- Home
- Attack Surface
- External Attack Surface Management
- TruffleHog Forager
TruffleHog Forager
Scans public internet for leaked cloud service keys and verifies them

TruffleHog Forager
Scans public internet for leaked cloud service keys and verifies them
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
TruffleHog Forager Description
TruffleHog Forager is a scanning tool that monitors the public internet for exposed cloud service credentials and secrets. The tool scans millions of push events on GitHub and NPM packages to identify leaked keys for cloud services including AWS and Google Cloud Platform. The product verifies discovered secrets to determine if they are live and active. It links detected secrets to specific organizations using email addresses, AWS and GCP account IDs, or GitHub organization member information. This linking capability works regardless of the commit email used by the developer. The tool provides alerting within minutes when a live key is detected. It supports over 800 detectors for different types of credentials and secrets. The detection capabilities can be extended through open-source contributions. TruffleHog Forager is available in two versions: a free community edition that scans the public internet and provides leak detection for company domains, and an enterprise version that integrates with TruffleHog Enterprise. The enterprise version offers enhanced linking capabilities beyond domain matching, connecting leaks to specific AWS or GCP account IDs and GitHub usernames. It includes a centralized dashboard for monitoring both internal and external leaks.
TruffleHog Forager FAQ
Common questions about TruffleHog Forager including features, pricing, alternatives, and user reviews.
TruffleHog Forager is Scans public internet for leaked cloud service keys and verifies them developed by Truffle Security. It is a Attack Surface solution designed to help security teams with Secret Detection, Secrets Management, Cloud Security.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox