
TruffleHog
TruffleHog finds and verifies leaked secrets across git, cloud storage and CI artefacts, with a free open-source scanner and commercial TruffleHog Enterprise.
0 upvotes · 0 downvotes
- Category
- Application Security
- Pricing
- Freemium
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
What it is
TruffleHog is a secrets discovery tool from Truffle Security that scans places such as Git history, filesystems, S3, Docker images and more for credentials, then classifies and verifies many secret types to reduce false positives. The open-source CLI is free; TruffleHog Enterprise adds continuous monitoring, dashboards, SSO and broader SaaS and CI/CD integrations.
What it helps with
- Detecting API keys, tokens, passwords and private keys committed to repositories.
- Verifying whether discovered credentials are still live against providers where supported.
- Scanning beyond git into object stores, containers and related development artefacts.
- Embedding checks in pre-commit hooks, CI jobs and GitHub Actions.
- Operating continuous secrets monitoring and alerting on Enterprise deployments.
- Supporting incident response when a leak needs classification and impact analysis.
Who it's for
AppSec, DevOps and cloud security engineers who need secrets scanning across the SDLC, from open-source CLI use through enterprise secrets programmes, as a peer to tools such as GitGuardian and gitleaks-style workflows.
Worth knowing
TruffleHog open source is free. TruffleHog Enterprise is commercial with custom pricing (contact Truffle Security; marketplace listings exist). Official site trufflesecurity.com; brand assets at /branding; source on GitHub under trufflesecurity/trufflehog. Authorised secrets detection and remediation use only; do not use findings to abuse third-party systems.