Skip to content

Entry

gitleaks

Appears in 5 awesome lists

Zachary Rice - Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repositories.

Open github.comzricethezav/gitleaks

Found in these lists

Awesome AWS Security

Section: Tools of Trade · Audit git repos for secrets

FreshScore 81

Awesome Bug Bounty Tools

Section: Secrets · Scan git repos (or files) for secrets using regex and entropy

FreshScore 89

Awesome Devsecops

Section: Secrets Scanning · Zachary Rice - Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repositories.

StaleScore 52

Awesome Web Security

Section: Leaking · Searches full repo history for secrets and keys by @zricethezav.

FreshScore 87

Static Analysis

Section: General · A SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos.

FreshScore 91

Cynative

🟢 — Local AI security research agent for cloud, code, and runtime environments across GitHub, GitLab, AWS, GCP, Azure, and Kubernetes, with read-only action gates, sandboxed code execution, evidence-backed verification, and audit logs. · updated 2026-08-14); Related: Fraim · EscalateGPT

In 6 listsDetails

Gitrob

a command line tool to find sensitive information lingering in publicly available files on GitHub

In 6 listsDetails

keyFinder

Chrome extension that passively discovers leaked API keys, tokens, secrets, and credentials on any web page by scanning scripts, meta tags, hidden fields, web storage, and network responses using 80+ detection patterns and Shannon entropy analysis.

In 5 listsDetails

Git Secrets

Prevents you from committing passwords and other sensitive information to a git repository.

In 5 listsDetails

trufflesecurity/trufflehog

Truffle Security - Searches through git repositories for secrets, digging deep into commit history and branches.

In 5 listsDetails

cloud-audit

Fast, opinionated AWS security scanner with 47 curated checks. Each finding includes copy-paste remediation in AWS CLI and Terraform. Features attack chain detection and a diff command for CI/CD pipeline gating.

In 4 listsDetails

AWS Tool Arsenal

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

In 4 lists

detect-secrets

An enterprise friendly way of detecting and preventing secrets in code. It does this by running periodic diff outputs against heuristically crafted regex statements, to identify whether any new secret has been committed. This way, it avoids the overhead of digging through all git history, as well…

In 3 lists