trufflesecurity/trufflehog

▲ 53 stars today★ 28,126⑂ 2,601

Find, verify, and analyze leaked credentials

About trufflesecurity/trufflehog

trufflesecurity/trufflehog is an open-source project on GitHub, mainly written in Go. Find, verify, and analyze leaked credentials It currently holds 28,126 stars and 2,601 forks with 557 open issues, and was last pushed on 2026-09-27 (repository created 2016-12-31).

Project Overview

Git Homed tracks it on the Today's Trending board, currently at rank #43 with 53 new stars today.

GitHub Repository Details

Repository trufflesecurity/trufflehog · default branch main · size 52405 KB · watchers 212 · source: GitHub REST API and repository README

README

https://github.com/trufflesecurity/trufflehog/blob/HEAD/GoReleaser Logo

TruffleHog

Find leaked credentials.

---

Go Report Card License Total Detectors

---

:mag_right: _Now Scanning_

...and more

To learn more about TruffleHog and its features and capabilities, visit our product page.

:globe_with_meridians: TruffleHog Enterprise

Are you interested in continuously monitoring Git, Jira, Slack, Confluence, Microsoft Teams, Sharepoint (and more) for credentials? We have an enterprise product that can help! Learn more at .

We take the revenue from the enterprise product to fund more awesome open source projects that the whole community can benefit from.

What is TruffleHog 🐽

TruffleHog is the most powerful secrets Discovery, Classification, Validation, and Analysis tool. In this context, secret refers to a credential a machine uses to authenticate itself to another machine. This includes API keys, database passwords, private encryption keys, and more.

Discovery 🔍

TruffleHog can look for secrets in many places including Git, chats, wikis, logs, API testing platforms, object stores, filesystems and more.

Classification 📁

TruffleHog classifies over 800 secret types, mapping them back to the specific identity they belong to. Is it an AWS secret? Stripe secret? Cloudflare secret? Postgres password? SSL Private key? Sometimes it's hard to tell looking at it, so TruffleHog classifies everything it finds.

Validation ✅

For every secret TruffleHog can classify, it can also log in to confirm if that secret is live or not. This step is critical to know if there’s an active present danger or not.

Analysis 🔬

For the 20 some of the most commonly leaked out credential types, instead of sending one request to check if the secret can log in, TruffleHog can send many requests to learn everything there is to know about the secret. Who created it? What resources can it access? What permissions does it have on those resources?

:loudspeaker: Join Our Community

Have questions? Feedback? Jump into Slack or Discord and hang out with us.

Join our Slack Community

Join the Secret Scanning Discord

:tv: Demo

GitHub scanning demo
docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity

:floppy_disk: Installation

Several options are available for you:

MacOS users

brew install trufflehog

Docker:

_Ensure Docker engine is running before executing the following commands:_

    Unix

docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys

    Windows Command Prompt

docker run --rm -it -v "%cd:/=\%:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys

    Windows PowerShell

docker run --rm -it -v "${PWD}:/pwd" trufflesecurity/trufflehog github --repo https://github.com/trufflesecurity/test_keys

    M1 and M2 Mac

docker run --platform linux/arm64 --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys

Binary releases

Download and unpack from https://github.com/trufflesecurity/trufflehog/releases

Compile from source

git clone https://github.com/trufflesecurity/trufflehog.git
cd trufflehog; go install

Using installation script

curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh | sh -s -- -b /usr/local/bin

Using installation script, verify checksum signature (requires cosign to be installed)

curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh | sh -s -- -v -b /usr/local/bin

Using installation script to install a specific version

curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh | sh -s -- -b /usr/local/bin 

:closed_lock_with_key: Verifying the artifacts

Checksums are applied to all artifacts, and the resulting checksum file is signed using cosign.

You need the following tool to verify signature:

Verification steps are as follows:

1. Download the artifact files you want, and the following files from the releases page.

2. Verify the signature:

   cosign verify-blob  \
   --certificate  \
   --signature  \
   --certificate-identity-regexp 'https://github\.com/trufflesecurity/trufflehog/\.github/workflows/.+' \
   --certificate-oidc-issuer "https://token.actions.githubusercontent.com"
   

3. Once the signature is confirmed as valid, you can proceed to validate that the SHA256 sums align with the downloaded artifact:

   sha256sum --ignore-missing -c trufflehog_{version}_checksums.txt
   

Replace {version} with the downloaded files version

Alternatively, if you are using the installation script, pass -v option to perform signature verification. This requires Cosign binary to be installed prior to running the installation script.

