Analyze secrets
1 min
Exposed secrets arenโt just a code security issue โ theyโre an IAM risk. When a secret leaks, the key questions include: Is the key live? Who owns it? What does the key have access to?
TruffleHog Analyze evaluates access patterns to identify a secretโs metadata, permissions, and resources.
๏ปฟ
To get started with TruffleHog Analyze:
- In open-source: Run trufflehog analyze
- In enterprise: Contact your account executive
๏ปฟ
There are 2 types of TruffleHog Analyzers:
- ๏ปฟSelf-discovery analyzers๏ปฟ: These analyzers perform non-state-changing API calls to determine resources and permissions of a particular key.
- To see our supported analyzers, visit trufflesecurity.com/analyzers๏ปฟ
- Cloud analyze: These analyzers examine cloud secrets by connecting to your cloud environments to determine a secrets IAM posture. This is an enterprise-only feature.
- ๏ปฟGCP analyze๏ปฟ is currently supported.