Microsoft Sharepoint
Microsoft SharePoint
Edition: Enterprise and Hosted Scanner Only
The Microsoft SharePoint integration scans files, site pages, attachments, and comments in Microsoft SharePoint for credentials and other sensitive data.
Configuration
The Microsoft SharePoint integration is configured in TruffleHog under Integrations. Local configuration is not available for this source.
Web configuration
Configure this integration from the Integrations page in TruffleHog.
SharePoint integration configuration screen
You'll need to grant the integration the following scopes:
- AllSites.Read — read access to all sites in your SharePoint workspace.
- Sites.Search.All — navigate the contents of your SharePoint workspace.
- offline_access — maintain detection state across scans.
When prompted, check Consent on behalf of your organization to grant access for all users in the organization. This option only appears for admin users.
Finding your Site URL. When the integration prompts for a Site URL, it expects the root of your SharePoint workspace — not a specific site path. To find it:
- Log into SharePoint.
- Open any SharePoint site.
- Copy the portion of the URL up to and including .com. For example: https://trufflesecurity.sharepoint.com.
Capabilities
Feature | Supported |
|---|---|
Scan files | ✅ |
Scan file versions | ✅ |
Scan SitePages | ✅ |
Scan generic lists | ✅ |
Scan attachments | ✅ |
Scan comments | ✅ |
Scan forms | ✅ |
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Scan Microsoft Office files | ✅ |
Auto-resume | ✅ |
Scan OneNote notebooks | ❌ |
Notes
- Files larger than 10 MB are not scanned.
- Drafts are not scanned.