daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

2-5-cheatsheet-trufflehog.md (26206B)


      1 ---
      2 title: "2.5 - Cheatsheet - TruffleHog"
      3 description: "brew install trufflehog"
      4 category: enumeration
      5 alsoIn: ["osint"]
      6 tags: ["enumeration", "osint", "secret-scanning"]
      7 tools: ["Gitleaks", "TruffleHog"]
      8 difficulty: intermediate
      9 updated: "2026-08-10"
     10 source: "vault:Enumeration/GitHub-Enum/2.5 - Cheatsheet - TruffleHog.md"
     11 ---
     12 ## Installation
     13 
     14 ```bash
     15 # macOS — Homebrew
     16 brew install trufflehog
     17 
     18 # Linux — install script (always fetches latest)
     19 curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh \
     20   | sh -s -- -b /usr/local/bin
     21 
     22 # Docker (no install required — pull and run)
     23 docker pull trufflesecurity/trufflehog:latest
     24 
     25 # Verify install
     26 trufflehog --version
     27 # Output:
     28 # trufflehog 3.88.1
     29 ```
     30 
     31 > [!info]+ Command Breakdown
     32 > 1. The **install script** always pulls the latest release binary — no need to track version numbers manually
     33 > 2. **-b /usr/local/bin** — places the binary in your PATH; change to `~/bin` if you don't have sudo
     34 > 3. The **Docker** option is useful on systems where you can't install binaries — swap any command below using `docker run --rm trufflesecurity/trufflehog:latest [subcommand]`
     35 
     36 ---
     37 
     38 ## Subcommands at a Glance
     39 
     40 | Subcommand | What It Scans | OSINT Use Case |
     41 |---|---|---|
     42 | `git` | Single git repository — full commit history | Cloned public repos, any local git repo |
     43 | `github` | Entire GitHub org or specific repo — including issues and PRs | Scan all of a company's public repos at once |
     44 | `gitlab` | GitLab org or specific project | European/self-hosted company repos |
     45 | `filesystem` | Local directories and files | Downloaded files, extracted archives, scraped content |
     46 | `s3` | AWS S3 buckets | Misconfigured public buckets found via GrayHatWarfare/Dorks |
     47 | `gcs` | Google Cloud Storage buckets | GCP-hosted company storage |
     48 | `docker` | Docker image layers | Find secrets baked into company Docker images |
     49 | `stdin` | Piped data stream | Scan any streamed content |
     50 | `circleci` | CircleCI build logs | CI/CD pipeline secret exposure |
     51 | `travisci` | Travis CI build logs | CI/CD pipeline secret exposure |
     52 | `jenkins` | Jenkins build logs | Self-hosted CI secret exposure |
     53 | `postman` | Postman workspaces | API collection secrets |
     54 | `elasticsearch` | Elasticsearch indices | Database-stored secrets |
     55 
     56 ---
     57 
     58 ## Understanding Results — The Verification Model
     59 
     60 > [!important]+ Result Types — Know These Before You Scan
     61 > TruffleHog classifies every finding into one of four result types. Use `--results=` to control what is shown:
     62 
     63 | Result Type | Meaning | What to Do |
     64 |---|---|---|
     65 | `verified` | Secret found AND confirmed live by API call | **Highest priority** — escalate immediately |
     66 | `unknown` | Secret found, API call inconclusive (no clear pass/fail) | Investigate manually — still worth reporting |
     67 | `unverified` | Secret found BUT API call confirmed it is invalid/expired | Lower priority — may still be useful for password reuse |
     68 | `filtered_unverified` | Duplicate unverified results filtered out | Noise reduction only |
     69 
     70 ```bash
     71 # Default — shows ALL result types (noisy but complete)
     72 trufflehog git https://github.com/target-org/target-repo.git
     73 
     74 # Focused — only show confirmed live secrets (fastest triage)
     75 trufflehog git https://github.com/target-org/target-repo.git --results=verified,unknown
     76 
     77 # Passive mode — no API verification calls at all (safest for engagements)
     78 trufflehog git https://github.com/target-org/target-repo.git --no-verification
     79 ```
     80 
     81 > [!info]+ Command Breakdown
     82 > 1. **--results=verified,unknown** — the most useful filter for OSINT; catches live secrets and anything the API couldn't definitively reject
     83 > 2. **--no-verification** — disables all outbound API calls; TruffleHog acts like a pattern matcher only; use this when you want passive-only operation during an engagement
     84 > 3. *Start every scan with `--results=verified,unknown` — if nothing comes back, broaden to all results*
     85 
     86 ---
     87 
     88 ## Exit Codes
     89 
     90 | Exit Code | Meaning |
     91 |---|---|
     92 | `0` | No errors, no results found |
     93 | `1` | An error was encountered — scan may be incomplete |
     94 | `183` | No errors, but **results were found** — only returned when `--fail` flag is used |
     95 
     96 ```bash
     97 # Use --fail to get exit code 183 on findings — useful in scripts
     98 trufflehog git . --results=verified,unknown --fail
     99 echo "Exit: $?"