:rocket: Quick Start

1: Scan a repo for only verified secrets

Command:

trufflehog git https://github.com/trufflesecurity/test_keys --results=verified

Expected output:

🐷🔑🐷  TruffleHog. Unearth your secrets. 🐷🔑🐷

Found verified result 🐷🔑 Detector Type: AWS Decoder Type: PLAIN Raw result: AKIAYVP4CIPPERUVIFXG Line: 4 Commit: fbc14303ffbf8fb1c2c1914e8dda7d0121633aca File: keys Email: counter Repository: https://github.com/trufflesecurity/test_keys Timestamp: 2022-06-16 10:17:40 -0700 PDT ...

2: Scan a GitHub Org for only verified secrets

trufflehog github --org=trufflesecurity --results=verified

3: Scan a GitHub Org excluding archived repositories

trufflehog github --org=trufflesecurity --exclude-archived

4: Scan a GitHub Repo for only verified secrets and get JSON output

Command:

trufflehog git https://github.com/trufflesecurity/test_keys --results=verified --json

Expected output:

{"SourceMetadata":{"Data":{"Git":{"commit":"fbc14303ffbf8fb1c2c1914e8dda7d0121633aca","file":"keys","email":"counter \[email protected]\u003e","repository":"https://github.com/trufflesecurity/test_keys","timestamp":"2022-06-16 10:17:40 -0700 PDT","line":4}}},"SourceID":0,"SourceType":16,"SourceName":"trufflehog - git","DetectorType":2,"DetectorName":"AWS","DecoderName":"PLAIN","Verified":true,"Raw":"AKIAYVP4CIPPERUVIFXG","Redacted":"AKIAYVP4CIPPERUVIFXG","ExtraData":{"account":"595918472158","arn":"arn:aws:iam::595918472158:user/canarytokens.com@@mirux23ppyky6hx3l6vclmhnj","user_id":"AIDAYVP4CIPPJ5M54LRCY"},"StructuredData":null}
...

TruffleHog can also output SARIF with --sarif instead of --json. GitHub code scanning understands SARIF natively, so uploading it surfaces findings inline on pull request diffs and in the repository's Security tab, and tracks findings as new/fixed across scans instead of reporting the same one every run — see the TruffleHog Github Action section below for how to upload it. Note that, unlike the other output formats, SARIF results are buffered in memory for the full scan and written out at the end, since SARIF requires a single JSON document rather than a stream — fine for typical scans, but scans producing a very large number of results will use proportionally more memory.

5: Scan a GitHub Repo + its Issues and Pull Requests

trufflehog github --repo=https://github.com/trufflesecurity/test_keys --issue-comments --pr-comments

6: Scan an S3 bucket for high-confidence results (verified + unknown)

trufflehog s3 --bucket= --results=verified,unknown

7: Scan S3 buckets using IAM Roles

trufflehog s3 --role-arn=

8: Scan a Github Repo using SSH authentication in Docker

docker run --rm -v "$HOME/.ssh:/root/.ssh:ro" trufflesecurity/trufflehog:latest git ssh://github.com/trufflesecurity/test_keys

9: Scan individual files or directories

trufflehog filesystem path/to/file1.txt path/to/file2.txt path/to/dir

10: Scan a local git repo

Clone the git repo. For example test keys repo.

git clone [email protected]:trufflesecurity/test_keys.git

Run trufflehog from the parent directory (outside the git repo).

trufflehog git file://test_keys --results=verified,unknown

To guard against malicious git configs in local scanning (see CVE-2025-41390), TruffleHog clones local git repositories to a temporary directory prior to scanning. This follows Git's security best practices. If you want to specify a custom path to clone the repository to (instead of tmp), you can use the --clone-path flag. If you'd like to skip the local cloning process and scan the repository directly (only do this for trusted repos), you can use the --trust-local-git-config flag.

11: Scan GCS buckets for only verified secrets

trufflehog gcs --project-id= --cloud-environment --results=verified

12: Scan a Docker image for only verified secrets

Use the --image flag multiple times to scan multiple images.

