2-5-cheatsheet-trufflehog.md (26206B)
1 --- 2 title: "2.5 - Cheatsheet - TruffleHog" 3 description: "brew install trufflehog" 4 category: enumeration 5 alsoIn: ["osint"] 6 tags: ["enumeration", "osint", "secret-scanning"] 7 tools: ["Gitleaks", "TruffleHog"] 8 difficulty: intermediate 9 updated: "2026-08-10" 10 source: "vault:Enumeration/GitHub-Enum/2.5 - Cheatsheet - TruffleHog.md" 11 --- 12 ## Installation 13 14 ```bash 15 # macOS — Homebrew 16 brew install trufflehog 17 18 # Linux — install script (always fetches latest) 19 curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh \ 20 | sh -s -- -b /usr/local/bin 21 22 # Docker (no install required — pull and run) 23 docker pull trufflesecurity/trufflehog:latest 24 25 # Verify install 26 trufflehog --version 27 # Output: 28 # trufflehog 3.88.1 29 ``` 30 31 > [!info]+ Command Breakdown 32 > 1. The **install script** always pulls the latest release binary — no need to track version numbers manually 33 > 2. **-b /usr/local/bin** — places the binary in your PATH; change to `~/bin` if you don't have sudo 34 > 3. The **Docker** option is useful on systems where you can't install binaries — swap any command below using `docker run --rm trufflesecurity/trufflehog:latest [subcommand]` 35 36 --- 37 38 ## Subcommands at a Glance 39 40 | Subcommand | What It Scans | OSINT Use Case | 41 |---|---|---| 42 | `git` | Single git repository — full commit history | Cloned public repos, any local git repo | 43 | `github` | Entire GitHub org or specific repo — including issues and PRs | Scan all of a company's public repos at once | 44 | `gitlab` | GitLab org or specific project | European/self-hosted company repos | 45 | `filesystem` | Local directories and files | Downloaded files, extracted archives, scraped content | 46 | `s3` | AWS S3 buckets | Misconfigured public buckets found via GrayHatWarfare/Dorks | 47 | `gcs` | Google Cloud Storage buckets | GCP-hosted company storage | 48 | `docker` | Docker image layers | Find secrets baked into company Docker images | 49 | `stdin` | Piped data stream | Scan any streamed content | 50 | `circleci` | CircleCI build logs | CI/CD pipeline secret exposure | 51 | `travisci` | Travis CI build logs | CI/CD pipeline secret exposure | 52 | `jenkins` | Jenkins build logs | Self-hosted CI secret exposure | 53 | `postman` | Postman workspaces | API collection secrets | 54 | `elasticsearch` | Elasticsearch indices | Database-stored secrets | 55 56 --- 57 58 ## Understanding Results — The Verification Model 59 60 > [!important]+ Result Types — Know These Before You Scan 61 > TruffleHog classifies every finding into one of four result types. Use `--results=` to control what is shown: 62 63 | Result Type | Meaning | What to Do | 64 |---|---|---| 65 | `verified` | Secret found AND confirmed live by API call | **Highest priority** — escalate immediately | 66 | `unknown` | Secret found, API call inconclusive (no clear pass/fail) | Investigate manually — still worth reporting | 67 | `unverified` | Secret found BUT API call confirmed it is invalid/expired | Lower priority — may still be useful for password reuse | 68 | `filtered_unverified` | Duplicate unverified results filtered out | Noise reduction only | 69 70 ```bash 71 # Default — shows ALL result types (noisy but complete) 72 trufflehog git https://github.com/target-org/target-repo.git 73 74 # Focused — only show confirmed live secrets (fastest triage) 75 trufflehog git https://github.com/target-org/target-repo.git --results=verified,unknown 76 77 # Passive mode — no API verification calls at all (safest for engagements) 78 trufflehog git https://github.com/target-org/target-repo.git --no-verification 79 ``` 80 81 > [!info]+ Command Breakdown 82 > 1. **--results=verified,unknown** — the most useful filter for OSINT; catches live secrets and anything the API couldn't definitively reject 83 > 2. **--no-verification** — disables