
Find leaked credentials by scanning repositories for high entropy strings.

Find leaked credentials by scanning repositories for high entropy strings.
TruffleHog is a Secrets Detection product. It is deployed as on-premises software. Pricing is free.
TruffleHog is an open-source secrets scanning tool developed by Truffle Security that searches for leaked credentials across a wide range of sources including Git repositories, chat platforms, wikis, logs, API testing platforms, object stores, and filesystems. The tool operates across four primary functions: - Discovery: Scans multiple source types for exposed secrets such as API keys, database passwords, and private encryption keys. - Classification: Identifies and categorizes over 800 distinct secret types, mapping each finding to the specific service or identity it belongs to (e.g., AWS, Stripe, Cloudflare, PostgreSQL, SSL private keys). - Validation: Actively attempts to authenticate using discovered secrets to determine whether they are live and currently usable, helping prioritize response efforts. - Analysis: For approximately 20 of the most commonly leaked credential types, performs extended analysis to determine who created the secret, what resources it can access, and what permissions it holds. TruffleHog can be installed via Homebrew, Docker, binary release, or compiled from source. It supports checksum verification using cosign for artifact integrity. An enterprise version, TruffleHog Enterprise, provides continuous monitoring across Git, Jira, Slack, Confluence, Microsoft Teams, and SharePoint. The open-source version is available under the AGPL-3.0 license on GitHub and is written in Go.
Common questions about TruffleHog including features, pricing, alternatives, and user reviews.
TruffleHog is Find leaked credentials by scanning repositories for high entropy strings. It is a Application Security solution designed to help security teams with Password Cracking, Secret Detection.
TruffleHog offers the following core capabilities:
TruffleHog integrates natively with Git, GitHub, Jira, Slack, Confluence, Microsoft Teams, SharePoint, Docker. Integration support lets security teams connect TruffleHog to existing SIEM, ticketing, identity, and notification systems without custom development.
TruffleHog is deployed as a on-premises solution, suited to startup, smb, mid-market, enterprise organizations looking to operationalize application security. The free tier is well-suited to evaluation, small teams, and learning environments.
TruffleHog is built for security teams handling Password Cracking, Secret Detection. It supports workflows including secrets discovery across git repos, chats, wikis, logs, object stores, and filesystems, classification of over 800 secret types mapped to specific services and identities, active validation of discovered secrets to confirm if they are live. Teams typically adopt TruffleHog when they need to application security capabilities integrated into their existing stack. Explore similar tools at https://cybersectools.com/alternatives/trufflehog
TruffleHog is a free Application Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/dxa4481/truffleHog/ for download and installation instructions.
Popular alternatives to TruffleHog include:
Compare all TruffleHog alternatives at https://cybersectools.com/alternatives/trufflehog
TruffleHog is for security teams and organizations that need Password Cracking, Secret Detection. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Application Security tools can be found at https://cybersectools.com/categories/application-security
Head-to-head feature, pricing, and rating breakdowns.
Non-human identity security platform for secrets detection and management
AI-powered secret detection tool for real-time credential scanning in code
Credential verification service that validates leaked secrets for liveness