TRUFFLEHOG
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Secrets detection tool that scans git repos, filesystems, S3 buckets, and more for leaked API keys, passwords, and credentials.
INSTALLATION#
# Homebrew brew install trufflehog # Docker docker pull trufflesecurity/trufflehog # Go go install github.com/trufflesecurity/trufflehog/v3@latest # Binary: https://github.com/trufflesecurity/trufflehog/releases
SCANNING GIT REPOS#
# Local repo trufflehog git file:///path/to/repo # Remote repo trufflehog git https://github.com/user/repo # Scan since specific commit trufflehog git https://github.com/user/repo --since-commit abc123 # Scan specific branch trufflehog git https://github.com/user/repo --branch develop # Include commit history (default) trufflehog git https://github.com/user/repo # Only current state (no history) trufflehog git https://github.com/user/repo --no-update
GITHUB / GITLAB SCANNING#
# Scan entire GitHub org trufflehog github --org=myorg --token=GITHUB_TOKEN # Scan specific GitHub repo trufflehog github --repo=https://github.com/user/repo --token=GITHUB_TOKEN # Scan GitLab trufflehog gitlab --token=GITLAB_TOKEN
FILESYSTEM SCANNING#
trufflehog filesystem /path/to/directory trufflehog filesystem .
S3 SCANNING#
trufflehog s3 --bucket=mybucket trufflehog s3 --bucket=mybucket --key=prefix/
OTHER SOURCES#
# Docker image trufflehog docker --image=nginx:latest # CircleCI trufflehog circleci --token=TOKEN # Syslog trufflehog syslog --address=127.0.0.1:514
OUTPUT OPTIONS#
trufflehog git REPO --json # JSON output trufflehog git REPO --json | jq # Pretty JSON trufflehog git REPO --only-verified # Only verified secrets trufflehog git REPO --no-verification # Skip verification # Verification: TruffleHog actually tests if found creds are valid!
DETECTABLE SECRET TYPES#
AWS keys (access key + secret key) GCP service account keys Azure credentials GitHub tokens (PAT, OAuth, App) GitLab tokens Slack tokens/webhooks Stripe API keys Twilio credentials SendGrid API keys Mailgun keys SSH private keys PGP private keys Database connection strings JWT secrets Heroku API keys DigitalOcean tokens NPM tokens PyPI tokens NuGet API keys Docker Hub tokens 700+ detector types total
TIPS#
- --only-verified shows confirmed-active credentials - Scan git history โ secrets removed from HEAD may still be in commits - Scan entire GitHub orgs for org-wide exposure - Use in CI/CD to prevent secret commits - Combine with Gitleaks for cross-validation - S3 scanning catches secrets in cloud storage - Verification feature distinguishes active vs rotated secrets - JSON output integrates with SIEM and ticketing - Docker image scanning catches secrets in build layers - Pre-commit hook prevents secrets from being committed