TRUFFLES
Enumerate owners or search GitHub globally, filter with globs or regex, then scan full git history with trufflehog — or run both steps from a YAML playbook.

truffles is an open-source CLI that finds GitHub repos at scale, filters them, and scans full git history with trufflehog — or runs both steps from a YAML playbook.
Owner enumeration List every public repo under an org or user, then filter locally with globs or regex.
Global search Hit GitHub’s search API without -owner; repeat -q and narrow with -filter.
Proxy pool Rotate proxies to ride out rate limits when you enumerate or search at scale.
Full-history scan Feed a URL list to trufflehog and scan every commit — not just HEAD.
YAML playbooks Author search → scan in one file and run both steps with truffles playbook.
Durable reports Pretty, CSV, or JSONL output fsynced after every repo — Ctrl-C keeps what finished.
Wizard Guided walkthrough for owner vs global search, filters, and kicking off a scan.
Terminal tours for each step of the secrets pipeline.
Enumerate an owner or search GitHub globally, then write a repo list.
An open-source CLI to find GitHub repos at scale, filter them, and scan full git history with trufflehog — or run both steps from a YAML playbook.
Install from the tabs above, then run truffles wizard. Or search an owner, write a repo list, and scan with truffles scan -f repos.txt.
Optional for public search. Required for private repos. Set GITHUB_TOKEN (or GH_TOKEN) in your environment.
scan shells out to trufflehog on PATH. Override with -bin if needed. Install trufflehog separately.
No. Reports contain secrets in plaintext and are gitignored by default. Keep them out of version control.
Not scanned — never counted as clean. [ok] is clean, [++] means findings.
No. -max-depth N is lossy and can miss old commits. Prefer full history when secrets matter.
Yes. MIT. Issues and PRs are welcome on GitHub.
Looking to collaborate — or searching for offensive security / secrets research work?
Check out OpenHat Security on GitHub — truffles, RunHug, and related tooling live there. If you want to contribute playbooks, proxy pools, cluster workers, or talk about engagements that need secrets hunting at scale, email Adam.