Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/mongodb/kingfisher
Static AnalysisVulnerability ScannersContainer SecurityDynamic Code Analysis (DAST)Information GatheringCloud SecurityDevSecOpsUtilities & FrameworksSecret DetectionSupply Chain Security
GitHubmongodb/kingfisher

kingfisher

Detect secrets + live validation. Map blast radius. Revoke fast. Use the CLI or embed in Rust and Python.

View RepositoryWebsite
1.3k12223 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Detect and Validate Secrets Anywhere. Map Access. Revoke Fast.

Kingfisher Logo
Apache 2.0 License Container downloads
GitHub downloads PyPI downloads

Find leaked secrets. Validate what’s live. Map the blast radius. Revoke fast.

Kingfisher is a blazingly fast, completely free and open source secret scanner built in Rust. It detects leaked secrets across your entire stack with hundreds of built-in rules, validates which credentials are actually live, maps the blast radius of every leak, and revokes exposed secrets in minutes - the full defender workflow in one Apache-2.0-licensed release:

Detect → Validate → Map → Triage → Revoke

  • scan source code, Git history, cloud storage, container images, archives, and developer platforms
  • validate which credentials are active
  • map a leaked secrete's identity, permissions, and reachable resources
  • triage findings in a browser, or output as SARIF, JSON, TOON
  • revoke supported secrets

Defender workflow: Follow the end-to-end defender workflow for secret detection, validation, notifications, blast-radius mapping, and revocation.

Optionally Embed Kingfisher as a Rust library or Python module

Add Kingfisher's fast secret scanning, live credential validation, and revocation to your own applications through a Python module or native Rust library. Everything runs in-process, with no CLI subprocess required.

Embedding Kingfisher in Python and Rust applications

  • Python: Install uv add kingfisher-secret-scanner and import kingfisher_sdk. See the Python SDK guide and runnable examples for scanning, validation, rule inspection, and explicit revocation.
  • Rust: Use kingfisher-scanner. See the library guide and runnable examples for scanning and validation, plus revocation via kingfisher-scanner.

Scan Targets

Kingfisher handles local files and directories, Git repositories and history, compressed and office-document archives, SQLite databases, Python bytecode, Docker images, source-hosting organizations, cloud object storage, collaboration tools, and API-development platforms.

Files / DirsLocal GitGitHubGitLabAzure ReposBitbucketGiteaHugging Face
Files / Dirs
Files / Dirs
Local Git
Local Git
GitHub
GitHub
GitLab
GitLab
Azure Repos
Azure Repos
Bitbucket
Bitbucket
Gitea
Gitea
Hugging Face
Hugging Face
DockerJiraConfluenceSlackTeamsPostmanAWS S3Google Cloud
Docker
Docker
Jira
Jira
Confluence
Confluence
Slack
Slack
Microsoft Teams
Teams
Postman
Postman
AWS S3
AWS S3
Google Cloud Storage
Cloud Storage

For target-specific commands, authentication, scope, and pagination behavior, use the platform integration guide.

Discover, validate, and revoke — open source options

Of the popular secret scanning tools compared below, only Kingfisher and Betterleaks 2.0 offer built-in credential revocation. All open source, with no paid edition required.

Built-in capabilityKingfisherBetterleaks 2.0TruffleHog OSSGitleaks
(Find) Secret discovery✅✅✅✅
(Validate) Live credential verification✅✅✅❌
(Map) Identity and permission analysis✅✅✅❌
(Revoke) Credential revocation✅✅❌❌
LicenseApache-2.0MITAGPL-3.0MIT

✅ Supported · ❌ Not Supported

Built for Speed and Accuracy

Kingfisher's multithreaded Vectorscan engine recorded the lowest runtime on every repository in the published benchmark suite, from small projects through the Linux kernel and GitLab monorepo. Lower runtimes are better.

Download Tool