1200KM / tool
TruffleHog — Attack Tool
TruffleHog is an open-source secrets-discovery tool that is used to search for credentials, API keys, and encryption keys across a variety of data sources and environments. TruffleHog has the ability to discover credentials and secrets stored in code repositories, git history, CI/CD pipelines, among other common storage locations to include filesystems and cloud storage buckets. TruffleHog was first released by its author in 2016.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: TruffleHog, Trufflehog
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1005 · Data from Local System · Detection rules & anomalies
- T1059.009 · Cloud API · Detection rules & anomalies
- T1078.004 · Cloud Accounts · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1213.001 · Confluence · Detection rules & anomalies
- T1213.002 · Sharepoint · Detection rules & anomalies
- T1213.003 · Code Repositories · Detection rules & anomalies
- T1213.005 · Messaging Applications · Detection rules & anomalies
- T1526 · Cloud Service Discovery · Detection rules & anomalies
- T1528 · Steal Application Access Token · Detection rules & anomalies
- T1530 · Data from Cloud Storage · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1552.005 · Cloud Instance Metadata API · Detection rules & anomalies
- T1555.006 · Cloud Secrets Management Stores · Detection rules & anomalies
- T1580 · Cloud Infrastructure Discovery · Detection rules & anomalies
- T1619 · Cloud Storage Object Discovery · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Cloud Service Enumeration · DC0083
- Cloud Service Metadata · DC0070
- Cloud Service Modification · DC0069
- Cloud Storage Access · DC0025
- Cloud Storage Enumeration · DC0017
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- Instance Enumeration · DC0075
- Instance Metadata · DC0086
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Process Creation · DC0032
- User Account Authentication · DC0002
- User Account Metadata · DC0013
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.