OSINT
TruffleHog
Finds leaked secrets in git repos and filesystems.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Code review, OSINT on public repos, or local secret scanning.
How
Scan repo URL or directory; verify active credentials carefully.
Why
Secrets in git are a top real-world initial access path.
Commands & usage
trufflehog git https://github.com/org/repo --only-verified
trufflehog filesystem /path/to/code
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in OSINT
Maltego
Graph-based link analysis for people, domains, infrastructure, and relationships.
theHarvester
Gathers emails, subdomains, hosts, and employee names from public sources.
Recon-ng
Modular recon framework with workspace DB and API-backed modules.
SpiderFoot
Automated OSINT scanner with web UI covering 200+ data sources.
Sherlock
Hunt usernames across hundreds of social sites.
Maigret
Username OSINT tool with report generation across many sites.