<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>secrets-scanner</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/3400/feed"/>
    <updated>2026-06-14T16:33:02+00:00</updated>
    <id>https://links.biapy.com/guest/tags/3400/feed</id>
            <entry>
            <id>https://links.biapy.com/links/12877</id>
            <title type="text"><![CDATA[ghosttype]]></title>
            <link rel="alternate" href="https://github.com/xFreed0m/ghosttype" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12877"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
 
Local forensic scanner that extracts and verifies credentials from AI tool conversation history. Detection + verification powered by TruffleHog.]]>
            </summary>
            <updated>2026-06-01T15:50:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12353</id>
            <title type="text"><![CDATA[layerleak]]></title>
            <link rel="alternate" href="https://github.com/Brumbelow/layerleak" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12353"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[layerleak the Docker Hub Secret Scanner.

Traditional secret scanners often treat a container image as a flat blob or depend on a local Docker daemon. This project is designed around OCI image internals]]>
            </summary>
            <updated>2026-03-28T18:07:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12300</id>
            <title type="text"><![CDATA[Betterleaks]]></title>
            <link rel="alternate" href="https://betterleaks.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12300"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Better Secrets Scanner. Detect Leaked API Keys &amp;amp; Credentials.
 A Better Secrets Scanner built for configurability and speed.

Betterleaks is a tool for detecting secrets like passwords, API keys, and tokens in git repos, files, and whatever else you wanna throw at it via stdin. If you wanna learn more about how the detection engine works check out this blog: [Regex is (almost) all you need](https://lookingatcomputer.substack.com/p/regex-is-almost-all-you-need).

- [Betterleaks @ GitHub](https://github.com/betterleaks/betterleaks).

Related contents:

- [Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks @ aikido](https://www.aikido.dev/blog/betterleaks-gitleaks-successor).]]>
            </summary>
            <updated>2026-03-26T13:38:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12236</id>
            <title type="text"><![CDATA[Nord Stream]]></title>
            <link rel="alternate" href="https://github.com/synacktiv/nord-stream" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12236"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab. 

Related contents:

- [CI/CD secrets extraction, tips and tricks @ Synacktiv](https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks).]]>
            </summary>
            <updated>2026-03-23T14:24:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12158</id>
            <title type="text"><![CDATA[bagel]]></title>
            <link rel="alternate" href="https://boostsecurityio.github.io/bagel/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12158"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Bagel is a cross-platform CLI that inspects developer workstations and produces a structured report of security findings. It allows developers to understand their attack surface and what could be of interest to a malicious actor.

- [bagel @ GitHub](https://github.com/boostsecurityio/bagel).

Related contents:

- [Bagel : scanner la posture sécurité de votre poste développeur @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/outils/bagel/).]]>
            </summary>
            <updated>2026-03-17T07:24:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12018</id>
            <title type="text"><![CDATA[CredSweeper]]></title>
            <link rel="alternate" href="https://github.com/Samsung/CredSweeper" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12018"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CredSweeper is an advanced credential detection tool designed to identify exposed credentials such as passwords, API keys, tokens, and other sensitive information across source code, configuration files, documents, and binary assets. CredSweeper scans regular files, embedded data in containers, and files added in Git commits. The tool combines pattern-based detection, machine learning–based validation, and deep file inspection to deliver comprehensive and accurate security scanning for modern codebases and repositories.

Related contents:

- [\#66 @ Erreur 403 :fr:](https://newsletter.erreur403.fr/p/erreur-403-66).]]>
            </summary>
            <updated>2026-03-05T12:09:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11929</id>
            <title type="text"><![CDATA[Titus]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/titus" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11929"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 459 detection rules with live credential validation.]]>
            </summary>
            <updated>2026-02-26T11:16:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3870</id>
            <title type="text"><![CDATA[TruffleHog]]></title>
            <link rel="alternate" href="https://trufflesecurity.com/trufflehog" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3870"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Find and verify secrets. Find leaked credentials.

TruffleHog is the most powerful secrets Discovery, Classification, Validation, and Analysis tool. In this context secret refers to a credential a machine uses to authenticate itself to another machine. This includes API keys, database passwords, private encryption keys, and more...

- [TruffleHog @ GitHub](https://github.com/trufflesecurity/trufflehog).

Related contents:

- [Keeping Secrets Out of Logs @ allan.reyes.sh](https://allan.reyes.sh/posts/keeping-secrets-out-of-logs/).
- [How Security Tool Misuse Is Reshaping Cloud Compromise @ Qualys](https://blog.qualys.com/qualys-insights/2026/02/19/how-security-tool-misuse-is-reshaping-cloud-compromise).]]>
            </summary>
            <updated>2026-03-05T12:17:59+00:00</updated>
        </entry>
    </feed>