all outbound API calls; TruffleHog acts like a pattern matcher only; use this when you want passive-only operation during an engagement 84 > 3. *Start every scan with `--results=verified,unknown` — if nothing comes back, broaden to all results* 85 86 --- 87 88 ## Exit Codes 89 90 | Exit Code | Meaning | 91 |---|---| 92 | `0` | No errors, no results found | 93 | `1` | An error was encountered — scan may be incomplete | 94 | `183` | No errors, but **results were found** — only returned when `--fail` flag is used | 95 96 ```bash 97 # Use --fail to get exit code 183 on findings — useful in scripts 98 trufflehog git . --results=verified,unknown --fail 99 echo "Exit: $?" 100 # Exit: 183 ← secrets found 101 ``` 102 103 --- 104 105 ## Core Scan Commands 106 107 ### Scan a Single Git Repository 108 109 ```bash 110 # Scan a remote repo directly (no manual clone needed) 111 trufflehog git https://github.com/target-org/target-repo.git \ 112 --results=verified,unknown \ 113 --json 114 115 # Scan a locally cloned repo 116 trufflehog git file:///home/user/target-repo \ 117 --results=verified,unknown \ 118 --json 119 120 # Output example: 121 { 122 "SourceMetadata": { 123 "Data": { 124 "Git": { 125 "commit": "a3f2c1d9e8b74561...", 126 "file": "config/settings.py", 127 "email": "dev@target.com", 128 "repository": "https://github.com/target-org/target-repo.git", 129 "timestamp": "2023-04-18 14:22:01 +0000", 130 "line": 12 131 } 132 } 133 }, 134 "SourceID": 1, 135 "SourceType": 16, 136 "SourceName": "trufflehog - git", 137 "DetectorType": 2, 138 "DetectorName": "AWS", 139 "DecoderName": "PLAIN", 140 "Verified": true, 141 "Raw": "AKIAIOSFODNN7EXAMPLE", 142 "RawV2": "AKIAIOSFODNN7EXAMPLEwJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY", 143 "Redacted": "AKIAIOSFODNN7EXAMPLE", 144 "ExtraData": { 145 "account": "123456789012", 146 "arn": "arn:aws:iam::123456789012:user/dev", 147 "user_id": "AIDA..." 148 }, 149 "StructuredData": null 150 } 151 ``` 152 153 > [!info]+ Command Breakdown 154 > 1. **file://** — URI scheme for local paths; TruffleHog requires an explicit scheme (`https://`, `file://`, or `ssh://`) 155 > 2. **--json** — outputs each finding as a JSON object — one per line (NDJSON format) — essential for piping to `jq` 156 > 3. **Verified: true** — TruffleHog called the AWS API and confirmed this key is live 157 > 4. **ExtraData** — for verified AWS keys, TruffleHog returns the account ID, ARN, and user ID — you know exactly whose account was compromised without touching the infrastructure 158 > 5. **RawV2** — for credentials with two parts (key ID + secret), both values are shown 159 > 6. *The `email` field in `SourceMetadata` gives you the committer's email — direct attribution* 160 161 --- 162 163 ### Scan a Specific Branch or Commit Depth 164 165 ```bash 166 # Scan a specific branch only 167 trufflehog git https://github.com/target-org/target-repo.git \ 168 --branch=develop \ 169 --results=verified,unknown \ 170 --json 171 172 # Limit to the last N commits 173 trufflehog git https://github.com/target-org/target-repo.git \ 174 --max-depth=100 \ 175 --results=verified,unknown 176 177 # Start scan from a specific commit (scan everything after this hash) 178 trufflehog git https://github.com/target-org/target-repo.git \ 179 --since-commit=a3f2c1d9e8b74561 \ 180 --results=verified,unknown 181 ``` 182 183 > [!info]+ Command Breakdown 184 > 1. **--branch** — restricts scan to one branch; combine with multiple runs to cover all branches 185 > 2. **--max-depth** — limits how many commits deep to scan from HEAD; useful for large repos where you only care about recent history 186 > 3. **--since-commit** — start scanning from after this commit hash; useful for delta scans (only check what changed since last run) 187 > 4. *Unlike Gitleaks, TruffleHog does NOT have an `--all` flag for all branches — run it per branch or use