Core Engine

Secret Detection

Introduction

Secret detection scans codebases and compiled artefacts for exposed sensitive data such as API keys, cryptographic certificates, hardcoded passwords and AWS tokens.

Why it's needed

One leaked API key can compromise a whole corporate infrastructure. Developers often hardcode credentials while debugging and forget to remove them before compiling. Legacy scanners tend to miss secrets buried in compiled binaries because they only read source code.

How TrustDyne works

TrustDyne scans the extracted firmware image with TruffleHog and its own pattern checks for hardcoded passwords. Where a provider supports it, TruffleHog tests a discovered credential against the live service, and a credential the provider confirms is valid is reported as CRITICAL. Unconfirmed matches are kept only for detectors with a distinctive format, which cuts false positives.