    100 # Exit: 183   ← secrets found
    101 ```
    102 
    103 ---
    104 
    105 ## Core Scan Commands
    106 
    107 ### Scan a Single Git Repository
    108 
    109 ```bash
    110 # Scan a remote repo directly (no manual clone needed)
    111 trufflehog git https://github.com/target-org/target-repo.git \
    112   --results=verified,unknown \
    113   --json
    114 
    115 # Scan a locally cloned repo
    116 trufflehog git file:///home/user/target-repo \
    117   --results=verified,unknown \
    118   --json
    119 
    120 # Output example:
    121 {
    122   "SourceMetadata": {
    123     "Data": {
    124       "Git": {
    125         "commit": "a3f2c1d9e8b74561...",
    126         "file": "config/settings.py",
    127         "email": "dev@target.com",
    128         "repository": "https://github.com/target-org/target-repo.git",
    129         "timestamp": "2023-04-18 14:22:01 +0000",
    130         "line": 12
    131       }
    132     }
    133   },
    134   "SourceID": 1,
    135   "SourceType": 16,
    136   "SourceName": "trufflehog - git",
    137   "DetectorType": 2,
    138   "DetectorName": "AWS",
    139   "DecoderName": "PLAIN",
    140   "Verified": true,
    141   "Raw": "AKIAIOSFODNN7EXAMPLE",
    142   "RawV2": "AKIAIOSFODNN7EXAMPLEwJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY",
    143   "Redacted": "AKIAIOSFODNN7EXAMPLE",
    144   "ExtraData": {
    145     "account": "123456789012",
    146     "arn": "arn:aws:iam::123456789012:user/dev",
    147     "user_id": "AIDA..."
    148   },
    149   "StructuredData": null
    150 }
    151 ```
    152 
    153 > [!info]+ Command Breakdown
    154 > 1. **file://** — URI scheme for local paths; TruffleHog requires an explicit scheme (`https://`, `file://`, or `ssh://`)
    155 > 2. **--json** — outputs each finding as a JSON object — one per line (NDJSON format) — essential for piping to `jq`
    156 > 3. **Verified: true** — TruffleHog called the AWS API and confirmed this key is live
    157 > 4. **ExtraData** — for verified AWS keys, TruffleHog returns the account ID, ARN, and user ID — you know exactly whose account was compromised without touching the infrastructure
    158 > 5. **RawV2** — for credentials with two parts (key ID + secret), both values are shown
    159 > 6. *The `email` field in `SourceMetadata` gives you the committer's email — direct attribution*
    160 
    161 ---
    162 
    163 ### Scan a Specific Branch or Commit Depth
    164 
    165 ```bash
    166 # Scan a specific branch only
    167 trufflehog git https://github.com/target-org/target-repo.git \
    168   --branch=develop \
    169   --results=verified,unknown \
    170   --json
    171 
    172 # Limit to the last N commits
    173 trufflehog git https://github.com/target-org/target-repo.git \
    174   --max-depth=100 \
    175   --results=verified,unknown
    176 
    177 # Start scan from a specific commit (scan everything after this hash)
    178 trufflehog git https://github.com/target-org/target-repo.git \
    179   --since-commit=a3f2c1d9e8b74561 \
    180   --results=verified,unknown
    181 ```
    182 
    183 > [!info]+ Command Breakdown
    184 > 1. **--branch** — restricts scan to one branch; combine with multiple runs to cover all branches
    185 > 2. **--max-depth** — limits how many commits deep to scan from HEAD; useful for large repos where you only care about recent history
    186 > 3. **--since-commit** — start scanning from after this commit hash; useful for delta scans (only check what changed since last run)
    187 > 4. *Unlike Gitleaks, TruffleHog does NOT have an `--all` flag for all branches — run it per branch or use the `github` subcommand to cover all branches automatically*
    188 
    189 ---
    190 
    191 ### Scan an Entire GitHub Organisation
    192 
    193 ```bash
    194 # Unauthenticated — public repos only (rate-limited to ~60 req/hr)
    195 trufflehog github --org=target-org \
    196   --results=verified,unknown \
    197   --json
    198 
    199 # Authenticated — public + private repos (rate-limited to ~5000 req/hr)
    200 trufflehog github --org=target-org \
    201   --token=ghp_YourGitHubPAThere \
    202   --results=verified,unknown \
    203   --json
    204 
