🚀BIG NEWS! Truffle Security raised a $25M Series B led by @intelcapital & @a16z to accelerate making secrets easier to manage
🐷 Starting today - TruffleHog GCP Analyze maps leaked GCP secrets, their permissions & reach to remediate with confidence
🔗 https://t.co/AXMIVpvKW3
🔥 You can now add TruffleHog to Burp Suite!
🌐 Install it directly from the BApp Store
🔍Scan web traffic for live, verified credentials—active & exploitable
Because secrets don’t just leak in code… 😬
Big Thanks to @PortSwigger ! 🙌
🔗https://t.co/1fZKNgJUKC
💁💥 Today we’re unlocking a novel method of detecting AWS canary tokens, completely statically, without setting them off.
This feature is now natively built into TruffleHog, learn more: https://t.co/GaSFroERvl
@securitypuck@trufflesec Thanks for the praise! If you didn't already know, you can use a native TruffleHog integration for GitHub to take care of the enumeration for you:
`trufflehog github --help`
It can even scan the issue comments, PR comments, gist comments, etc.
🐷 TruffleHog now shows AWS account IDs for live and revoked keys!
🔐Shoutout to @TalBeerySec for finding #AWS Account Numbers hidden in access keys. 🙀Easily discovered with a base-32 decode & bit shift!
👀 Read @JoeLeonJr interview with Tal: https://t.co/uzr1O13P36
🔍Study shows 74% of exposed API keys still live after 1 month! @JoeLeonJr reveals:
📉 Only 26% keys revoked in 31 days
🔑 For keys removed, 1/2 remain live
📚 63% files exposing keys still public!
Need details? Check Joe’s blog 👉 https://t.co/ViQtnIKAGc
😱 4,500 of the Top 1 Million Websites Leaked Source Code, Secrets
→ Found by searching <domain>.com/.git
* AWS/GitHub keys: 45% leaked credentials
* 67% of GitHub creds had Admin Access
B y @trufflesec, @harshbothra_, @hakluke
https://t.co/en4uOl8yAW
🚀 Excited to open source our collection of API key rotation tutorials for #AWS, #GitHub , and more. After detecting a leaked secret with TruffleHog, the most effective way to remediate a leaked secret is with API Key rotation.
👉Check out the guides: https://t.co/Od87TNkBJE
Ever get tempted to reflexively take down an exposed secret?
That wont fix your troubles unfortunately. Here's what you need to do:
https://t.co/znyvbe30uy
if you look at the CISA stats:
https://t.co/hISbotjFYV
~88% of pwnage is from the attacker having a set of credentials that work... (phishing, brute force or theft etc.)
Cybercrime is largely stealing credentials....
lot's of "IT people" say stuff like:
well sure if you have credentials then you have the data...
this is not how CYBER DEFENSE works... this is why as whole (partly) why the world fails to defend!
People don’t realize how often live keys leak out on GitHub in 2023, despite this being a known problem for almost a decade.
Next week we’re releasing a tool to check if your company exposed any. Here’s a thread on it 1/6
@SwiftOnSecurity TruffleHog v3 can detect a few archive formats for finding and verifying credentials within them as well. Really useful for scanning Jars, APKs, docx files, etc. This combined with its decoders allow it to find credentials within binaries too!