查找、验证和分析泄露的凭证
查找泄露的凭据。
您是否有兴趣持续监控 Git、Jira、Slack、Confluence、Microsoft Teams、Sharepoint(以及更多) 中的凭据?我们有一款企业产品可以帮到您!请访问 https://trufflesecurity.com/trufflehog-enterprise 了解更多信息。
我们将企业产品的收入用于资助更多出色的开源项目,让整个社区都能从中受益。
TruffleHog 是最强大的机密发现、分类、验证和分析工具。在此上下文中,机密指的是机器用于向另一台机器进行身份验证的凭据。这包括 API 密钥、数据库密码、私有加密密钥等。
TruffleHog 可以在许多地方查找机密,包括 Git、聊天记录、wiki、日志、API 测试平台、对象存储、文件系统等。
TruffleHog 可对 800 多种机密类型进行分类,并将它们映射回所属的特定身份。它是 AWS 机密?Stripe 机密?Cloudflare 机密?Postgres 密码?SSL 私钥?有时仅凭观察很难判断,因此 TruffleHog 会对其发现的所有内容进行分类。
对于 TruffleHog 能够分类的每一个机密,它还可以登录以确认该机密是否仍然有效。这一步对于判断是否存在当前活跃的危险至关重要。
对于 20 多种最常见的泄露凭据类型,TruffleHog 不是发送一个请求来检查机密能否登录,而是可以发送多个请求来了解有关该机密的一切信息。是谁创建的?它可以访问哪些资源?它对这些资源拥有什么权限?
有问题?反馈?加入 Slack 或 Discord,和我们一起交流。
加入我们的 Slack 社区
```bash
docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity
# :floppy_disk: 安装
为您提供了几种选项:
### MacOS 用户```bash
brew install trufflehog
在执行以下命令前,请确保 Docker 引擎正在运行:
docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys
#### Windows 命令提示符```bash
docker run --rm -it -v "%cd:/=\%:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys
docker run --rm -it -v "${PWD}:/pwd" trufflesecurity/trufflehog github --repo https://github.com/trufflesecurity/test_keys
#### M1 和 M2 Mac```bash
docker run --platform linux/arm64 --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys
Download and unpack from https://github.com/trufflesecurity/trufflehog/releases
### 从源码编译```bash
git clone https://github.com/trufflesecurity/trufflehog.git
cd trufflehog; go install
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh | sh -s -- -b /usr/local/bin
### 使用安装脚本,验证校验和签名(需要安装 cosign)```bash
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh | sh -s -- -v -b /usr/local/bin
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh | sh -s -- -b /usr/local/bin
# :closed_lock_with_key: 验证制品
所有制品均应用了校验和,生成的校验和文件使用 cosign 进行签名。
验证签名需要以下工具:
- [Cosign](https://docs.sigstore.dev/cosign/system_config/installation/)
验证步骤如下:
1. 下载你需要的制品文件,以及 [releases](https://github.com/trufflesecurity/trufflehog/releases) 页面中的以下文件。
- trufflehog\_{version}\_checksums.txt
- trufflehog\_{version}\_checksums.txt.pem
- trufflehog\_{version}\_checksums.txt.sig
2. 验证签名: ```shell
cosign verify-blob <path to trufflehog_{version}_checksums.txt> \
--certificate <path to trufflehog_{version}_checksums.txt.pem> \
--signature <path to trufflehog_{version}_checksums.txt.sig> \
--certificate-identity-regexp 'https://github\.com/trufflesecurity/trufflehog/\.github/workflows/.+' \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"
将 {version} 替换为已下载文件的版本
或者,如果您使用的是安装脚本,请传递 -v 选项以执行签名验证。
这需要在运行安装脚本之前安装 Cosign 二进制文件。
命令:```bash trufflehog git https://github.com/trufflesecurity/test_keys --results=verified
预期输出:```
🐷🔑🐷 TruffleHog. Unearth your secrets. 🐷🔑🐷
Found verified result 🐷🔑
Detector Type: AWS
Decoder Type: PLAIN
Raw result: AKIAYVP4CIPPERUVIFXG
Line: 4
Commit: fbc14303ffbf8fb1c2c1914e8dda7d0121633aca
File: keys
Email: counter <[email protected]>
Repository: https://github.com/trufflesecurity/test_keys
Timestamp: 2022-06-16 10:17:40 -0700 PDT
...
trufflehog github --org=trufflesecurity --results=verified
## 3:扫描 GitHub 组织,排除已归档的仓库```bash
trufflehog github --org=trufflesecurity --exclude-archived
命令:```bash trufflehog git https://github.com/trufflesecurity/test_keys --results=verified --json
预期输出:```
{"SourceMetadata":{"Data":{"Git":{"commit":"fbc14303ffbf8fb1c2c1914e8dda7d0121633aca","file":"keys","email":"counter \[email protected]\u003e","repository":"https://github.com/trufflesecurity/test_keys","timestamp":"2022-06-16 10:17:40 -0700 PDT","line":4}}},"SourceID":0,"SourceType":16,"SourceName":"trufflehog - git","DetectorType":2,"DetectorName":"AWS","DecoderName":"PLAIN","Verified":true,"Raw":"AKIAYVP4CIPPERUVIFXG","Redacted":"AKIAYVP4CIPPERUVIFXG","ExtraData":{"account":"595918472158","arn":"arn:aws:iam::595918472158:user/canarytokens.com@@mirux23ppyky6hx3l6vclmhnj","user_id":"AIDAYVP4CIPPJ5M54LRCY"},"StructuredData":null}
...
TruffleHog 还可以使用 --sarif 代替 --json 输出 SARIF。GitHub 代码扫描原生支持 SARIF,因此上传后可在拉取请求差异中内联显示发现结果,并在仓库的 Security 标签页中展示,同时跨扫描将发现结果跟踪为新发现/已修复,而不是每次运行都报告同一个结果——有关如何上传,请参阅下方的 TruffleHog Github Action 部分。请注意,与其他输出格式不同,SARIF 结果会在整个扫描过程中缓冲在内存中,并在最后写出,因为 SARIF 需要单个 JSON 文档而不是流——对于典型扫描来说没问题,但产生大量结果的扫描将按比例使用更多内存。
trufflehog github --repo=https://github.com/trufflesecurity/test_keys --issue-comments --pr-comments
## 6: 扫描 S3 存储桶以获取高置信度结果(已验证 + 未知)```bash
trufflehog s3 --bucket=<bucket name> --results=verified,unknown
trufflehog s3 --role-arn=
## 8:在 Docker 中使用 SSH 认证扫描 Github 仓库```bash
docker run --rm -v "$HOME/.ssh:/root/.ssh:ro" trufflesecurity/trufflehog:latest git ssh://github.com/trufflesecurity/test_keys
trufflehog filesystem path/to/file1.txt path/to/file2.txt path/to/dir
## 10: 扫描本地 git 仓库