Hardcoded Secrets Enumeration
Tools
- synacktiv/nord-stream - List the secrets stored inside CI/CD environments and extract them by deploying malicious pipelines
- xforcered/SCMKit - Source Code Management Attack Toolkit
Search inside Repositories, Files and Codes
-
Discover repositories being used in a particular SCM system
-
Search for repositories by repository name in a particular SCM system
-
Search for code containing a given keyword in a particular SCM system
-
Search for files in repositories containing a given keyword in the file name in a particular SCM system
-
List snippets owned by the current user in GitLab