selection_child: - Image|endswith: - '/trufflehog' - '/gitleaks' - CommandLine|contains: - 'trufflehog' - 'gitleaks' condition:all of selection_* Falsepositives:
-Legitimate pre-commit hooks or CI/CD pipeline jobs that use a script to run a credential scanner as part of a security check. Level:high