# to scan from a remote registry
trufflehog docker --image trufflesecurity/secrets --results=verified

to scan from the local docker daemon

trufflehog docker --image docker://new_image:tag --results=verified

to scan from an image saved as a tarball

trufflehog docker --image file://path_to_image.tar --results=verified

13: Scan in CI

Set the --since-commit flag to your default branch that people merge into (ex: "main"). Set the --branch flag to your PR's branch name (ex: "feature-1"). Depending on the CI/CD platform you use, this value can be pulled in dynamically (ex: CIRCLE_BRANCH in Circle CI and TRAVIS_PULL_REQUEST_BRANCH in Travis CI). If the repo is cloned and the target branch is already checked out during the CI/CD workflow, then --branch HEAD should be sufficient. The --fail flag will return an 183 error code if valid credentials are found.

trufflehog git file://. --since-commit main --branch feature-1 --results=verified,unknown --fail

14: Scan a Postman workspace

Use the --workspace-id, --collection-id, --environment flags multiple times to scan multiple targets.

trufflehog postman --token= --workspace-id=

15: Scan a Jenkins server

trufflehog jenkins --url https://jenkins.example.com --username admin --password admin

16: Scan an Elasticsearch server

Scan a Local Cluster

There are two ways to authenticate to a local cluster with TruffleHog: (1) username and password, (2) service token.

Connect to a local cluster with username and password

trufflehog elasticsearch --nodes 192.168.14.3 192.168.14.4 --username truffle --password hog

Connect to a local cluster with a service token

trufflehog elasticsearch --nodes 192.168.14.3 192.168.14.4 --service-token ‘AAEWVaWM...Rva2VuaSDZ’

Scan an Elastic Cloud Cluster

To scan a cluster on Elastic Cloud, you’ll need a Cloud ID and API key.

trufflehog elasticsearch \
  --cloud-id 'search-prod:dXMtY2Vx...YjM1ODNlOWFiZGRlNjI0NA==' \
  --api-key 'MlVtVjBZ...ZSYlduYnF1djh3NG5FQQ=='

17. Scan a GitHub Repository for Cross Fork Object References and Deleted Commits

The following command will enumerate deleted and hidden commits on a GitHub repository and then scan them for secrets. This is an alpha release feature.

trufflehog github-experimental --repo https://github.com//.git --object-discovery

In addition to the normal TruffleHog output, the --object-discovery flag creates two files in a new $HOME/.trufflehog directory: valid_hidden.txt and invalid.txt. These are used to track state during commit enumeration, as well as to provide users with a complete list of all hidden and deleted commits (valid_hidden.txt). If you'd like to automatically remove these files after scanning, please add the flag --delete-cached-data.

Note: Enumerating all valid commits on a repository using this method takes between 20 minutes and a few hours, depending on the size of your repository. We added a progress bar to keep you updated on how long the enumeration will take. The actual secret scanning runs extremely fast.

For more information on Cross Fork Object References, please read our blog post.

18. Scan Hugging Face

Scan a Hugging Face Model, Dataset, Space or Bucket

trufflehog huggingface \
    --model <model_id> \
    --dataset <dataset_id> \
    --space <space_id> \
    --bucket <bucket_id>

Scan all Models, Datasets, Spaces and Buckets belonging to a Hugging Face Organization or User

trufflehog huggingface --org  --user 

(Optionally) When scanning an organization or user, you can skip an entire class of resources with --skip-all-models, --skip-all-datasets, --skip-all-spaces, --skip-all-buckets OR a particular resource with --ignore-models <model_id>, --ignore-datasets <dataset_id>, --ignore-spaces <space_id>, --ignore-buckets <bucket_id>.

Scan Discussion and PR Comments

trufflehog huggingface --model <model_id> --include-discussions --include-prs

19. Scan stdin Input

aws s3 cp s3://example/gzipped/data.gz - | gunzip -c | trufflehog stdin

:question: FAQ

:newspaper: What's new in v3?

TruffleHog v3 is a complete rewrite in Go with many new powerful features.

What is credential verification?

For every potential credential that is detected, we've painstakingly implemented programmatic verification against the API that we think it belongs to. Verification eliminates false positives and provides three result statuses:

For example, the AWS credential detector performs a GetCallerIdentity API call against the AWS API to verify if an AWS credential is active.

:memo: Usage

TruffleHog has a sub-command for each source of data that you may want to scan:

Each subcommand can have options that you can see with the --help flag provided to the sub command:

$ trufflehog git --help
usage: TruffleHog []  [ ...]

TruffleHog is a tool for finding credentials.

