sublime
critical
mql
DLP - Clear-Text Credentials Outbound
Detects outbound emails containing clear-text credentials in the body,
subject, or attachments using ML extraction. Covers private keys, AWS access
keys, GitHub tokens, HTTP Basic auth headers, and OAuth client secrets.
Attachment content is scanned via ml_extract on both raw text and OCR surfaces,
catching credentials embedded in images or binary document formats.
Note: GCP API keys, Slack tokens, JWTs, and database connection strings are
not covered by ml_extract and are intentionally omitte