AppSecNews
Secret Scanning Open source and commercial Established

TruffleHog

by Truffle Security

Secret scanner that calls each provider's API to confirm whether a discovered credential is active, across git history, cloud storage, container images and chat and ticketing systems.

Visit trufflesecurity.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run TruffleHog in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Full list of supported scan sources and detectors: confirm against current documentation
  • Feature boundary between the open-source scanner and the commercial platform: confirm with vendor

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

TruffleHog splits secret detection into two steps, and the second is the point of the tool. Detection is conventional: many detectors, each a Go type with keyword prefilters and an expression for one provider's credential format. Verification is what follows. For a detector that supports it, TruffleHog takes the candidate string and makes a real authenticated request to that provider, and reports the finding as verified only if the credential is accepted. That collapses triage from a queue of maybes into a short list of keys that work right now.

It also scans more than a repository. Sources include local directories, git history across every branch, whole GitHub and GitLab organizations including forks and gists, container image layers, object storage buckets, CI systems, and collaboration tools where credentials get pasted more often than into code. An analyze mode takes a confirmed key and enumerates what it can reach, turning a finding into an impact statement.

Where it fits

The open-source binary runs as a pre-commit hook, a pull request check, and a scheduled organization-wide sweep. The sweep is where it earns its place, because that is when verification separates historical noise from live exposure. Security teams own the org-wide scans and the response that follows; developers see the pull request gate. Verification requires outbound network access to every provider you check against, a real prerequisite in a locked-down build environment.

Strengths

  • Verification is the difference between a report and a work queue. A verified finding is an incident, not a candidate for triage.
  • The breadth of non-code sources catches leaks repository-only scanners structurally cannot see.
  • Analyze mode enumerates a live key's permissions and reachable resources, shortening the decision about how urgently to rotate.

Limitations

  • Verification sends candidate strings to third party APIs. Some organizations cannot permit that, and in restricted networks verification silently degrades to unverified results.
  • Detector coverage is strongest for well-known SaaS providers, so homegrown formats need custom detectors or are missed. Full history scans across a large organization are also slow and rate-limited by the platforms being scanned.
  • The scanner is AGPL licensed, which some legal teams treat as a blocker for embedding it in internal tooling, and the managed incident workflow sits in the commercial product rather than the CLI.

Who it suits

Security teams drowning in unverified findings who need to know which ones matter, and incident responders who want reach beyond git. It fits organizations with permissive enough egress to allow verification. Teams that cannot call credential providers, or that need only a lightweight local commit gate, will get most of the value from a simpler scanner without the constraint.

Used TruffleHog? Recommend it under your own name and title.

Recommend this tool