    205 # Scan a specific repo via the github subcommand (also scans issues + PRs)
    206 trufflehog github \
    207   --repo=https://github.com/target-org/target-repo \
    208   --issue-comments \
    209   --pr-comments \
    210   --results=verified,unknown \
    211   --json
    212 ```
    213 
    214 > [!info]+ Command Breakdown
    215 > 1. **--org** — scans ALL repositories belonging to the organisation — the most powerful single-command recon capability TruffleHog has over Gitleaks
    216 > 2. **--token** — GitHub PAT; use a throwaway account's PAT for OSINT — never your real account
    217 > 3. **--issue-comments** — scans issue comment text — devs frequently paste credentials into issue comments ("here's the key to reproduce this bug: `sk-...`")
    218 > 4. **--pr-comments** — scans pull request comments and review threads — another common accidental paste location
    219 > 5. *The org-level scan is the single most impactful command for OSINT — one command, every repo, all history, verified results*
    220 
    221 ---
    222 
    223 ### Scan a Filesystem or Directory
    224 
    225 ```bash
    226 # Scan a downloaded directory
    227 trufflehog filesystem /path/to/downloaded/files \
    228   --results=verified,unknown \
    229   --json
    230 
    231 # Scan a single file
    232 trufflehog filesystem /path/to/suspicious/.env \
    233   --results=verified,unknown
    234 
    235 # Scan current directory
    236 trufflehog filesystem . --results=verified,unknown --json
    237 
    238 # Scan with archive extraction (zip, tar.gz, etc.)
    239 trufflehog filesystem /path/to/directory \
    240   --results=verified,unknown \
    241   --archive-max-depth=5 \
    242   --archive-max-size=100MB \
    243   --json
    244 ```
    245 
    246 > [!info]+ Command Breakdown
    247 > 1. **filesystem** — no git context required; scans raw file contents; useful for downloaded cloud bucket files, scraped web content, or extracted archives
    248 > 2. **--archive-max-depth** — how many levels of nested archives to open and scan (e.g., a `.zip` inside a `.tar.gz`); default is disabled
    249 > 3. **--archive-max-size** — caps how large an archive can be before TruffleHog skips it; prevents memory exhaustion on large files
    250 > 4. *Pair with GrayHatWarfare — download files from public buckets, then run TruffleHog filesystem over the download folder with archive scanning enabled*
    251 
    252 ---
    253 
    254 ### Scan an S3 Bucket
    255 
    256 ```bash
    257 # Scan a public or accessible bucket (uses ~/.aws/credentials automatically)
    258 trufflehog s3 --bucket=target-company-assets \
    259   --results=verified,unknown \
    260   --json
    261 
    262 # Scan using an assumed IAM role (for cross-account scanning)
    263 trufflehog s3 --bucket=target-bucket \
    264   --role-arn=arn:aws:iam::123456789012:role/ScannerRole \
    265   --results=verified,unknown
    266 
    267 # Scan ALL buckets accessible via multiple roles
    268 trufflehog s3 \
    269   --role-arn=arn:aws:iam::111111111111:role/Role1 \
    270   --role-arn=arn:aws:iam::222222222222:role/Role2 \
    271   --results=verified,unknown
    272 ```
    273 
    274 > [!info]+ Command Breakdown
    275 > 1. TruffleHog uses the **AWS SDK** — it automatically picks up credentials from `~/.aws/credentials`, environment variables, or EC2 instance metadata
    276 > 2. **--role-arn** — assume an IAM role before scanning; useful if you have a role ARN from a leaked key and want to enumerate what that role can access
    277 > 3. Multiple **--role-arn** flags — TruffleHog scans all buckets each role has `s3:ListBucket` permissions on — one command enumerates and scans everything reachable
    278 > 4. *If you find an AWS key via git scanning, verify it with `aws sts get-caller-identity`, then pivot: use the same key to run TruffleHog against all accessible S3 buckets*
    279 
    280 ---
    281 
    282 ### Scan a Docker Image
    283 
    284 ```bash
    285 # Scan a public Docker image from Docker Hub
    286 trufflehog docker --image=target-org/target-app:latest \
    287   --results=verified,unknown \
    288   --json
    289 
    290 # Scan a specific image by digest (for precise version targeting)
