ATT&CKReferencesBlack Hills Information Security TruffleHog January 2024

Black Hills Information Security TruffleHog January 2024

Chris Traynor. (2024, January 18). Rooting For Secrets with TruffleHog. Retrieved April 15, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
ToolTruffleHog

TruffleHog has can browse and scan individual files and directories.

T1526
Cloud Service Discovery
ToolTruffleHog

TruffleHog has the ability to scan code repositories and CI/CD platforms.

T1528
Steal Application Access Token
ToolTruffleHog

TruffleHog has gathered access tokens and API tokens from CI/CD pipeline solutions and repositories.

T1530
Data from Cloud Storage
ToolTruffleHog

TruffleHog has the ability to scan cloud storage services for credentials to include Amazon (AWS) S3 and Google Cloud Storage.

T1552.001
Credentials In Files
ToolTruffleHog

TruffleHog has obtained credentials stored in config files and credential files in victim environments.

T1552.005
Cloud Instance Metadata API
ToolTruffleHog

TruffleHog can query the AWS and GCP metadata endpoints for instances and service credentials.

T1555.006
Cloud Secrets Management Stores
ToolTruffleHog

TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history.

T1619
Cloud Storage Object Discovery
ToolTruffleHog

TruffleHog can enumerate cloud storage environments including Amazon Web Service (AWS) S3 buckets and Google Cloud Storage buckets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.