AppSecNews

Secret Scanning

Secret Scanning

Find credentials, tokens and keys committed to code or exposed in build systems.

9 tools profiled

How it differs Finds credentials committed to code, git history and build artifacts. Vulnerable dependencies are SCA, not this.

License
Subcategory
Deployment
Integrations
Maturity
Signals
Clear

6 tools match

  • Secret Scanning

    Python secret scanner built around a baseline file, so teams can block new credentials from entering a repository without first cleaning up every historical finding.

    Open source
    Established
  • GitGuardian

    GitGuardian

    Secret Scanning

    Platform that scans internal repositories and public code for leaked credentials and tracks each finding as an incident through validation, ownership and rotation.

    Freemium
    Established
  • Gitleaks

    Gitleaks

    Secret Scanning

    Go command line scanner that walks git history and file trees against a TOML rule set, combining regular expressions with entropy thresholds to find committed secrets.

    Open source
    Established
  • Python secret scanner built around a baseline file, so teams can block new credentials from entering a repository without first cleaning up every historical finding.

    Open source Established
    Secret Scanning
  • GitGuardian

    GitGuardian

    Platform that scans internal repositories and public code for leaked credentials and tracks each finding as an incident through validation, ownership and rotation.

    Freemium Established
    Secret Scanning
  • Gitleaks

    Gitleaks

    Go command line scanner that walks git history and file trees against a TOML rule set, combining regular expressions with entropy thresholds to find committed secrets.

    Open source Established
    Secret Scanning
  • Kingfisher

    MongoDB

    Secret Scanning

    Rust secret scanner that pairs a high-throughput regular expression engine with language-aware parsing and live validation of the credentials it finds.

    Open source
    Growing
  • SpectralOps

    Check Point

    Secret Scanning

    Commercial scanner that looks for hardcoded credentials and configuration exposure across source, infrastructure code and build output, with a developer-facing CLI and a central console.

    Commercial
    Established
  • TruffleHog

    Truffle Security

    Secret Scanning

    Secret scanner that calls each provider's API to confirm whether a discovered credential is active, across git history, cloud storage, container images and chat and ticketing systems.

    Open source and commercial
    Established
  • Kingfisher

    MongoDB

    Rust secret scanner that pairs a high-throughput regular expression engine with language-aware parsing and live validation of the credentials it finds.

    Open source Growing
    Secret Scanning
  • SpectralOps

    Check Point

    Commercial scanner that looks for hardcoded credentials and configuration exposure across source, infrastructure code and build output, with a developer-facing CLI and a central console.

    Commercial Established
    Secret Scanning
  • TruffleHog

    Truffle Security

    Secret scanner that calls each provider's API to confirm whether a discovered credential is active, across git history, cloud storage, container images and chat and ticketing systems.

    Open source and commercial Established
    Secret Scanning
Tick up to 4 tools above.