Git & CI/CD Secret Recon
Find leaked credentials and internal detail across code, git history, and exposed CI artifacts.
Tags: secrets, git, ci, recon
Level: intermediate
Method
Find repos & exposed .git
Enumerate the org's public repos and probe web roots for exposed /.git/ directories you can dump.
httpx -l live.txt -path '/.git/HEAD' -mc 200 -silentScan history, not just HEAD
Secrets are usually in old commits. Scan full history with verification to cut noise.
trufflehog git https://github.com/org/repo --only-verifiedTools: trufflehog, gitleaks
Mine JS & artifacts
Pull JS bundles and CI logs/artifacts for API keys, tokens, and internal endpoints.
cat jsfiles.txt | jsluice secretsValidate & scope impact
Confirm a leaked key is live and map what it unlocks (cloud, SaaS, internal APIs) before reporting.
Field notes
- Dorking org members' personal repos often beats the main org repo.
- A dumped /.git/ lets you reconstruct source and find more secrets offline.