the `github` subcommand to cover all branches automatically* 188 189 --- 190 191 ### Scan an Entire GitHub Organisation 192 193 ```bash 194 # Unauthenticated — public repos only (rate-limited to ~60 req/hr) 195 trufflehog github --org=target-org \ 196 --results=verified,unknown \ 197 --json 198 199 # Authenticated — public + private repos (rate-limited to ~5000 req/hr) 200 trufflehog github --org=target-org \ 201 --token=ghp_YourGitHubPAThere \ 202 --results=verified,unknown \ 203 --json 204 205 # Scan a specific repo via the github subcommand (also scans issues + PRs) 206 trufflehog github \ 207 --repo=https://github.com/target-org/target-repo \ 208 --issue-comments \ 209 --pr-comments \ 210 --results=verified,unknown \ 211 --json 212 ``` 213 214 > [!info]+ Command Breakdown 215 > 1. **--org** — scans ALL repositories belonging to the organisation — the most powerful single-command recon capability TruffleHog has over Gitleaks 216 > 2. **--token** — GitHub PAT; use a throwaway account's PAT for OSINT — never your real account 217 > 3. **--issue-comments** — scans issue comment text — devs frequently paste credentials into issue comments ("here's the key to reproduce this bug: `sk-...`") 218 > 4. **--pr-comments** — scans pull request comments and review threads — another common accidental paste location 219 > 5. *The org-level scan is the single most impactful command for OSINT — one command, every repo, all history, verified results* 220 221 --- 222 223 ### Scan a Filesystem or Directory 224 225 ```bash 226 # Scan a downloaded directory 227 trufflehog filesystem /path/to/downloaded/files \ 228 --results=verified,unknown \ 229 --json 230 231 # Scan a single file 232 trufflehog filesystem /path/to/suspicious/.env \ 233 --results=verified,unknown 234 235 # Scan current directory 236 trufflehog filesystem . --results=verified,unknown --json 237 238 # Scan with archive extraction (zip, tar.gz, etc.) 239 trufflehog filesystem /path/to/directory \ 240 --results=verified,unknown \ 241 --archive-max-depth=5 \ 242 --archive-max-size=100MB \ 243 --json 244 ``` 245 246 > [!info]+ Command Breakdown 247 > 1. **filesystem** — no git context required; scans raw file contents; useful for downloaded cloud bucket files, scraped web content, or extracted archives 248 > 2. **--archive-max-depth** — how many levels of nested archives to open and scan (e.g., a `.zip` inside a `.tar.gz`); default is disabled 249 > 3. **--archive-max-size** — caps how large an archive can be before TruffleHog skips it; prevents memory exhaustion on large files 250 > 4. *Pair with GrayHatWarfare — download files from public buckets, then run TruffleHog filesystem over the download folder with archive scanning enabled* 251 252 --- 253 254 ### Scan an S3 Bucket 255 256 ```bash 257 # Scan a public or accessible bucket (uses ~/.aws/credentials automatically) 258 trufflehog s3 --bucket=target-company-assets \ 259 --results=verified,unknown \ 260 --json 261 262 # Scan using an assumed IAM role (for cross-account scanning) 263 trufflehog s3 --bucket=target-bucket \ 264 --role-arn=arn:aws:iam::123456789012:role/ScannerRole \ 265 --results=verified,unknown 266 267 # Scan ALL buckets accessible via multiple roles 268 trufflehog s3 \ 269 --role-arn=arn:aws:iam::111111111111:role/Role1 \ 270 --role-arn=arn:aws:iam::222222222222:role/Role2 \ 271 --results=verified,unknown 272 ``` 273 274 > [!info]+ Command Breakdown 275 > 1. TruffleHog uses the **AWS SDK** — it automatically picks up credentials from `~/.aws/credentials`, environment variables, or EC2 instance metadata 276 > 2. **--role-arn** — assume an IAM role before scanning; useful if you have a role ARN from a leaked key and want to enumerate what that role can access 277 > 3. Multiple **--role-arn** flags — TruffleHog scans all buckets each role has `s3:ListBucket` permissions on — one command enumerates and scans everything