TruffleHog — Malware Profile
TruffleHog is an open-source secrets-discovery tool that is used to search for credentials, API keys, and encryption keys across a variety of data sources and environments. TruffleHog has the ability to discover credentials and secrets stored in code repositories, git history, CI/CD pipelines, among other common storage locations to include filesystems and cloud storage buckets. TruffleHog was first released by its author in 2016.
MITRE ATT&CK techniques (16)
- T1005 Data from Local System
- T1059.009 Cloud API
- T1078.004 Cloud Accounts
- T1083 File and Directory Discovery
- T1213.001 Confluence
- T1213.002 Sharepoint
- T1213.003 Code Repositories
- T1213.005 Messaging Applications
- T1526 Cloud Service Discovery
- T1528 Steal Application Access Token
- T1530 Data from Cloud Storage
- T1552.001 Credentials In Files
- T1552.005 Cloud Instance Metadata API
- T1555.006 Cloud Secrets Management Stores
- T1580 Cloud Infrastructure Discovery
- T1619 Cloud Storage Object Discovery