Awesome AWS Security
Section: Tools of Trade · Audit git repos for secrets
Entry
Appears in 5 awesome lists
Zachary Rice - Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repositories.
Section: Tools of Trade · Audit git repos for secrets
Section: Secrets · Scan git repos (or files) for secrets using regex and entropy
Section: Secrets Scanning · Zachary Rice - Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repositories.
Section: Leaking · Searches full repo history for secrets and keys by @zricethezav.
Section: General · A SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos.
🟢 — Local AI security research agent for cloud, code, and runtime environments across GitHub, GitLab, AWS, GCP, Azure, and Kubernetes, with read-only action gates, sandboxed code execution, evidence-backed verification, and audit logs. · updated 2026-08-14); Related: Fraim · EscalateGPT
a command line tool to find sensitive information lingering in publicly available files on GitHub
Chrome extension that passively discovers leaked API keys, tokens, secrets, and credentials on any web page by scanning scripts, meta tags, hidden fields, web storage, and network responses using 80+ detection patterns and Shannon entropy analysis.
Prevents you from committing passwords and other sensitive information to a git repository.
Truffle Security - Searches through git repositories for secrets, digging deep into commit history and branches.
Fast, opinionated AWS security scanner with 47 curated checks. Each finding includes copy-paste remediation in AWS CLI and Terraform. Features attack chain detection and a diff command for CI/CD pipeline gating.
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
An enterprise friendly way of detecting and preventing secrets in code. It does this by running periodic diff outputs against heuristically crafted regex statements, to identify whether any new secret has been committed. This way, it avoids the overhead of digging through all git history, as well…