TruffleHog

MITRE ATT&CK: S9009 View on attack.mitre.org

Aliases: Trufflehog, TruffleHog

First seen
2016-01-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
iaas, linux, saas, windows
Profile updated
2026-07-07 15:28:31

Targeted industries: technology-and-telecommunications professional-services

Context

TruffleHog is an open-source secrets-discovery tool that is used to search for credentials, API keys, and encryption keys across a variety of data sources and environments. TruffleHog has the ability to discover credentials and secrets stored in code repositories, git history, CI/CD pipelines, among other common storage locations to include filesystems and cloud storage buckets. TruffleHog was first released by its author in 2016.

Detection coverage

  • 121 Sigma rules

Malware & tools used

  • Sharepoint (attack-pattern)
  • Messaging Applications (attack-pattern)
  • Cloud Storage Object Discovery (attack-pattern)
  • Cloud API (attack-pattern)
  • Cloud Service Discovery (attack-pattern)
  • Cloud Secrets Management Stores (attack-pattern)
  • Cloud Infrastructure Discovery (attack-pattern)
  • Cloud Instance Metadata API (attack-pattern)
  • Steal Application Access Token (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Cloud Accounts (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Data from Cloud Storage (attack-pattern)
  • Confluence (attack-pattern)
  • Code Repositories (attack-pattern)

Reports & references

  • netskope.com — Shai Hulud 2 0 Aggressive Automated One Of Fastest Spreading Npm Supply Chain Attacks Ever Observed (report)
  • MITRE ATT&CK — S9009 (report)
  • github.com — Trufflehog (report)
  • blackhillsinfosec.com — Rooting For Secrets With Trufflehog (report)

External references