Self-discovery analyzers
3 min
Before TruffleHog Analyze, identifying a key's access often meant manually digging through a SaaS provider's settings page. With TruffleHog Analyze, we use the API to automatically discover a key's metadata, resources, and permissions.
We use self-discovery techniques so that the discovery portion is stateless and minimizes potential impacts. These include the following:
- Inferring scope from headers and API endpoints
- Testing permissions via stateless API calls
- Sending malformed requests to stateful endpoints to observe permission errors
Example permission output for Hugging Face secret
