trufflesecurity/trufflehog
Find, verify, and analyze leaked credentials
About the project
TruffleHog is a Go tool for finding leaked credentials: it scans Git, chats, wikis, logs and filesystems, classifies secrets across 800+ types, and verifies whether they are still live. It is aimed at security teams and developers auditing repos and infrastructure.
Useful for
- Scan a GitHub repo for live secrets before making code public
- Scan an entire GitHub org while excluding archived repositories
- Run checks in CI to block commits containing leaked keys
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 19 stars today.
- Over the last two days the pace is 2× that of the previous week and a half.
- The spike has held for 2 days in a row — not a one-off blip.
- GitHub Trending Go today: #18, +32 stars.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 27,866
- Stars in a day
- 19
- Forks
- 2,579
- Issues and pull requests
- 5,242
- Watchers
- 212
- Language
- Go
- License
- AGPL-3.0
- Latest release
- v3.97.4 · September 3, 2026
- Created
- December 31, 2016
- Last push
- September 12, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 13, 2026GitHub Trending Go today: #3, +32 stars
Similar projects
-
7.0
SnailSploit/Claude-Red
A curated library of drop-in SKILL.md files for the Claude Skills system that primes Claude with offensive security methodology, from SQL injection to EDR evasion and exploit development.
-
6.2
vxcontrol/pentagi
Autonomous multi-agent system in Go for automated penetration testing: AI agents plan and execute steps in an isolated Docker sandbox with 20+ tools (nmap, metasploit, sqlmap).
-
5.0
hezhanleiok/freesub
Automatically tests and publishes subscription pools of free proxy nodes (VLESS, VMess, Trojan, Shadowsocks, Hysteria2, TUIC, AnyTLS), filtering out dead and hijacked nodes via real HTTPS handshakes and TLS validation.
-
4.9
tsymbaluyk/maskgate
PII masking service that detects passports, tax IDs, SNILS, bank cards, phones, medical data and secrets in text and files and masks them before they reach ChatGPT, Claude, Gemini. Source code is proprietary; this repo…
-
4.3
zhihui-hu/one-ip
Web tool for IP lookups: identifies datacenter, VPN, Tor and proxy usage, rates reputation from 0 to 100, shows ASN, WHOIS, DNS, CDN, geolocation and checks AI service reachability.
-
4.2
realchendahuang/feedsieve
A Chrome extension that flags spam accounts on X (Twitter) with a yellow border and lets you block them manually or in bulk via the native API, synced across all devices.