vulns.co
/
GKData.io MCP

Back to Playbooks

Git & CI/CD Secret Recon

Find leaked credentials and internal detail across code, git history, and exposed CI artifacts.

Tags: secrets, git, ci, recon

Level: intermediate

Method

  1. Find repos & exposed .git

    Enumerate the org's public repos and probe web roots for exposed /.git/ directories you can dump.

    httpx -l live.txt -path '/.git/HEAD' -mc 200 -silent

    Tools: httpx, nuclei

  2. Scan history, not just HEAD

    Secrets are usually in old commits. Scan full history with verification to cut noise.

    trufflehog git https://github.com/org/repo --only-verified

    Tools: trufflehog, gitleaks

  3. Mine JS & artifacts

    Pull JS bundles and CI logs/artifacts for API keys, tokens, and internal endpoints.

    cat jsfiles.txt | jsluice secrets

    Tools: jsluice, getJS

  4. Validate & scope impact

    Confirm a leaked key is live and map what it unlocks (cloud, SaaS, internal APIs) before reporting.

Field notes

  • Dorking org members' personal repos often beats the main org repo.
  • A dumped /.git/ lets you reconstruct source and find more secrets offline.

References