godaddy / tartufoLinks
Searches through git repositories for high entropy strings and secrets, digging deep into commit history
☆509Updated 3 weeks ago
Alternatives and similar repositories for tartufo
Users that are interested in tartufo are comparing it to the libraries listed below
Sorting:
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆228Updated last month
- CI/CD Security Analyzer☆728Updated 10 months ago
- tool designed for identifying vulnerabilities in open source codebases at scale. It can gather and filter on key repository metrics such …☆235Updated 11 months ago
- Gram is Klarna's own threat model diagramming tool☆330Updated 2 weeks ago
- Secrets scanner that understands code☆191Updated 2 years ago
- A suite of secret scanners built in Rust for performance. Based on TruffleHog (https://github.com/dxa4481/truffleHog) which is written in…☆535Updated 6 months ago
- A humble, and 𝗳𝗮𝘀𝘁, security-oriented HTTP headers analyzer.☆348Updated this week
- API Security Vulnerability Scanner designed to help you secure your APIs.☆229Updated last week
- An uber fast and simple subdomain enumeration tool using DNS and web requests with support for detecting wildcard DNS records.☆173Updated last year
- Security tool against dependency typosquatting attacks☆54Updated this week
- OXO is a security scanning orchestrator for the modern age.☆559Updated last week
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆315Updated 2 months ago
- cloudgrep is grep for cloud storage☆327Updated 10 months ago
- Prevent merging of malicious code in pull requests☆253Updated 9 months ago
- A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Sec…☆315Updated 4 months ago
- Light-weight web security scanner☆149Updated last month
- An open-source collection of API key rotation tutorials.☆76Updated 4 months ago
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆37Updated 2 years ago
- Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams☆78Updated 3 weeks ago
- Scan for secrets in dangling commits on GitHub using GH Archive data.☆415Updated 6 months ago
- GitHub Actions Pipeline Enumeration and Attack Tool☆724Updated 3 months ago
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆120Updated 2 years ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆158Updated last year
- FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).☆180Updated last year
- Awesome secure by default libraries to help you eliminate bug classes!☆700Updated last month
- A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration☆335Updated 3 weeks ago
- A multi-vault secret injection tool for safely injecting secrets into app environment☆131Updated last week
- Identify hardcoded secrets in static structured text (version 2)☆96Updated 11 months ago
- ☆314Updated 5 months ago
- A Powerful Network Reconnaissance Tool for Security Professionals☆106Updated last year