← All cheat sheets

GITLEAKS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Git secrets scanner that detects hardcoded passwords, API keys,
and tokens in git repos using regex and entropy analysis.

INSTALLATION#

brew install gitleaks                       # macOS
go install github.com/gitleaks/gitleaks/v8@latest  # Go
# Or download binary from GitHub releases

SCANNING#

# Scan local repo (git history)
gitleaks detect -s /path/to/repo

# Scan current directory
gitleaks detect

# Scan only staged changes (pre-commit)
gitleaks protect --staged

# Scan specific commit range
gitleaks detect --log-opts="--since=2024-01-01"
gitleaks detect --log-opts="abc123..HEAD"

# No git history (filesystem only)
gitleaks detect --no-git -s /path/to/directory

OUTPUT#

gitleaks detect -f json -r results.json     # JSON report
gitleaks detect -f csv -r results.csv       # CSV report
gitleaks detect -f sarif -r results.sarif   # SARIF
gitleaks detect --verbose                   # Verbose output
gitleaks detect --exit-code 1               # Non-zero on findings

CONFIGURATION#

# Custom config file
gitleaks detect -c custom-config.toml

# Default config: .gitleaks.toml in repo root

# Example .gitleaks.toml:
title = "Custom Gitleaks Config"

[[rules]]
id = "aws-access-key"
description = "AWS Access Key"
regex = '''AKIA[0-9A-Z]{16}'''
tags = ["aws", "key"]

[[rules]]
id = "generic-password"
description = "Generic Password"
regex = '''(?i)password\s*=\s*['"][^'"]{8,}['"]'''
tags = ["password"]

# Allowlist (ignore false positives)
[allowlist]
paths = ["vendor/", "node_modules/", "*.test.js"]
commits = ["abc123def456"]
regexes = ["EXAMPLE_KEY"]

PRE-COMMIT HOOK#

# Install as pre-commit hook
# In .pre-commit-config.yaml:
repos:
  - repo: https://github.com/gitleaks/gitleaks
    rev: v8.18.0
    hooks:
      - id: gitleaks

# Or manual hook (.git/hooks/pre-commit):
#!/bin/bash
gitleaks protect --staged --exit-code 1

# Baseline (ignore existing secrets)
gitleaks detect --baseline-path baseline.json
gitleaks detect --baseline-path baseline.json --exit-code 1

TIPS#

  - Use protect (not detect) for pre-commit hooks
  - Baseline file allows gradual remediation
  - SARIF output for GitHub/GitLab security dashboards
  - Combine with TruffleHog (TruffleHog verifies, Gitleaks is faster)
  - Custom rules in .gitleaks.toml for org-specific patterns
  - --no-git mode scans filesystems without git
  - Allowlist paths to reduce false positives
  - Run in CI/CD with --exit-code 1 as quality gate
  - Entropy-based detection catches non-pattern secrets
  - Scan all branches, not just main