    291 trufflehog docker --image=target-org/app@sha256:abc123... \
    292   --results=verified,unknown \
    293   --json
    294 ```
    295 
    296 > [!info]+ Command Breakdown
    297 > 1. TruffleHog scans **each layer** of the Docker image — secrets baked in during build (e.g., `RUN curl -H "Authorization: Bearer $TOKEN"`) survive in image layers even if later layers delete them
    298 > 2. Uses Docker Hub's public API — no authentication needed for public images
    299 > 3. **Image digest scanning** allows scanning a specific build — if a company publishes versioned images, older versions may contain secrets removed in newer builds
    300 > 4. *Company Docker images are often on Docker Hub or GitHub Container Registry — search `docker.io/[company-name]` or `ghcr.io/[org-name]` for public images*
    301 
    302 ---
    303 
    304 ### Scan via stdin
    305 
    306 ```bash
    307 # Scan a file piped from curl — no local save needed
    308 curl -s https://target-bucket.s3.amazonaws.com/.env \
    309   | trufflehog stdin --results=verified,unknown --json
    310 
    311 # Scan any command output
    312 cat suspicious_config.py | trufflehog stdin --results=verified,unknown
    313 ```
    314 
    315 > [!info]+ Command Breakdown
    316 > 1. **stdin** — accepts raw streamed content; anything that produces output can be scanned
    317 > 2. Combine with `curl` to triage a suspicious file from a public URL instantly
    318 > 3. *Fastest initial triage method — pipe before deciding whether to fully download a file*
    319 
    320 ---
    321 
    322 ## Output and Triage
    323 
    324 ### JSON Output with jq Triage
    325 
    326 ```bash
    327 # Save all findings to a file
    328 trufflehog github --org=target-org \
    329   --results=verified,unknown \
    330   --json > findings.json 2>/dev/null
    331 
    332 # Show only verified findings — simplest triage
    333 cat findings.json | jq 'select(.Verified == true)'
    334 
    335 # Extract key fields for a clean summary
    336 cat findings.json | jq -r '
    337   select(.Verified == true) |
    338   "\(.DetectorName) | \(.SourceMetadata.Data.Git.file) | \(.SourceMetadata.Data.Git.email) | \(.Raw[0:20])..."
    339 '
    340 # Output:
    341 # AWS | config/settings.py | dev@target.com | AKIAIOSFODNN7EXAMPL...
    342 # GitHub | scripts/deploy.sh | ci@target.com | ghp_aBcDeFgHiJkLmN...
    343 
    344 # Count findings by detector type
    345 cat findings.json | jq -r '.DetectorName' | sort | uniq -c | sort -rn
    346 # Output:
    347 #  14 GenericAPIKey
    348 #   3 AWS
    349 #   1 GitHub
    350 
    351 # Get ExtraData for verified AWS keys (account ID, ARN, user)
    352 cat findings.json | jq 'select(.DetectorName == "AWS" and .Verified == true) | .ExtraData'
    353 # Output:
    354 # {
    355 #   "account": "123456789012",
    356 #   "arn": "arn:aws:iam::123456789012:user/ci-deploy",
    357 #   "user_id": "AIDA4EXAMPLE"
    358 # }
    359 ```
    360 
    361 > [!info]+ Command Breakdown
    362 > 1. **2>/dev/null** — suppresses TruffleHog's progress logs; keeps the JSON output clean for piping
    363 > 2. **select(.Verified == true)** — jq filter that only returns verified findings
    364 > 3. **\(.Raw[0:20])...** — shows only the first 20 chars of the secret — enough to identify it without printing the full value in terminal history
    365 > 4. **uniq -c | sort -rn** — counts and sorts by frequency — tells you which secret type is most prevalent
    366 > 5. **ExtraData** — the intelligence goldmine for AWS findings — account ID tells you the AWS account; ARN tells you the user; these confirm the blast radius of the leak
    367 
    368 ---
    369 
    370 ### Controlling Noise — Entropy and Detector Filters
    371 
    372 ```bash
    373 # Filter low-entropy unverified results (reduces generic false positives)
    374 # Start at 3.0 and increase if still too noisy
    375 trufflehog git https://github.com/target-org/repo.git \
    376   --results=unverified \
    377   --filter-entropy=3.5 \
    378   --json
    379 
    380 # Scan ONLY specific detector types (focus on high-value targets)
    381 trufflehog git https://github.com/target-org/repo.git \
    382   --include-detectors="AWS,GitHub,GitLab,Slack,Stripe,OpenAI" \
