2 repos
Core engines for detecting hardcoded credentials.
Distinguishing note: Focuses on the engine component of secret detection.
Explore 2 awesome GitHub repositories matching security & cryptography · Secret Scanning Engines. Refine with filters or upvote what's useful.
Gitleaks is a security scanning engine designed to identify hardcoded credentials, API keys, and other sensitive information within version control systems and local file structures. It functions as a static analysis tool that automates the detection of secrets, helping to prevent the accidental exposure of sensitive data during the development lifecycle. The tool distinguishes itself through its ability to perform deep forensic analysis of git history, allowing users to audit entire project timelines or enforce security gates within continuous integration pipelines. It supports complex detec
Identifies hardcoded credentials and sensitive information within version control history and local file systems.
Trufflehog is a security tool designed to continuously monitor code repositories and cloud environments to detect, verify, and remediate exposed sensitive credentials and API keys. It functions as a comprehensive secret scanning engine that integrates directly into deployment pipelines and version control systems to intercept sensitive data before it is committed or pushed. By utilizing read-only operations and volatile memory processing, the system ensures that discovered credentials are never stored persistently, maintaining strict data privacy throughout the scanning lifecycle. The platfor
Scans repositories to identify and prevent the accidental exposure of sensitive credentials.