reachable 278 > 4. *If you find an AWS key via git scanning, verify it with `aws sts get-caller-identity`, then pivot: use the same key to run TruffleHog against all accessible S3 buckets* 279 280 --- 281 282 ### Scan a Docker Image 283 284 ```bash 285 # Scan a public Docker image from Docker Hub 286 trufflehog docker --image=target-org/target-app:latest \ 287 --results=verified,unknown \ 288 --json 289 290 # Scan a specific image by digest (for precise version targeting) 291 trufflehog docker --image=target-org/app@sha256:abc123... \ 292 --results=verified,unknown \ 293 --json 294 ``` 295 296 > [!info]+ Command Breakdown 297 > 1. TruffleHog scans **each layer** of the Docker image — secrets baked in during build (e.g., `RUN curl -H "Authorization: Bearer $TOKEN"`) survive in image layers even if later layers delete them 298 > 2. Uses Docker Hub's public API — no authentication needed for public images 299 > 3. **Image digest scanning** allows scanning a specific build — if a company publishes versioned images, older versions may contain secrets removed in newer builds 300 > 4. *Company Docker images are often on Docker Hub or GitHub Container Registry — search `docker.io/[company-name]` or `ghcr.io/[org-name]` for public images* 301 302 --- 303 304 ### Scan via stdin 305 306 ```bash 307 # Scan a file piped from curl — no local save needed 308 curl -s https://target-bucket.s3.amazonaws.com/.env \ 309 | trufflehog stdin --results=verified,unknown --json 310 311 # Scan any command output 312 cat suspicious_config.py | trufflehog stdin --results=verified,unknown 313 ``` 314 315 > [!info]+ Command Breakdown 316 > 1. **stdin** — accepts raw streamed content; anything that produces output can be scanned 317 > 2. Combine with `curl` to triage a suspicious file from a public URL instantly 318 > 3. *Fastest initial triage method — pipe before deciding whether to fully download a file* 319 320 --- 321 322 ## Output and Triage 323 324 ### JSON Output with jq Triage 325 326 ```bash 327 # Save all findings to a file 328 trufflehog github --org=target-org \ 329 --results=verified,unknown \ 330 --json > findings.json 2>/dev/null 331 332 # Show only verified findings — simplest triage 333 cat findings.json | jq 'select(.Verified == true)' 334 335 # Extract key fields for a clean summary 336 cat findings.json | jq -r ' 337 select(.Verified == true) | 338 "\(.DetectorName) | \(.SourceMetadata.Data.Git.file) | \(.SourceMetadata.Data.Git.email) | \(.Raw[0:20])..." 339 ' 340 # Output: 341 # AWS | config/settings.py | dev@target.com | AKIAIOSFODNN7EXAMPL... 342 # GitHub | scripts/deploy.sh | ci@target.com | ghp_aBcDeFgHiJkLmN... 343 344 # Count findings by detector type 345 cat findings.json | jq -r '.DetectorName' | sort | uniq -c | sort -rn 346 # Output: 347 # 14 GenericAPIKey 348 # 3 AWS 349 # 1 GitHub 350 351 # Get ExtraData for verified AWS keys (account ID, ARN, user) 352 cat findings.json | jq 'select(.DetectorName == "AWS" and .Verified == true) | .ExtraData' 353 # Output: 354 # { 355 # "account": "123456789012", 356 # "arn": "arn:aws:iam::123456789012:user/ci-deploy", 357 # "user_id": "AIDA4EXAMPLE" 358 # } 359 ``` 360 361 > [!info]+ Command Breakdown 362 > 1. **2>/dev/null** — suppresses TruffleHog's progress logs; keeps the JSON output clean for piping 363 > 2. **select(.Verified == true)** — jq filter that only returns verified findings 364 > 3. **\(.Raw[0:20])...