    383   --results=verified,unknown \
    384   --json
    385 
    386 # Exclude noisy low-value detectors
    387 trufflehog git https://github.com/target-org/repo.git \
    388   --exclude-detectors="GenericAPIKey,URI" \
    389   --results=verified,unknown \
    390   --json
    391 ```
    392 
    393 > [!info]+ Command Breakdown
    394 > 1. **--filter-entropy** — [Shannon entropy](https://en.wikipedia.org/wiki/Entropy_(information_theory)) score threshold; only show unverified results above this score; higher entropy = more random = more likely to be a real secret; `3.5` is a good starting value
    395 > 2. **--include-detectors** — comma-separated list; restrict to only the detectors you care about; eliminates entire categories of noise
    396 > 3. **--exclude-detectors** — `GenericAPIKey` and `URI` are the noisiest detectors; excluding them dramatically reduces false positives when you just want high-confidence results
    397 > 4. *For OSINT triage: start with `--include-detectors="AWS,GitHub,GitLab,Slack,Stripe,OpenAI,Twilio"` — these are the highest-impact credentials*
    398 
    399 ---
    400 
    401 > [!tip]+ High-Value Detector Priority List
    402 > | Priority | Detector | Why |
    403 > |---|---|---|
    404 > | **Critical** | `AWS` | Direct cloud infrastructure access — account takeover |
    405 > | **Critical** | `GitHub` | Access to code, Actions secrets, repo admin |
    406 > | **Critical** | `GitLab` | Same as GitHub for GitLab-hosted companies |
    407 > | **High** | `Slack` | Internal comms — further OSINT, social engineering |
    408 > | **High** | `Stripe` | Financial API — direct monetary impact |
    409 > | **High** | `OpenAI` | AI API access — often expensive, reveals internal tooling |
    410 > | **High** | `Twilio` | SMS/voice API — phishing pivot, account takeover via 2FA |
    411 > | **Medium** | `Sendgrid` / `Mailgun` | Email sending — phishing infrastructure |
    412 > | **Medium** | `Postman` | Reveals internal API structure and endpoints |
    413 > | **Medium** | `HuggingFace` | ML model access — internal AI tooling |
    414 
    415 ---
    416 
    417 ## The `analyze` Subcommand — Key Permission Enumeration
    418 
    419 ```bash
    420 # Interactively analyse a found key — TruffleHog auto-detects the type
    421 trufflehog analyze --token=AKIAIOSFODNN7EXAMPLEwJalrXUtnFEMI
    422 
    423 # Specify key type explicitly
    424 trufflehog analyze github --token=ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456
    425 
    426 # JSON output for scripting
    427 trufflehog analyze github \
    428   --token=ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456 \
    429   --json
    430 
    431 # Output:
    432 # {
    433 #   "token_type": "GitHub",
    434 #   "permissions": {
    435 #     "repo": "write",
    436 #     "admin:org": "none",
    437 #     "read:user": "read",
    438 #     "workflow": "write"
    439 #   },
    440 #   "scopes": ["repo", "read:user", "workflow"],
    441 #   "username": "ci-deploy-bot",
    442 #   "org_memberships": ["target-org"]
    443 # }
    444 ```
    445 
    446 > [!info]+ Command Breakdown
    447 > 1. **analyze** — TruffleHog's unique capability; takes a found credential and enumerates exactly what permissions it has, without you having to manually test each API endpoint
    448 > 2. Supported key types: AWS, GitHub, GitLab, Slack, Stripe, Twilio, OpenAI, Postman, Shopify, Sendgrid, Mailchimp, Mailgun, Bitbucket, HuggingFace, and more
    449 > 3. **permissions** output — tells you exactly what the key can do: read-only? Write access? Admin? — determines the blast radius before you even make a decision
    450 > 4. **org_memberships** — for GitHub tokens, reveals which organisations the token has access to — one leaked personal token can expose multiple organisations
    451 > 5. *This replaces manually calling `aws sts get-caller-identity`, `curl https://api.github.com/user`, etc. — TruffleHog does it all in one command*
    452 
    453 > [!warning]+ analyze Makes Live API Calls
    454 > 1. Every `analyze` run makes real API calls to the target service
    455 > 2. These calls may be logged by the service — AWS CloudTrail, GitHub audit logs, etc.
