TRUFFLEHOG

TRUFFLEHOG

FORAGER

FORAGER

A powerful scanning tool for the public web—seamlessly integrated with TruffleHog Enterprise.

A powerful scanning tool for the public web—seamlessly integrated with TruffleHog Enterprise.

Forager finds live secrets and verifies them with TruffleHog

Forager finds live secrets and verifies them with TruffleHog

It ties the secret to your organization using emails, account IDs*, or members of your GitHub organization**

*For AWS and GCP
**Regardless of the commit email used—cool, right?

Now you can view the details of the exposure in TruffleHog Enterprise

Expansive internet scanning

Scans the public internet for cloud service keys (like Google Cloud and AWS), including millions of push events on GitHub and NPM packages.

Go beyond domain matching

We go beyond domain matching and links leaks to specific account IDs for AWS and GCP.

On GitHub, Forager pulls members from the organization and monitors for leaks, regardless of commit email.

Monitoring and alerts

Alerts within minutes of a live key being detected, reducing the noise of false positives and irrelevant alerts.

Open-source flexibility

Supports more than 800 detectors, with the ability to add detectors easily through an open-source pull request.

Community

FREE!

Enterprise

Public internet scanning

GitHub and NPM packages

Leak detection

For company domain only

Goes beyond domain matching to link leaks to AWS or GCP account IDs or Github usernames for members of your organization*

Alerting

Alerts within minutes of a live key being detected for higher fidelity

Monitoring

Built-in dashboard for a centralized view of internal and external leaks

Open-source flexibility

Ability to add support for new keys and platforms

Community

FREE!

Enterprise

Public internet scanning of GitHub and NPM packages

Leak detection for company domain only

Goes beyond domain matching to link leaks to AWS or GCP account IDs or Github usernames for members of your organization*

Alerts within minutes of a live key being detected for higher fidelity

Built-in dashboard for a centralized view of internal and external leaks

Ability to add support for new keys and platforms

*Note that scanning solutions that link to keywords result in a higher number of false positives—we're all about the true positives here.

Take control of your secrets with TruffleHog

Contact us to protect your data across the entire SDLC

Get started

Take control of your secrets with TruffleHog

Contact us to protect your data across the entire SDLC

Get started