
TRUFFLEHOG ANALYZE
FOR AWS
FOR AWS
Understand the impact of your secrets
Understand the impact of your secrets
Exposed secrets are IAM security risks, not just static code issues.
A leaked AWS credential doesn't reveal its true risk
A leaked AWS credential doesn't reveal its true risk
A single access key can inherit permissions through IAM policies, groups, and assumable roles. Understanding what a credential can actually access often requires manually tracing those relationships before remediation can begin.
Analyze for AWS surfaces the identity and access context teams need to understand risk and prioritize remediation.
A single access key can inherit permissions through IAM policies, groups, and assumable roles. Understanding what a credential can actually access often requires manually tracing those relationships before remediation can begin.
Analyze for AWS surfaces the identity and access context teams need to understand risk and prioritize remediation.
Complete identity and access context for AWS credentials
Complete identity and access context for AWS credentials
Analyze every leaked AWS credential from four perspectives:
Analyze every leaked AWS credential from four perspectives:

Identify the AWS identity
See the AWS non-human identity behind a leaked credential, including the associated IAM user or role, so you know exactly what you're investigating.
Assess effective permissions
See the effective permissions granted to a leaked AWS credential so you can understand what it can actually access, not just the IAM policies attached to it.


Trace privilege paths
Analyze direct and single-hop assumable roles to understand how far a compromised credential could extend its access across your AWS environment.
Turn IAM complexity into actionable findings
Turn IAM complexity into actionable findings
AWS IAM policies, effective permissions, and assumable roles can make credential investigations difficult to piece together manually. Analyze for AWS brings that context together so teams can understand effective access, prioritize remediation, and respond with confidence.
AWS IAM policies, effective permissions, and assumable roles can make credential investigations difficult to piece together manually. Analyze for AWS brings that context together so teams can understand effective access, prioritize remediation, and respond with confidence.
Learn more about TruffleHog Analyze
Learn more about TruffleHog Analyze
Every surface presents different investigation challenges. TruffleHog Analyze includes specialized analyzers for AWS, Google Cloud, and supported SaaS credential types, each designed to surface the identity and access context unique to that environment while maintaining a consistent investigation workflow.
Every surface presents different investigation challenges. TruffleHog Analyze includes specialized analyzers for AWS, Google Cloud, and supported SaaS credential types, each designed to surface the identity and access context unique to that environment while maintaining a consistent investigation workflow.
Analyze for GCP
Visualize service account permissions, IAM inheritance, and accessible resources across your Google Cloud hierarchy.
Visualize service account permissions, IAM inheritance, and accessible resources across your Google Cloud hierarchy.
Learn more →



The Dig
Thoughts, research findings, reports, and more from Truffle Security Co.
The Dig
Thoughts, research findings, reports, and more from Truffle Security Co.
STAY STRONG
DIG DEEP
TRUFFLEHOG
DOING IT THE RIGHT WAY
© 2026 Truffle Security Co.
STAY STRONG
DIG DEEP
© 2026 Truffle Security Co.