    456 > 3. In an engagement: get written approval to verify credentials before running `analyze`
    457 > 4. Use `--no-verification` during scanning and `analyze` only on the highest-confidence findings after scope confirmation
    458 
    459 ---
    460 
    461 ## Custom Detectors — Target-Specific Patterns
    462 
    463 ```yaml
    464 # custom-detectors.yaml
    465 # Reference with --config=custom-detectors.yaml
    466 
    467 detectors:
    468   - name: TargetCorpInternalToken
    469     keywords:
    470       - "TGT-"
    471     regex:
    472       secret: "TGT-[a-zA-Z0-9]{32}"
    473     verify:
    474       - endpoint: "https://api.target-internal.com/v1/auth/verify"
    475         unsafe: true
    476         headers:
    477           - "Authorization: Bearer $secret"
    478         successRanges:
    479           - "200-299"
    480 
    481   - name: TargetCorpJWTSecret
    482     keywords:
    483       - "jwt_secret"
    484       - "JWT_SECRET"
    485     regex:
    486       secret: '(?i)jwt_secret\s*[=:]\s*["'']([a-zA-Z0-9+/=]{40,})["'']'
    487 ```
    488 
    489 ```bash
    490 # Run with custom detectors alongside default ruleset
    491 trufflehog git https://github.com/target-org/repo.git \
    492   --config=custom-detectors.yaml \
    493   --results=verified,unknown \
    494   --json
    495 ```
    496 
    497 > [!info]+ Command Breakdown
    498 > 1. **keywords** — pre-filter strings TruffleHog looks for before applying the regex; improves scan performance
    499 > 2. **regex.secret** — the capture group that extracts the actual secret value
    500 > 3. **verify.endpoint** — TruffleHog will call this URL with the found secret to verify it — returns `verified: true` if the response is in `successRanges`
    501 > 4. **unsafe: true** — required for non-HTTPS endpoints (internal APIs); omit for public HTTPS endpoints
    502 > 5. *Custom detectors give TruffleHog's verification power to company-specific secrets discovered through job posting and LinkedIn OSINT*
    503 
    504 ---
    505 
    506 ## Full OSINT Workflow
    507 
    508 ```bash
    509 # ── PHASE 1: Org-Level Sweep ──────────────────────────────────────────
    510 # Scan the entire GitHub org — all repos, all history, verify everything
    511 trufflehog github \
    512   --org=target-org \
    513   --results=verified,unknown \
    514   --json \
    515   --no-update \
    516   2>/dev/null | tee org-findings.json
    517 
    518 # ── PHASE 2: Triage ───────────────────────────────────────────────────
    519 # Count by detector type — identify the biggest wins
    520 cat org-findings.json | jq -r '.DetectorName' | sort | uniq -c | sort -rn
    521 
    522 # Pull all verified findings with attribution
    523 cat org-findings.json | jq -r '
    524   select(.Verified == true) |
    525   [.DetectorName, .SourceMetadata.Data.Git.repository, .SourceMetadata.Data.Git.file,
    526    .SourceMetadata.Data.Git.email, .SourceMetadata.Data.Git.commit] | @tsv
    527 ' | column -t
    528 
    529 # ── PHASE 3: Deep Dive High-Value Repos ───────────────────────────────
    530 # For repos with findings — run Gitleaks for full history depth
    531 git clone https://github.com/target-org/high-value-repo.git
    532 gitleaks git -v --log-opts="--all" --report-path=repo-findings.json ./high-value-repo
    533 
    534 # ── PHASE 4: Expand to Cloud ──────────────────────────────────────────
    535 # If AWS keys were found — scan all accessible S3 buckets with them
    536 export AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE
    537 export AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
    538 trufflehog s3 --results=verified,unknown --json 2>/dev/null | tee s3-findings.json
    539 
    540 # ── PHASE 5: Analyse Key Permissions ──────────────────────────────────
    541 # For each high-value verified credential
    542 trufflehog analyze github --token=ghp_FoundToken --json