Flags: -h, --[no-]help Show context-sensitive help (also try --help-long and --help-man). --log-level=0 Logging verbosity on a scale of 0 (info) to 5 (trace). Can be disabled with "-1". --[no-]profile Enables profiling and sets a pprof and fgprof server on :18066. -j, --[no-]json Output in JSON format. --[no-]json-legacy Use the pre-v3.0 JSON format. Only works with git, gitlab, and github sources. --[no-]github-actions Output in GitHub Actions format. --[no-]sarif Output in SARIF format for upload to GitHub code scanning (e.g. via github/codeql-action/upload-sarif). --concurrency=12 Number of concurrent workers. --[no-]no-verification Don't verify the results. --results=RESULTS Specifies which type(s) of results to output: verified (confirmed valid by API), unknown (verification failed due to error), unverified (detected but not verified), filtered_unverified (unverified but would have been filtered out). Defaults to verified,unverified,unknown. --[no-]no-color Disable colorized output --[no-]allow-verification-overlap Allow verification of similar credentials across detectors --[no-]filter-unverified Only output first unverified result per chunk per detector if there are more than one results. --filter-entropy=FILTER-ENTROPY Filter unverified results with Shannon entropy. Start with 3.0. --config=CONFIG Path to configuration file. --[no-]print-avg-detector-time Print the average time spent on each detector. --[no-]no-update Don't check for updates. --[no-]fail Exit with code 183 if results are found. --[no-]fail-on-scan-errors Exit with non-zero error code if an error occurs during the scan. --verifier=VERIFIER ... Set custom verification endpoints. --[no-]custom-verifiers-only Only use custom verification endpoints. --detector-timeout=DETECTOR-TIMEOUT Maximum time to spend scanning chunks per detector (e.g., 30s). --archive-max-size=ARCHIVE-MAX-SIZE Maximum size of archive to scan. (Byte units eg. 512B, 2KB, 4MB) --archive-max-depth=ARCHIVE-MAX-DEPTH Maximum depth of archive to scan. --archive-timeout=ARCHIVE-TIMEOUT Maximum time to spend extracting an archive. --include-detectors="all" Comma separated list of detector types to include. Protobuf name or IDs may be used, as well as ranges. --exclude-detectors=EXCLUDE-DETECTORS Comma separated list of detector types to exclude. Protobuf name or IDs may be used, as well as ranges. IDs defined here take precedence over the include list. --[no-]no-verification-cache Disable verification caching --[no-]force-skip-binaries Force skipping binaries. --[no-]force-skip-archives Force skipping archives. --[no-]skip-additional-refs Skip additional references. --user-agent-suffix=USER-AGENT-SUFFIX Suffix to add to User-Agent. --[no-]version Show application version.

Commands: help [...] Show help.

git []

Find credentials in git repositories.

github [] Find credentials in GitHub repositories.

github-experimental --repo=REPO [] Run an experimental GitHub scan. Must specify at least one experimental sub-module to run: object-discovery.

gitlab --token=TOKEN [] Find credentials in GitLab repositories.

filesystem [] [...] Find credentials in a filesystem.

s3 [] Find credentials in S3 buckets.

gcs [] Find credentials in GCS buckets.

syslog --format=FORMAT [] Scan syslog

circleci --token=TOKEN Scan CircleCI

docker [] Scan Docker Image

travisci --token=TOKEN Scan TravisCI

postman [] Scan Postman

elasticsearch [] Scan Elasticsearch

jenkins --url=URL [] Scan Jenkins

huggingface [] Find credentials in HuggingFace datasets, models and spaces.

stdin Find credentials from stdin.

multi-scan Find credentials in multiple sources defined in configuration.

json-enumerator [...] Find credentials from a JSON enumerator input.

analyze Analyze API keys for fine-grained permissions information.

For example, to scan a git repository, start with

``` trufflehog git https://github.com/trufflesecurity/truffleh

GitHub Stars & Activity

28,126Stars
2,601Forks
557Open issues
GoLanguage

GitHub Popularity

GitHub stars28,126
Forks2,601
Open issues557
Primary languageGo
LicenseAGPL-3.0
Stars gained today53
Created2016-12-31
Last pushed2026-09-27

Trending History

Daily boardrank #43 · ▲ 53 stars

Related GitHub Projects

1

golang / go

Go★ 139,060⑂ 20,752▲ 30 stars
→
2

kubernetes / kubernetes

Go★ 128,061⑂ 45,499▲ 36 stars
→
3

microsoft / TypeScript

Go★ 111,249⑂ 15,184▲ 19 stars
→
4

junegunn / fzf

Go★ 83,282⑂ 3,943▲ 21 stars
→
5

mudler / LocalAI

Go★ 49,304⑂ 4,474▲ 20 stars
→
6

putyy / res-downloader

Go★ 20,268⑂ 2,520▲ 68 stars
→
7

Billionmail / BillionMail

Go★ 15,702⑂ 1,721▲ 26 stars
→
8

git-bug / git-bug

Go★ 10,628⑂ 332▲ 55 stars
→

More Trending Repositories