fully autonomous credential intelligence platform that discovers, │ │ extracts, correlates, verifies, and reports exposed secrets across your │ │ target's entire attack surface.
-
Updated
May 10, 2026 - Python
fully autonomous credential intelligence platform that discovers, │ │ extracts, correlates, verifies, and reports exposed secrets across your │ │ target's entire attack surface.
Self-hosted secret scanning. 900+ detection rules across 53 modules, AI triage to cut false positives, and provider verification so you know which keys are actually live. Source-available under the Vooda Community Licence 1.0.
Browser extension that finds API keys leaked in websites and audits their access & billing exposure. Live-validates Google, OpenAI, Anthropic, OpenRouter, xAI, Twilio, AWS, GitHub, GitLab, Slack & Stripe keys, fully on-device, no backend, no telemetry.
GitHub OSINT tool for searching code patterns, files, issues, and commits. Detect security vulnerabilities, exposed credentials, and dangerous code patterns.
VS Code extension that finds secrets in git history, verifies live credentials, and helps remove leaks with safe rewrite workflows
🔦 كاشف — Client-side secrets & sensitive-data exposure scanner. 35+ patterns, entropy analysis, AI triage, zero telemetry.
X-Ways Forensics X-Tension wrapping TruffleHog v3 for per-item secret scanning across volume snapshots.
MCP server detecting leaked secrets/credentials (32+ provider rules). In the official MCP Registry: io.github.eltociear/secrets-audit-mcp. Pure stdlib, zero deps.
Public-service credential-leak detection and responsible disclosure: find exposed credentials on public GitHub, file courtesy notices, track remediation.
Experimental local secret-pattern scanner for staged changes, with bounded remediation and optional provider verification. Expect false positives and misses.
🔒 Real-time secret detection for VS Code - Scan code for AWS, GitHub, Stripe, Slack credentials and 40+ more patterns. Privacy-first, local processing.
🔐 Scan repos for secrets, API keys & PII before going public. Integrates TruffleHog, Gitleaks & Presidio with auto-remediation.
GitHub Action for secretlint: scan PRs for leaked secrets & credentials in CI — zero config, fail on detection
High-performance secret detection engine with 131 provider rules (Go)
Cloudexec: A high-performance, multi-threaded multi-cloud security & audit framework. Features concurrent secrets scanning, real-time automated pivot validation, post-auth enumeration, and WAF/DNS bypass capabilities. YAML-driven and built for DevSecOps.
Git secret scanner and protection tool - prevent API keys, passwords, and credentials from being committed (Dual Licensed: GPL v3 / Commercial)
Security starter pack for Claude Code — CLAUDE.md rules + hooks that block credential leaks before they happen
Advanced Secrets & API Key Scanner - Protect Your Code, Protect Your Business
Multi-layer Git secret scanner using regex + entropy analysis + LLM verification to detect exposed API keys, credentials, and sensitive data in commit history. Built with Python for security auditing and DevSecOps workflows
To associate your repository with the credential-scanning topic, visit your repo's landing page and select "manage topics."