    543 trufflehog analyze aws --token=AKIAIOSFODNN7EXAMPLE:wJalrXUtnFEMI/K7MDENG --json
    544 
    545 # ── PHASE 6: Docker Images ────────────────────────────────────────────
    546 # Check public Docker images for the org
    547 trufflehog docker \
    548   --image=target-org/main-app:latest \
    549   --results=verified,unknown \
    550   --json 2>/dev/null | tee docker-findings.json
    551 ```
    552 
    553 > [!info]+ Workflow Breakdown
    554 > 1. **Phase 1** — `tee` writes to file AND shows on terminal simultaneously; `2>/dev/null` suppresses progress noise; `--no-update` skips the version check for speed
    555 > 2. **Phase 2** — the `@tsv | column -t` combination produces a clean aligned table of all verified findings with repo, file, email, and commit — copy-paste ready for a report
    556 > 3. **Phase 3** — TruffleHog catches live secrets; Gitleaks catches historical patterns — they complement each other; use both on high-value repos
    557 > 4. **Phase 4** — a verified AWS key is the bridge from code recon to cloud infrastructure recon; TruffleHog can enumerate all buckets that key has access to automatically
    558 > 5. **Phase 5** — `analyze` tells you the blast radius before you escalate — no manual API testing required
    559 > 6. **Phase 6** — Docker layers frequently contain secrets from build-time environment variables and RUN commands that were never intended to persist
    560 
    561 ---
    562 
    563 > [!success]+ What to Do with a Verified Finding
    564 > 1. **Record** — detector name, raw value (first 20 chars only), file, commit hash, author email, repository, timestamp
    565 > 2. **Analyse** — run `trufflehog analyze [type] --token=[value] --json` to enumerate permissions and blast radius
    566 > 3. **Confirm scope** — verify the credential's service is within your engagement scope before proceeding
    567 > 4. **Document** — include verification status, `ExtraData` (account IDs, ARNs, usernames), and permissions in your report
    568 > 5. **Do not exploit** beyond confirming the credential is valid — accessing systems, exfiltrating data, or making changes is out of bounds
    569 
    570 ---
    571 
    572 ## References
    573 
    574 1. [TruffleHog GitHub Repository](https://github.com/trufflesecurity/trufflehog)
    575 2. [TruffleHog Official Documentation](https://docs.trufflesecurity.com/)
    576 3. [TruffleHog Scanning Git — 2024 Comprehensive Guide](https://trufflesecurity.com/blog/scanning-git-for-secrets-the-2024-comprehensive-guide)
    577 4. [TruffleHog Analyze — Key Permissions Blog Post](https://trufflesecurity.com/blog/trufflehog-now-analyzes-permissions-of-api-keys-and-passwords)
    578 5. [TruffleHog Git vs Filesystem Commands](https://trufflesecurity.com/blog/trufflehog-commands-git-vs-filesystem)
    579 6. [Driftwood — Private Key Verification](https://trufflesecurity.com/blog/driftwood)
    580 7. [TruffleHog Custom Detectors](https://github.com/trufflesecurity/trufflehog/blob/main/pkg/custom_detectors/CUSTOM_DETECTORS.md)
    581 8. [Shannon Entropy — Wikipedia](https://en.wikipedia.org/wiki/Entropy_(information_theory))
    582 9. [HTB Academy - Footprinting Module](https://academy.hackthebox.com/module/details/112)
    583 10. [HackTricks - OSINT](https://book.hacktricks.xyz/generic-methodologies-and-resources/external-recon-methodology)
    584 11. [MITRE ATT&CK - Search Open Technical Databases (T1596)](https://attack.mitre.org/techniques/T1596/)
    585 12. [Source: 2.4 - Cheatsheet - Gitleaks](02Cybersecurity/Cheatsheets/Enumeration/GitHub-Enum/2.4%20-%20Cheatsheet%20-%20Gitleaks.md)
    586 13. [Source: 2.3 - Theory Staff](2.3%20-%20Theory%20Staff.md)
    587 14. [Source: 2.0 - Cheatsheet - Infrastructure Enumeration Tools](2.0%20-%20Cheatsheet%20-%20Infrastructure%20Enumeration%20Tools.md)
    588 
    589 ---
    590 
    591 #HTB #Footprinting #OSINT #TruffleHog #SecretScanning #CredentialVerification #GitHistory #AWS #GitHub #Cheatsheet #PassiveRecon