TruffleHog

Truffle Security

Secret scanner that verifies whether a found credential is still live.

Application & Supply Chain Freemium CLI Learning Cross-platform

Cyber Kill Chain & Defender Lifecycle

Attacker — Kill Chain
1 Reconnaissance
2 Weaponization
3 Delivery
4 Exploitation
5 Installation
6 Command & Control
7 Actions on Objectives
Defender — IR Lifecycle
8 Preparation
9 Detection & Analysis
10 Containment, Eradication & Recovery
11 Post-Incident Activity

Description

TruffleHog covers the same ground as Gitleaks with one decisive addition: verification. For hundreds of credential types it calls the provider's API to check whether the key still works, which collapses a page of findings into the handful that are actually live.

That distinction is the difference between a report someone triages and a report someone acts on today.

Use cases

  • Separating live credentials from long-dead ones
  • Scanning an organisation's repositories at once
  • Prioritising rotation by what is verifiably still valid

Example

trufflehog git file://. --results=verified --json