** — shows only the first 20 chars of the secret — enough to identify it without printing the full value in terminal history 365 > 4. **uniq -c | sort -rn** — counts and sorts by frequency — tells you which secret type is most prevalent 366 > 5. **ExtraData** — the intelligence goldmine for AWS findings — account ID tells you the AWS account; ARN tells you the user; these confirm the blast radius of the leak 367 368 --- 369 370 ### Controlling Noise — Entropy and Detector Filters 371 372 ```bash 373 # Filter low-entropy unverified results (reduces generic false positives) 374 # Start at 3.0 and increase if still too noisy 375 trufflehog git https://github.com/target-org/repo.git \ 376 --results=unverified \ 377 --filter-entropy=3.5 \ 378 --json 379 380 # Scan ONLY specific detector types (focus on high-value targets) 381 trufflehog git https://github.com/target-org/repo.git \ 382 --include-detectors="AWS,GitHub,GitLab,Slack,Stripe,OpenAI" \ 383 --results=verified,unknown \ 384 --json 385 386 # Exclude noisy low-value detectors 387 trufflehog git https://github.com/target-org/repo.git \ 388 --exclude-detectors="GenericAPIKey,URI" \ 389 --results=verified,unknown \ 390 --json 391 ``` 392 393 > [!info]+ Command Breakdown 394 > 1. **--filter-entropy** — [Shannon entropy](https://en.wikipedia.org/wiki/Entropy_(information_theory)) score threshold; only show unverified results above this score; higher entropy = more random = more likely to be a real secret; `3.5` is a good starting value 395 > 2. **--include-detectors** — comma-separated list; restrict to only the detectors you care about; eliminates entire categories of noise 396 > 3. **--exclude-detectors** — `GenericAPIKey` and `URI` are the noisiest detectors; excluding them dramatically reduces false positives when you just want high-confidence results 397 > 4. *For OSINT triage: start with `--include-detectors="AWS,GitHub,GitLab,Slack,Stripe,OpenAI,Twilio"` — these are the highest-impact credentials* 398 399 --- 400 401 > [!tip]+ High-Value Detector Priority List 402 > | Priority | Detector | Why | 403 > |---|---|---| 404 > | **Critical** | `AWS` | Direct cloud infrastructure access — account takeover | 405 > | **Critical** | `GitHub` | Access to code, Actions secrets, repo admin | 406 > | **Critical** | `GitLab` | Same as GitHub for GitLab-hosted companies | 407 > | **High** | `Slack` | Internal comms — further OSINT, social engineering | 408 > | **High** | `Stripe` | Financial API — direct monetary impact | 409 > | **High** | `OpenAI` | AI API access — often expensive, reveals internal tooling | 410 > | **High** | `Twilio` | SMS/voice API — phishing pivot, account takeover via 2FA | 411 > | **Medium** | `Sendgrid` / `Mailgun` | Email sending — phishing infrastructure | 412 > | **Medium** | `Postman` | Reveals internal API structure and endpoints | 413 > | **Medium** | `HuggingFace` | ML model access — internal AI tooling | 414 415 --- 416 417 ## The `analyze` Subcommand — Key Permission Enumeration 418 419 ```bash 420 # Interactively analyse a found key — TruffleHog auto-detects the type 421 trufflehog analyze --token=AKIAIOSFODNN7EXAMPLEwJalrXUtnFEMI 422 423 # Specify key type explicitly 424 trufflehog analyze github --token=ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456 425 426 # JSON output for scripting 427 trufflehog analyze github \ 428 --token=ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ123456 \ 429 --json 430 431 # Output: 432 # { 433 # "token_type": "GitHub", 434 # "permissions": { 435 # "repo": "write", 436 # "admin:org": "none", 437 # "read:user": "read", 438 # "workflow": "write" 439 # }, 440 # "scopes": ["repo", "read:user", "workflow"], 441 # "username": "ci-deploy-bot", 442 # "org_memberships": ["target-org"] 443 # } 444 ``` 445 446 > [!info]+ Command Breakdown 447 > 1. **analyze** — TruffleHog's unique capability; takes a found credential and enumerates exactly what permissions it has, without you having to manually test each API endpoint 448 > 2. Supported key types: AWS, GitHub, GitLab, Slack, Stripe, Twilio, OpenAI, Postman, Shopify, Sendgrid, Mailchimp, Mailgun, Bitbucket, HuggingFace, and more 449 > 3. **permissions** output — tells you exactly what the key can do: read-only? Write access? Admin? — determines the blast radius before you even make a decision 450 > 4. **org_memberships** — for GitHub