arrow-left

All pages
gitbookPowered by GitBook
1 of 1

Loading...

TruffleHog

Find leaked credentials.

hashtag
URL

Product Page - https://trufflesecurity.com/trufflehogarrow-up-right

GitHub Repository - https://github.com/trufflesecurity/trufflehogarrow-up-right

hashtag
Description

TruffleHog is a tool that is capable of finding, verifying, and analyzing leaked credentials. Credentials can be API keys, passwords, authentication tokens, private keys, etc. TruffleHog is capable of searching through multiple data sources, including local and remote git repositories, Dockerfiles, AWS S3 buckets, file-systems, CI/CD systems, and more. Once a secret is detected, TruffleHog (since version 3) will additionally validate the secret in order to identify which detections are still active and not previously disabled and/or rotated. Lastly, the tool comes with an analyze command that is capable of of taking a detected secret and giving you more information about the permissions and resources it has access to.

hashtag
Cost

While TruffleHog is free at it's core, there is an available. However, there is little functionality provided in Enterprise that is of much use to an individual researcher.

hashtag
Level of difficulty

hashtag
Requirements

A terminal emulator is required to install and use the tool.

hashtag
Limitations

The tool is limited to detecting types of credentials that it has pre-configured detectors for. See a list . You may also define .

hashtag
Ethical Considerations

Using credentials found by TruffleHog to gain (or attempt to gain) unauthorized access is unethical and illegal in most countries.

hashtag
Guides and articles

The has information on how to install and use the tool, including advanced usage.

The provides additional information, though there are Enterprise features co-mingled with the open source features. If a feature is Enterprise-only, the page will have a banner that indicates this, as seen on the (as of: 27 August, 2024).

hashtag
Tool provider

Truffle Security Co. - USA

hashtag
Advertising Trackers

Page maintainer
starstarstarstarstarstarstar

Max Louthain

Enterprise versionarrow-up-right
herearrow-up-right
custom detectorsarrow-up-right
TruffleHog READMEarrow-up-right
TruffleHog Documentationarrow-up-right
Google Drive pagearrow-up-right
https://trufflesecurity.com/arrow-up-right