: structurally constrained pattern with corroborative keyword support reduces false positive rates significantly. Added context gating and exclusion rules improve precision and reduce incidental matches.
- Detection quality
- Verified
- Jurisdictions
- global
- Regulations
- Criminal Code Act 1995 (Cth)
- Frameworks
- CIS Controls, ISO 27001, NIST CSF, PCI-DSS, SOC 2
- Data categories
- credentials, security
- Scope
- specific
- Risk rating
- 8
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Compatible, Netskope: Compatible
Pattern
-----BEGIN EC PRIVATE KEY-----
Corroborative evidence keywords
private key, secret key, key file, PEM, certificate, RSA, cryptographic, api key, api_key, apikey, access key, access token, auth token, authorization, bearer, conn str, connection string, connectionstring, cookie, credential (+38 more)
Proximity: 300 characters
Should match
-----BEGIN EC PRIVATE KEY-----— Low-tier probe - EC armor header without SEC1 body-----BEGIN EC PRIVATE KEY----- MHcCAQEEIF6Yx7K2mN9pQ4sT8vW3yZ6aB1cD5eF7gH8jK2mN— Medium-tier probe - SEC1-like EC body without closing armorECDSA signing key curve secp256r1 -----BEGIN EC PRIVATE KEY----- MHcCAQEEIF6Yx7K2mN9pQ4sT8vW3yZ6aB1cD5eF7gH8jK2mN -----END EC PRIVATE KEY-----— High-tier probe - complete SEC1 container with curve context
Should not match
-----BEGIN PUBLIC KEY-----— Public key, not private-----BEGIN CERTIFICATE-----— Certificate, not private key-----BEGIN EC PRIVATE KEY----- MIIE-not-sec1— Malformed body lacks a SEC1 EC private-key prefix-----BEGIN EC PRIVATE KEY----- PLACEHOLDER -----END EC PRIVATE KEY-----— Placeholder body must not enforceDocumentation example: ECDSA signing key curve secp256r1 -----BEGIN EC PRIVATE KEY----- MHcCAQEEIF6Yx7K2mN9pQ4sT8vW3yZ6aB1cD5eF7gH8jK2mN -----END EC PRIVATE KEY-----— Documentation quoting a complete EC key must not enforce-----BEGIN RSA PRIVATE KEY-----— Sibling PKCS#1 RSA private-key armor is not SEC1 EC
Known false positives
- PEM-encoded certificates or public keys that use similar header formats Mitigation: The pattern specifically matches the private key header text, but verify the full PEM block contains actual key material.