tokens, reveals which organisations the token has access to — one leaked personal token can expose multiple organisations 451 > 5. *This replaces manually calling `aws sts get-caller-identity`, `curl https://api.github.com/user`, etc. — TruffleHog does it all in one command* 452 453 > [!warning]+ analyze Makes Live API Calls 454 > 1. Every `analyze` run makes real API calls to the target service 455 > 2. These calls may be logged by the service — AWS CloudTrail, GitHub audit logs, etc. 456 > 3. In an engagement: get written approval to verify credentials before running `analyze` 457 > 4. Use `--no-verification` during scanning and `analyze` only on the highest-confidence findings after scope confirmation 458 459 --- 460 461 ## Custom Detectors — Target-Specific Patterns 462 463 ```yaml 464 # custom-detectors.yaml 465 # Reference with --config=custom-detectors.yaml 466 467 detectors: 468 - name: TargetCorpInternalToken 469 keywords: 470 - "TGT-" 471 regex: 472 secret: "TGT-[a-zA-Z0-9]{32}" 473 verify: 474 - endpoint: "https://api.target-internal.com/v1/auth/verify" 475 unsafe: true 476 headers: 477 - "Authorization: Bearer $secret" 478 successRanges: 479 - "200-299" 480 481 - name: TargetCorpJWTSecret 482 keywords: 483 - "jwt_secret" 484 - "JWT_SECRET" 485 regex: 486 secret: '(?i)jwt_secret\s*[=:]\s*["'']([a-zA-Z0-9+/=]{40,})["'']' 487 ``` 488 489 ```bash 490 # Run with custom detectors alongside default ruleset 491 trufflehog git https://github.com/target-org/repo.git \ 492 --config=custom-detectors.yaml \ 493 --results=verified,unknown \ 494 --json 495 ``` 496 497 > [!info]+ Command Breakdown 498 > 1. **keywords** — pre-filter strings TruffleHog looks for before applying the regex; improves scan performance 499 > 2. **regex.secret** — the capture group that extracts the actual secret value 500 > 3. **verify.endpoint** — TruffleHog will call this URL with the found secret to verify it — returns `verified: true` if the response is in `successRanges` 501 > 4. **unsafe: true** — required for non-HTTPS endpoints (internal APIs); omit for public HTTPS endpoints 502 > 5. *Custom detectors give TruffleHog's verification power to company-specific secrets discovered through job posting and LinkedIn OSINT* 503 504 --- 505 506 ## Full OSINT Workflow 507 508 ```bash 509 # ── PHASE 1: Org-Level Sweep ────────────────────────────────────────── 510 # Scan the entire GitHub org — all repos, all history, verify everything 511 trufflehog github \ 512 --org=target-org \ 513 --results=verified,unknown \ 514 --json \ 515 --no-update \ 516 2>/dev/null | tee org-findings.json 517 518 # ── PHASE 2: Triage ─────────────────────────────────────────────────── 519 # Count by detector type — identify the biggest wins 520 cat org-findings.json | jq -r '.DetectorName' | sort | uniq -c | sort -rn 521 522 # Pull all verified findings with attribution 523 cat org-findings.json | jq -r ' 524 select(.Verified == true) | 525 [.DetectorName, .SourceMetadata.Data.Git.repository, .SourceMetadata.Data.Git.file, 526 .SourceMetadata.Data.Git.email, .SourceMetadata.Data.Git.commit] | @tsv 527 ' | column -t 528 529 # ── PHASE 3: Deep Dive High-Value Repos ─────────────────────────────── 530 # For repos with findings — run Gitleaks for full history depth 531 git clone https://github.com/target-org/high-value-repo.git 532 gitleaks git -v --log-opts="--all" --report-path=repo-findings.json ./high-value-repo 533 534 # ── PHASE 4: Expand to Cloud ────────────────────────────────────────── 535 # If AWS keys were found — scan all accessible S3 buckets with them 536 export AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE 537 export AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY 538 trufflehog s3 --results=verified,unknown --json 2>/dev/null | tee s3-findings.json 539 540 # ── PHASE 5: Analyse Key Permissions ────────────────────────────────── 541 # For each