CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing OSINT against a target company. They are particularly interested in finding any accidentally exposed credentials, API keys, or sensitive configuration files that might have been committed to public Git repositories. Which specialized OSINT tool is designed to scan Git repositories for such sensitive information?

  1. AtheHarvester
  2. BTruffleHog
  3. CAmass
  4. DMaltego
Show answer & explanation

Correct answer: B. TruffleHog

TruffleHog is a specialized tool used to scan Git repositories (both public and private, with appropriate access) for sensitive data like API keys, credentials, and configuration files by looking through commit history.

Why the other options are wrong

  • A. theHarvester gathers emails, subdomains, and hosts, not specifically sensitive data in Git repos.
  • C. Amass is an attack surface mapping tool focused on subdomain enumeration and DNS records, not Git repository content scanning.
  • D. Maltego is a graphical link analysis tool for data mining and visualization, not for scanning Git repos for secrets.

TruffleHog

A specialized OSINT tool that scans Git repositories, including their commit history, to discover accidentally exposed sensitive information such as credentials, API keys, and configuration files.

  • Scans Git repositories for secrets.
  • Analyzes commit history.
  • Detects various types of sensitive data (e.g., API keys, passwords).

Memory trick: TruffleHog digs deep into Git for hidden 'truffles' (secrets).

More Reconnaissance and Enumeration questions