Secret detection scans codebases and compiled artefacts for exposed sensitive data such as API keys, cryptographic certificates, hardcoded passwords and AWS tokens.
One leaked API key can compromise a whole corporate infrastructure. Developers often hardcode credentials while debugging and forget to remove them before compiling. Legacy scanners tend to miss secrets buried in compiled binaries because they only read source code.
TrustDyne scans the extracted firmware image with TruffleHog and its own pattern checks for hardcoded passwords. Where a provider supports it, TruffleHog tests a discovered credential against the live service, and a credential the provider confirms is valid is reported as CRITICAL. Unconfirmed matches are kept only for detectors with a distinctive format, which cuts false positives.