high-value verified credential 542 trufflehog analyze github --token=ghp_FoundToken --json 543 trufflehog analyze aws --token=AKIAIOSFODNN7EXAMPLE:wJalrXUtnFEMI/K7MDENG --json 544 545 # ── PHASE 6: Docker Images ──────────────────────────────────────────── 546 # Check public Docker images for the org 547 trufflehog docker \ 548 --image=target-org/main-app:latest \ 549 --results=verified,unknown \ 550 --json 2>/dev/null | tee docker-findings.json 551 ``` 552 553 > [!info]+ Workflow Breakdown 554 > 1. **Phase 1** — `tee` writes to file AND shows on terminal simultaneously; `2>/dev/null` suppresses progress noise; `--no-update` skips the version check for speed 555 > 2. **Phase 2** — the `@tsv | column -t` combination produces a clean aligned table of all verified findings with repo, file, email, and commit — copy-paste ready for a report 556 > 3. **Phase 3** — TruffleHog catches live secrets; Gitleaks catches historical patterns — they complement each other; use both on high-value repos 557 > 4. **Phase 4** — a verified AWS key is the bridge from code recon to cloud infrastructure recon; TruffleHog can enumerate all buckets that key has access to automatically 558 > 5. **Phase 5** — `analyze` tells you the blast radius before you escalate — no manual API testing required 559 > 6. **Phase 6** — Docker layers frequently contain secrets from build-time environment variables and RUN commands that were never intended to persist 560 561 --- 562 563 > [!success]+ What to Do with a Verified Finding 564 > 1. **Record** — detector name, raw value (first 20 chars only), file, commit hash, author email, repository, timestamp 565 > 2. **Analyse** — run `trufflehog analyze [type] --token=[value] --json` to enumerate permissions and blast radius 566 > 3. **Confirm scope** — verify the credential's service is within your engagement scope before proceeding 567 > 4. **Document** — include verification status, `ExtraData` (account IDs, ARNs, usernames), and permissions in your report 568 > 5. **Do not exploit** beyond confirming the credential is valid — accessing systems, exfiltrating data, or making changes is out of bounds 569 570 --- 571 572 ## References 573 574 1. [TruffleHog GitHub Repository](https://github.com/trufflesecurity/trufflehog) 575 2. [TruffleHog Official Documentation](https://docs.trufflesecurity.com/) 576 3. [TruffleHog Scanning Git — 2024 Comprehensive Guide](https://trufflesecurity.com/blog/scanning-git-for-secrets-the-2024-comprehensive-guide) 577 4. [TruffleHog Analyze — Key Permissions Blog Post](https://trufflesecurity.com/blog/trufflehog-now-analyzes-permissions-of-api-keys-and-passwords) 578 5. [TruffleHog Git vs Filesystem Commands](https://trufflesecurity.com/blog/trufflehog-commands-git-vs-filesystem) 579 6. [Driftwood — Private Key Verification](https://trufflesecurity.com/blog/driftwood) 580 7. [TruffleHog Custom Detectors](https://github.com/trufflesecurity/trufflehog/blob/main/pkg/custom_detectors/CUSTOM_DETECTORS.md) 581 8. [Shannon Entropy — Wikipedia](https://en.wikipedia.org/wiki/Entropy_(information_theory)) 582 9. [HTB Academy - Footprinting Module](https://academy.hackthebox.com/module/details/112) 583 10. [HackTricks - OSINT](https://book.hacktricks.xyz/generic-methodologies-and-resources/external-recon-methodology) 584 11. [MITRE ATT&CK - Search Open Technical Databases (T1596)](https://attack.mitre.org/techniques/T1596/) 585 12. [Source: 2.4 - Cheatsheet - Gitleaks](02Cybersecurity/Cheatsheets/Enumeration/GitHub-Enum/2.4%20-%20Cheatsheet%20-%20Gitleaks.md) 586 13. [Source: 2.3 - Theory Staff](2.3%20-%20Theory%20Staff.md) 587 14. [Source: 2.0 - Cheatsheet - Infrastructure Enumeration Tools](2.0%20-%20Cheatsheet%20-%20Infrastructure%20Enumeration%20Tools.md) 588 589 --- 590 591 #HTB #Footprinting #OSINT #TruffleHog #SecretScanning #CredentialVerification #GitHistory #AWS #GitHub #Cheatsheet #PassiveRecon