7,380 open-source and SaaS tools, with GitHub stats refreshed every day.

TruffleHog

Open source

TruffleHog finds, classifies and verifies leaked credentials across Git, chats, wikis, logs, filesystems and cloud storage.

Open-source alternative to

trufflesecurity.com
TruffleHog homepage screenshot
GitHub stars
28k
Last commit
today
Repository age
9 years
Version
v3.97.9
Licence
AGPL-3.0
Self-hosted
Yes

About TruffleHog

TruffleHog is a tool for discovering, classifying, validating and analyzing secrets, meaning credentials a machine uses to authenticate to another machine, such as API keys, database passwords and private keys. It is written in Go and released under the AGPL-3.0 license. It can be used from the command line and in pre-commit and CI scans as part of DevSecOps work.

Discovery reaches into Git repositories, chat tools, wikis, log files, API testing platforms, object stores and filesystems. Classification identifies more than 800 secret types and maps each to the identity it belongs to. Validation attempts to log in with the found secret to confirm whether it is still live, and analysis for roughly twenty common credential types sends further requests to learn who created the secret and what it can access. Truffle Security also sells an enterprise product that monitors systems such as Git, Jira, Slack and Confluence.

Key features

  • Scans Git, chats, wikis, logs and filesystems
  • Classifies over 800 secret types
  • Validates whether a found secret is live
  • Analyzes permissions of common credential types
  • Runs from the CLI and in pre-commit checks
  • Enterprise monitoring product available separately

Good fit for

  • โ†’Finding leaked keys in git history
  • โ†’Prioritizing exposed secrets that are still active
Built with
Go
Tags
secret-scanning
security
credentials
devsecops
git
pre-commit
golang
verification

TruffleHog: questions and answers

What is TruffleHog used for?
TruffleHog finds, classifies and verifies leaked credentials across Git, chats, wikis, logs, filesystems and cloud storage. It is a good fit for finding leaked keys in git history and prioritizing exposed secrets that are still active.
Is TruffleHog open source?
Yes. TruffleHog is open source under the AGPL-3.0 licence. Its source code is on GitHub at trufflesecurity/trufflehog and is written mainly in Go.
Is TruffleHog free?
Yes. TruffleHog is open source, so the software itself is free to use.
What is TruffleHog an alternative to?
TruffleHog is an open-source alternative to GitGuardian and Aikido Security. Other open-source alternatives to GitGuardian include Gitleaks and Trivy.
Is TruffleHog actively maintained?
Yes. The most recent commit to TruffleHog was on 2 October 2026, and the latest release is v3.97.9, published on 24 September 2026. The project has 28k stars on GitHub.

Open-source alternatives to TruffleHog

See all

SaaS alternatives to TruffleHog

See all