ATT&CKSoftwareTruffleHog

TruffleHog

S9009

Tool.View on attack.mitre.org

About this tool

TruffleHog is an open-source secrets-discovery tool that is used to search for credentials, API keys, and encryption keys across a variety of data sources and environments. TruffleHog has the ability to discover credentials and secrets stored in code repositories, git history, CI/CD pipelines, among other common storage locations to include filesystems and cloud storage buckets. TruffleHog was first released by its author in 2016.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1005
Data from Local System

TruffleHog has gathered data from home directories of the victim environment.

T1059.009
Cloud API

TruffleHog has leveraged Cloud CLI in order to enumerate and gather credentials.

T1078.004
Cloud Accounts

TruffleHog has used stolen credentials to log into cloud services to access cloud hosted repositories and other cloud storage solutions to discover sensitive data to include API Keys, tokens and credentials.

T1083
File and Directory Discovery

TruffleHog has can browse and scan individual files and directories.

T1213.001
Confluence

TruffleHog has collected credentials and data associated with Confluence.

T1213.002
Sharepoint

TruffleHog has searched SharePoint for data and credentials.

T1213.003
Code Repositories

TruffleHog has gathered data and credentials from code repositories.

T1213.005
Messaging Applications

TruffleHog has obtained data and credentials associated with messaging applications to include Slack.

T1526
Cloud Service Discovery

TruffleHog has the ability to scan code repositories and CI/CD platforms.

T1528
Steal Application Access Token

TruffleHog has gathered access tokens and API tokens from CI/CD pipeline solutions and repositories.

T1530
Data from Cloud Storage

TruffleHog has the ability to scan cloud storage services for credentials to include Amazon (AWS) S3 and Google Cloud Storage.

T1552.001
Credentials In Files

TruffleHog has obtained credentials stored in config files and credential files in victim environments.

T1552.005
Cloud Instance Metadata API

TruffleHog can query the AWS and GCP metadata endpoints for instances and service credentials.

T1555.006
Cloud Secrets Management Stores

TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history.

T1580
Cloud Infrastructure Discovery

TruffleHog can enumerate AWS Infrastructure to include EC2 instances.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Black Hills Information Security TruffleHog January 2024 Open source
    Chris Traynor. (2024, January 18). Rooting For Secrets with TruffleHog. Retrieved April 15, 2026.
  2. Github TruffleSecurity Trufflehog April 2025 Open source
    Trufflesecurity. (2026, April 8). TruffleHog Enterprise. Retrieved April 15, 2026.
  3. Netskope Shai-Hulud November 2025 Open source
    Gianpietro Cutolo. (2025, November 26). Shai-Hulud 2.0: Aggressive, Automated, and Fast Spreading. Retrieved April 9, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.