PKCS#8 Private Key Header

Detects unencrypted PKCS#8 private-key armor. The generic BEGIN PRIVATE KEY marker is discovery-only; a DER algorithm prelude supports medium confidence, and near-header wrapped body data or an exact compact-key prelude reaches high.

Type
regex
Engine
universal
Confidence
high
Confidence justification
High confidence: structurally constrained pattern with corroborative keyword support reduces false positive rates significantly. Added context gating and exclusion rules improve precision and reduce incidental matches.
Detection quality
Verified
Jurisdictions
global
Regulations
Criminal Code Act 1995 (Cth)
Frameworks
CIS Controls, ISO 27001, NIST CSF, PCI-DSS, SOC 2
Data categories
credentials, security
Scope
specific
Risk rating
8
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Compatible, Netskope: Compatible

Pattern

-----BEGIN PRIVATE KEY-----

Corroborative evidence keywords

private key, secret key, key file, PEM, certificate, RSA, cryptographic, api key, api_key, apikey, access key, access token, auth token, authorization, bearer, conn str, connection string, connectionstring, cookie, credential (+38 more)

Proximity: 300 characters

Should match

Should not match

Known false positives

Collections