
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Security Governance for Agentic AI

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Filesystem scanner for Log4Shell (CVE-2021-44228) and related CVEs. Detects vulnerable JAR files via hash matching and class presence. Runs…

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Proof-of-concept exploit for CVE-2019-17041, a buffer overflow in rsyslog's parser, demonstrating remote code execution.

Defense Against the Shai-Hulud Supply Chain Attack

Open-source secret scanner in Rust

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

IOC scanner for agentic AI coding tools — detects Mini Shai-Hulud, Gemini CLI RCE, Cursor CVE-2026-26268, and DPRK PromptMink.

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

a guard that blocks catastrophic agent actions

0-day malware detection for binaries, source & scripts (that doesn't suck)

An easy to use, light-weight, on-demand virus scanner for Linux systems. For additional help, see the <a…

Generates portable SystemTap kernel modules to mitigate CVE-2013-2094 on Enterprise Linux systems, with automated build and deployment scripts for…

Scan your Windows computer for known vulnerable or malicious drivers.

Fast, auditable Linux mitigation for CVE-2026-31431 Copy Fail: algif_aead block, verification, and AF_ALG seccomp hardening.