TRUFFLEHOG ANALYZE

Understand the impact of your secrets

Understand the impact of your secrets

TruffleHog Analyze is the identity intelligence layer of TruffleHog Enterprise, mapping verified secrets to the non-human identities (NHIs) behind them.

Detection isn't the end of the investigation

Once a secret has been tested and confirmed as live, the next step is understanding its impact. Every leaked credential raises the same questions:

  • Who owns it?

  • What NHI does it represent?

  • What can it access?

  • How urgent is it?


TruffleHog Analyze answers those questions by mapping verified credentials to their associated NHIs, giving teams the identity and access context they need to prioritize remediation. Without requiring additional configuration, TruffleHog Analyze automatically queries provider APIs to retrieve the context teams need for investigation and remediation.

Turn verified secrets into actionable findings

Investigate every SaaS credential the same way

Identify the owner

Map verified credentials to their true owners so responders know who is responsible before remediation begins.

Understand access

See what the NHI can access so you can evaluate blast radius based on real permissions instead of assumptions.

Prioritize by risk

Identify low-risk development credentials from high-impact production identities so teams fix what matters first.

Accelerate remediation

Accelerate response with guided remediation that helps responders take the right next step and reduce risk quickly.

Different credentials require different investigation

Different credentials require different investigation

Analyze includes specialized analyzers for SaaS platforms, AWS, and Google Cloud, each designed to surface the identity and access context unique to that ecosystem.

Analyze includes specialized analyzers for SaaS platforms, AWS, and Google Cloud, each designed to surface the identity and access context unique to that ecosystem.

Analyze for SaaS

Understand the identity, ownership, and access behind 40+ supported SaaS analyzers.

Understand the identity, ownership, and access behind 40+ supported SaaS analyzers.

Learn more →

Analyze for AWS

Map AWS identities, effective permissions, assumable roles, and credential access to understand real blast radius.

Map AWS identities, effective permissions, assumable roles, and credential access to understand real blast radius.

Learn more →

Analyze for GCP

Visualize service account permissions, IAM inheritance, and accessible resources across your Google Cloud hierarchy.

Visualize service account permissions, IAM inheritance, and accessible resources across your Google Cloud hierarchy.

Learn more →

infra