Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
titus — High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation. | Kitploit
Tools/GitHubGitHub/praetorian-inc/titus
Static AnalysisVulnerability ScannersContainer SecurityWeb Proxies & InterceptionCode AnalysisPenetration TestingDevSecOpsSecret DetectionSupply Chain Security
GitHubpraetorian-inc/titus

titus

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

66775353 days agoReviewed by Kitploit
View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Titus - high-performance secrets scanner for source code, git history, and binary files

Titus: High-Performance Secrets Scanner

Go License CI

Titus is a high-performance secrets scanner that detects credentials, API keys, and tokens in source code, files, and git history. It ships with 487 detection rules covering hundreds of services and credential types, drawn from NoseyParker and Kingfisher. Titus runs as a CLI, a Go library, a Burp Suite extension, and a Chrome browser extension — all sharing the same detection engine and rule set.

Built for security engineers, penetration testers, and DevSecOps teams, Titus combines Hyperscan/Vectorscan-accelerated regex matching with live credential validation to find and verify leaked secrets across your entire codebase.

Table of Contents

  • Why Titus?
  • Installation
  • Quick Start
  • Scanning Options
  • Finding Scoring
  • Go Library
  • Burp Suite Extension
  • Browser Extension
  • Building from Source
  • Contributing
  • License

Why Titus?

  • Fast secrets scanning: Regex matching accelerated by Hyperscan/Vectorscan when available, with a pure-Go fallback for portability on any platform.
  • Broad credential detection coverage: 487 rules detect API keys, tokens, and credentials for AWS, GCP, Azure, GitHub, Slack, databases, CI/CD systems, and hundreds more services.
  • Live secret validation: Detected secrets are checked against their source APIs to confirm whether they are active, reducing false positives and prioritizing remediation.
  • Risk-based severity scoring: Every finding receives a numeric score (0–100) and severity tier (info → critical). Scores are tuned by static rule metadata, code-accessibility context, and live API calls that measure the real blast radius of a credential — so the most dangerous findings always surface first.
  • Container image scanning: Scan Docker and OCI images directly from any registry, tarball, or OCI layout directory — no Docker daemon or binary required.
  • Multiple interfaces for every workflow: Scan from the CLI, embed as a Go library, passively scan HTTP traffic in Burp Suite, or scan web pages in Chrome during application security testing.
  • Binary file extraction: Extract and scan secrets from Office documents, PDFs, archives (zip, tar, 7z), mobile apps (APK, IPA), browser extensions, and more.

Installation

Download a prebuilt binary from the Releases page, or build from source:

make build

The binary will be at dist/titus.

Quick Start

# Scan a file for secrets
titus scan path/to/file.txt

# Scan a directory for leaked credentials
titus scan path/to/directory

# Scan a public GitHub repository (no token needed)
titus scan github.com/org/repo

# Scan a public GitLab project (no token needed)
titus scan gitlab.com/namespace/project

# Scan git history for secrets in past commits
titus scan --git path/to/repo

# Scan a Docker / OCI image (pulled from a registry — no docker daemon required)
titus scan --docker alpine:latest

# Validate detected secrets against source APIs
titus scan path/to/code --validate

Results are written to a datastore (titus.ds by default) and printed to the console.

Scanning Options

GitHub & GitLab Scanning

Scan public repositories directly by URL — no API token required:

# Scan a GitHub repository
titus scan github.com/kubernetes/kubernetes

# Scan a GitLab project
titus scan gitlab.com/gitlab-org/cli

# Full URLs work too
titus scan https://github.com/org/repo
titus scan https://gitlab.com/namespace/project.git

For organization-wide or user-wide scanning, use the dedicated subcommands:

# Scan all public repos in a GitHub org
titus github --org kubernetes

# Scan all repos in a GitHub org with a token (private repos + higher rate limits)
titus github --org kubernetes --token $GITHUB_TOKEN

# Scan all repos for a GitHub user
titus github --user octocat

# Scan all projects in a GitLab group
titus gitlab scan --group mygroup --token $GITLAB_TOKEN

# Scan a single repo with git history (finds deleted secrets)
titus github owner/repo --git

Tokens are optional for public repositories. Set GITHUB_TOKEN or GITLAB_TOKEN (or use --token) for private repository access and higher API rate limits.

Docker / OCI Image Scanning

Scan container images directly — no docker daemon, no docker binary required. Titus pulls images straight from any OCI registry over HTTPS (using credentials from ~/.docker/config.json), or reads images from a local docker save tarball or OCI image layout directory. It then scans image manifest/config metadata and every regular file in every layer, including lower-layer files deleted by later layers (since secrets can remain recoverable from image history).

# Pull from a registry and scan
titus scan --docker alpine:latest
titus scan docker://ghcr.io/owner/repo:tag

# Scan an image saved to a tarball:
#   docker save my-app:latest -o my-app.tar
#   podman save my-app:latest -o my-app.tar
titus scan --docker ./my-app.tar

# Scan an OCI image layout directory:
#   docker buildx build --output type=oci,dest=./img/ .
#   skopeo copy docker://my-app:latest oci:./img:latest
titus scan --docker ./img/

Authentication uses your existing Docker / Podman config (~/.docker/config.json, ${XDG_RUNTIME_DIR}/containers/auth.json). Private registries that need a fresh login should first be authenticated with docker login (or podman login, or crane auth login) — titus does not prompt for credentials.

Viewing Scan Results

Use report to re-read findings from a previous scan:

# Human-readable summary of detected secrets
titus report

# JSON output for programmatic processing
titus report --format json

# SARIF output for CI/CD integration with GitHub Advanced Security
titus report --format sarif

# Report from a specific datastore
titus report --datastore path/to/titus.ds

You can also control the output format at scan time with --format:

titus scan path/to/code --format json

Validating Detected Secrets

Pass --validate during a scan to check detected secrets against their source APIs:

titus scan path/to/code --validate

Validation runs concurrently (4 workers by default, configurable with --validate-workers) and marks each finding as confirmed, denied, or unknown.

Filtering Detection Rules

# List all available detection rules
titus rules list

# Scan with only specific rules (e.g., AWS and GCP credentials)
titus scan path/to/code --rules-include "aws,gcp"

# Exclude rules by pattern
titus scan path/to/code --rules-exclude "kingfisher.generic"

# Use a custom rules file for organization-specific secrets
titus scan path/to/code --rules path/to/custom-rules.yaml

# Opt in to rules marked noisy: true (high false-positive rate, off by default)
titus scan path/to/code --include-noisy
Download Tool