godaddy / tartufoLinks
Searches through git repositories for high entropy strings and secrets, digging deep into commit history
☆506Updated last month
Alternatives and similar repositories for tartufo
Users that are interested in tartufo are comparing it to the libraries listed below
Sorting:
- CI/CD Security Analyzer☆659Updated 4 months ago
- tool designed for identifying vulnerabilities in open source codebases at scale. It can gather and filter on key repository metrics such …☆229Updated 5 months ago
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆220Updated last month
- Gram is Klarna's own threat model diagramming tool☆320Updated last week
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆527Updated 4 months ago
- A humble, and 𝗳𝗮𝘀𝘁, security-oriented HTTP headers analyzer.☆319Updated this week
- A suite of secret scanners built in Rust for performance. Based on TruffleHog (https://github.com/dxa4481/truffleHog) which is written in…☆517Updated 2 weeks ago
- boostsecurityio/poutine☆306Updated last week
- API Security Vulnerability Scanner designed to help you secure your APIs.☆152Updated this week
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆376Updated last week
- Awesome secure by default libraries to help you eliminate bug classes!☆697Updated 2 months ago
- Security tool against dependency typosquatting attacks☆52Updated last week
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆284Updated 5 months ago
- Light-weight web security scanner☆150Updated 4 months ago
- Secrets scanner that understands code☆188Updated last year
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applic…☆450Updated last year
- An open-source collection of API key rotation tutorials.☆70Updated 2 weeks ago
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆119Updated last year
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆813Updated 3 months ago
- An uber fast and simple subdomain enumeration tool using DNS and web requests with support for detecting wildcard DNS records.☆176Updated last year
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆213Updated 3 months ago
- A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration☆328Updated 2 weeks ago
- OXO is a security scanning orchestrator for the modern age.☆552Updated last week
- cloudgrep is grep for cloud storage☆325Updated 4 months ago
- A curated list of awesome GraphQL Security frameworks, libraries, software and resources☆338Updated last year
- 💀 Don't fear the Reaper 👻☆553Updated last week
- A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.☆146Updated 2 months ago
- Next Generation Software Composition Analysis (SCA) with Malicious Package Detection, Code Context & Policy as Code☆531Updated this week
- Secret Magpie - Secret Detection Tool☆232Updated last year
- GitHub Actions Pipeline Enumeration and Attack Tool☆675Updated 2 weeks ago