Secrets… Secrets… Secrets… Every company has them, every hacker wants to know them.
TruffleHog is a lightweight tool used to scan for secrets, such as API keys, passwords, or other sensitive information, in code repositories.
While TruffleHog is traditionally used in CI/CD pipelines as part of DevSecOps practices, this project is aimed at those who are just getting started with security scanning. The focus will be on how to use TruffleHog on a single static repo.
I will cover:
How to set it up (Micro Project)
CV Challenge Pointers (You should do this)
So how can you easily set this up?
You’ll need a few things like Docker and Basic Bash commands knowledge but I’ll walk you through it all…
Keep reading with a 7-day free trial
Subscribe to Cyber Notes to keep reading this post and get 7 days of free access to the full post archives.