godaddy / tartufoLinks
Searches through git repositories for high entropy strings and secrets, digging deep into commit history
☆511Updated 3 weeks ago
Alternatives and similar repositories for tartufo
Users that are interested in tartufo are comparing it to the libraries listed below
Sorting:
- CI/CD Security Analyzer☆722Updated 9 months ago
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆227Updated this week
- tool designed for identifying vulnerabilities in open source codebases at scale. It can gather and filter on key repository metrics such …☆234Updated 9 months ago
- A humble, and 𝗳𝗮𝘀𝘁, security-oriented HTTP headers analyzer.☆347Updated this week
- Gram is Klarna's own threat model diagramming tool☆327Updated last month
- Secrets scanner that understands code☆191Updated 2 years ago
- A suite of secret scanners built in Rust for performance. Based on TruffleHog (https://github.com/dxa4481/truffleHog) which is written in…☆536Updated 4 months ago
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆312Updated last month
- cloudgrep is grep for cloud storage☆325Updated 8 months ago
- An uber fast and simple subdomain enumeration tool using DNS and web requests with support for detecting wildcard DNS records.☆174Updated last year
- Customized CVE FEED Notifier☆114Updated 7 months ago
- API Security Vulnerability Scanner designed to help you secure your APIs.☆219Updated this week
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆557Updated 3 weeks ago
- A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Sec…☆304Updated 3 months ago
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆121Updated 2 years ago
- Awesome secure by default libraries to help you eliminate bug classes!☆700Updated 7 months ago
- OXO is a security scanning orchestrator for the modern age.☆559Updated last week
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆463Updated 2 weeks ago
- find dangling domains in a multi cloud environment☆173Updated 3 weeks ago
- A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration☆333Updated this week
- GitHub Actions Pipeline Enumeration and Attack Tool☆712Updated 2 months ago
- Prevent merging of malicious code in pull requests☆239Updated 8 months ago
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆818Updated 7 months ago
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applic…☆461Updated last year
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆37Updated last year
- An open-source collection of API key rotation tutorials.☆74Updated 2 months ago
- boostsecurityio/poutine☆345Updated this week
- Light-weight web security scanner☆150Updated 8 months ago
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git☆136Updated this week
- Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams☆75Updated this week