godaddy / tartufoLinks
Searches through git repositories for high entropy strings and secrets, digging deep into commit history
☆507Updated 2 months ago
Alternatives and similar repositories for tartufo
Users that are interested in tartufo are comparing it to the libraries listed below
Sorting:
- CI/CD Security Analyzer☆667Updated 6 months ago
- Gram is Klarna's own threat model diagramming tool☆324Updated 3 weeks ago
- A humble, and 𝗳𝗮𝘀𝘁, security-oriented HTTP headers analyzer.☆329Updated last week
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆220Updated 2 months ago
- tool designed for identifying vulnerabilities in open source codebases at scale. It can gather and filter on key repository metrics such …☆232Updated 6 months ago
- An uber fast and simple subdomain enumeration tool using DNS and web requests with support for detecting wildcard DNS records.☆176Updated last year
- A suite of secret scanners built in Rust for performance. Based on TruffleHog (https://github.com/dxa4481/truffleHog) which is written in…☆524Updated last month
- Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams☆52Updated this week
- API Security Vulnerability Scanner designed to help you secure your APIs.☆165Updated this week
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆536Updated 6 months ago
- Secrets scanner that understands code☆188Updated last year
- Customized CVE FEED Notifier☆114Updated 4 months ago
- cloudgrep is grep for cloud storage☆326Updated 6 months ago
- OXO is a security scanning orchestrator for the modern age.☆556Updated 3 weeks ago
- A multi-vault secret injection tool for safely injecting secrets into app environment☆128Updated last week
- boostsecurityio/poutine☆309Updated last week
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆36Updated last year
- FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).☆179Updated last year
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆297Updated 3 weeks ago
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applic…☆452Updated last year
- Attack surface detector that identifies endpoints by static analysis☆730Updated this week
- Awesome secure by default libraries to help you eliminate bug classes!☆699Updated 4 months ago
- A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration☆330Updated last week
- Security tool against dependency typosquatting attacks☆53Updated this week
- An open-source collection of API key rotation tutorials.☆72Updated 2 months ago
- The Internets #1 Subdomain Takeover Tool☆266Updated 2 months ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆152Updated 9 months ago
- ☆82Updated 7 months ago
- Static code analyser for backdoors and malicious code in git repos using OpenAI compatible LLM APIs☆73Updated last year
- Secret Magpie - Secret Detection Tool☆236Updated last year