____ __ _____ _ __
/ __ \__ ______ / /__/ ___/___ _______ _______(_) /___ __
/ /_/ / / / / __ \/ //_/\__ \/ _ \/ ___/ / / / ___/ / __/ / / /
/ ____/ /_/ / / / / ,< ___/ / __/ /__/ /_/ / / / / /_/ /_/ /
/_/ \__,_/_/ /_/_/|_|/____/\___/\___/\__,_/_/ /_/\__/\__, /
PRESENTS /____/
Secret-Magpie ✨
Scan all your github/bitbucket repos from one tool, with multiple tools!
SecretMagpie is a secret detection tool that hunts out all the secrets hiding in your GitHub repositories. It uses multiple tools in one convenient package to scan every branch of every repository in an organisation. It then smooshes all those results together into a lovely json output and reports some big ticket stats right to the screen.
By making use of the opensource tools Trufflehog 🐷 and Gitleaks, SecretMagpie can highlight a variety of different secrets and ensure that nothing is missed!
We've kept things nice and simple and bundled everything into a Docker container to enable you to start finding secrets as soon as possible. SecretMagpie has two mandatory parameters, a GitHub organisation name and a GitHub personal access token.
Simply run one of the following commands to get started:
docker run punksecurity/secret-magpie github --org 'github organisation name' --pat 'personal access token'
or
docker run punksecurity/secret-magpie bitbucket --workspace 'workspace name to scan' --username 'your username' --password 'your application password'
Copy from the container
docker cp 'container':/app/results/results.[csv/json] /host/path/target
OR Mount the volume
docker -v /localpath:/app/results
If you prefer not to use Docker then you will need to manually install the following:
You will also need to install the dependencies in requirements.txt by running the following command:
pip install -r requirements.txt
usage:
secret-magpie {bitbucket,github} [options]
positional arguments:
{github,bitbucket}
options:
-h, --help show this help message and exit
--out OUT Output file (default: results)
--out-format {csv,json}
--parallel-repos PARALLEL_REPOS
Number of repos to process in parallel - more than 3 not advised (default: 4)
--disable-trufflehog Scan without trufflehog
--disable-gitleaks Scan without gitleaks
--single-branch Scan only the default branch
--dont-store-secret Do not store the plaintext secret in the results
--no-stats Do not output stats summary
github:
--org ORG Github organisation name to target
--pat PAT Github Personal Access Token for API access and cloning
bitbucket:
--workspace WORKSPACE
--username USERNAME
--password PASSWORD
Content type
Image
Digest
sha256:1a53039f1…
Size
108.8 MB
Last updated
about 2 years ago
docker pull punksecurity/secret-magpie