โ† All cheat sheets

TRUFFLEHOG

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Secrets detection tool that scans git repos, filesystems, S3 buckets,
and more for leaked API keys, passwords, and credentials.

INSTALLATION#

# Homebrew
brew install trufflehog

# Docker
docker pull trufflesecurity/trufflehog

# Go
go install github.com/trufflesecurity/trufflehog/v3@latest

# Binary: https://github.com/trufflesecurity/trufflehog/releases

SCANNING GIT REPOS#

# Local repo
trufflehog git file:///path/to/repo

# Remote repo
trufflehog git https://github.com/user/repo

# Scan since specific commit
trufflehog git https://github.com/user/repo --since-commit abc123

# Scan specific branch
trufflehog git https://github.com/user/repo --branch develop

# Include commit history (default)
trufflehog git https://github.com/user/repo

# Only current state (no history)
trufflehog git https://github.com/user/repo --no-update

GITHUB / GITLAB SCANNING#

# Scan entire GitHub org
trufflehog github --org=myorg --token=GITHUB_TOKEN

# Scan specific GitHub repo
trufflehog github --repo=https://github.com/user/repo --token=GITHUB_TOKEN

# Scan GitLab
trufflehog gitlab --token=GITLAB_TOKEN

FILESYSTEM SCANNING#

trufflehog filesystem /path/to/directory
trufflehog filesystem .

S3 SCANNING#

trufflehog s3 --bucket=mybucket
trufflehog s3 --bucket=mybucket --key=prefix/

OTHER SOURCES#

# Docker image
trufflehog docker --image=nginx:latest

# CircleCI
trufflehog circleci --token=TOKEN

# Syslog
trufflehog syslog --address=127.0.0.1:514

OUTPUT OPTIONS#

trufflehog git REPO --json                  # JSON output
trufflehog git REPO --json | jq             # Pretty JSON
trufflehog git REPO --only-verified         # Only verified secrets
trufflehog git REPO --no-verification       # Skip verification

# Verification: TruffleHog actually tests if found creds are valid!

DETECTABLE SECRET TYPES#

  AWS keys (access key + secret key)
  GCP service account keys
  Azure credentials
  GitHub tokens (PAT, OAuth, App)
  GitLab tokens
  Slack tokens/webhooks
  Stripe API keys
  Twilio credentials
  SendGrid API keys
  Mailgun keys
  SSH private keys
  PGP private keys
  Database connection strings
  JWT secrets
  Heroku API keys
  DigitalOcean tokens
  NPM tokens
  PyPI tokens
  NuGet API keys
  Docker Hub tokens
  700+ detector types total

TIPS#

  - --only-verified shows confirmed-active credentials
  - Scan git history โ€” secrets removed from HEAD may still be in commits
  - Scan entire GitHub orgs for org-wide exposure
  - Use in CI/CD to prevent secret commits
  - Combine with Gitleaks for cross-validation
  - S3 scanning catches secrets in cloud storage
  - Verification feature distinguishes active vs rotated secrets
  - JSON output integrates with SIEM and ticketing
  - Docker image scanning catches secrets in build layers
  - Pre-commit hook prevents secrets from being committed