Key recovery material
Identifies key-recovery and escrow references, while reserving enforcement for records that contain a structured recovery value. A phrase alone is discovery-only; system identity and custody/escrow fields distinguish a high-confidence recovery-material record.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- structural regex with domain-specific anchors and constrained context replaces phrase-only marker. Added context gating and exclusion rules improve precision and reduce incidental matches.
- Detection quality
- Topic false positive
- Jurisdictions
- global
- Regulations
- GDPR, Criminal Code Act 1995 (Cth), NDB Scheme (Cth), SOCI Act 2018 (Cth), TIA Act 1979 (Cth)
- Data categories
- credentials, security
- Scope
- wide
- Risk rating
- 8
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:key\s+recovery|recovery\s+key|escrow\s+key|break-glass)\b
Corroborative evidence keywords
key recovery, recovery key, escrow key, break-glass, hsm, kms
Proximity: 240 characters
Should match
Key recovery procedure is under review— Low-tier probe - recovery phrase without a recovery valueBitLocker recovery key: 103482-275911-364820-451739-528604-617395-704286-893157— Medium-tier probe - structured recovery value without custody recordBitLocker recovery key: 103482-275911-364820-451739-528604-617395-704286-893157; device ID 4f9c2; escrowed to Entra ID; custodian: endpoint-ops— High-tier probe - structured value with system and custody metadataBreak-glass recovery key 219403-308214-497125-586036-674947-763858-852769-941670— Medium-tier probe - structured break-glass recovery value
Should not match
General key performance indicators for project recovery timeline— Unrelated use of key/recovery wordsGeneric policy prose without key escrow context— No structural security anchorstemplate example placeholder record identifier— Template/sample context should be excluded even when anchor words are presentRecovery key: 103482-275911-364820-451739-528604-617395-704286— Malformed recovery value has only seven groupsBitLocker recovery key: 000000-000000-000000-000000-000000-000000-000000-000000; escrowed to Entra ID— Repeated placeholder recovery value must not enforceDocumentation example: BitLocker recovery key 103482-275911-364820-451739-528604-617395-704286-893157; escrowed to Entra ID— Documentation quoting a complete recovery record must not enforceAPI key rotation completed for the production application— Sibling secret-management activity is not key-recovery material
Known false positives
- Authentication-related terminology in software documentation, security training materials, or system architecture descriptions without actual credentials. Mitigation: Require proximity to credential-specific patterns (API keys, connection strings, tokens) rather than general security terminology.
- Code snippets and configuration examples containing credential-related keywords or placeholder values in developer documentation. Mitigation: Check for common placeholder patterns (example.com, localhost, 0000) and documentation file types to reduce false positives from technical writing.
References
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight
- https://www.oaic.gov.au/privacy/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information