TruffleHog
Find leaked credentials, API keys, and private tokens across git histories and cloud filesystems.
Why consider TruffleHog?
TruffleHog is an open-source secret scanning engine written in Go by Truffle Security. TruffleHog scans git repos, S3 buckets, filesystems, and Docker containers, actively verifying whether discovered API keys (AWS, GitHub, Slack, OpenAI) are live and accessible.
Learn TruffleHog by building
Practical setup notes, real use cases, and copy-ready examples in one focused guide.
In this guide2 sections
Overview of TruffleHog
TruffleHog detects and validates exposed cloud credentials across commit histories.
Quickstart
trufflehog git https://github.com/myorg/myrepo --only-verifiedTruffleHog is licensed under the GNU AGPL-3.0 license.
Related tools
More options with a similar category or technology profile.
diskus
Minimal, fast alternative to du -sh written in Rust using multi-threaded directory traversal.
peco
Simplistic interactive filtering tool for Unix pipelines, process lists, and file trees.
Dapr CLI
Command-line tool for managing Dapr distributed application runtime environments and sidecars.
Freeze
Generate beautiful image screenshots and SVGs of code snippets and terminal outputs.