Skip to content

Code Repository OSINT

GitHub, GitLab, and the like are among the most rewarding recon sources there are: a company’s developers (and their employees personally) push code that, by mistake, contains credentials, API keys, tokens, internal paths, infrastructure names, and sensitive logic. And remember: Git keeps the history, so a “deleted” secret is still there. Searching repos well finds access no scan would reveal.

  • Secrets: API keys (AWS, GCP, Stripe…), passwords, tokens, SSH/PGP private keys.
  • Infrastructure: internal URLs, hostnames, IPs, non-public API endpoints.
  • Logic: how authentication works, custom algorithms, validations (to break them).
  • Employee repos: dotfiles, personal projects with work credentials.
# by organization
org:target-inc password
org:target-inc "api_key"
# by domain/hostname in the code
"target.com" password
"internal.target.local"
# by secret type
"AKIA" (AWS access key id) "-----BEGIN RSA PRIVATE KEY-----"
filename:.env DB_PASSWORD
filename:config.php password
# combining language/path
extension:yml password path:/.github/workflows secret

Also in the history and in gists (public snippets people forget).

# scan repos/history for secrets
trufflehog github --org=target-inc # high recall, verifies live keys
gitleaks detect --source .
# automated GitHub dorking
github-search / gitrob / gitdorker
# by commits and organizations
trufflehog git https://github.com/target-inc/repo

TruffleHog also verifies whether the found key is still active, reducing false positives.

1. Identify the org on GitHub/GitLab and its public repos
2. Enumerate employees (see recon-personas) and their personal accounts
3. Scan repos + history + gists with trufflehog/gitleaks
4. Manually search specific dorks (domain, "password", filename:.env)
5. Verify each secret (still live? what does it grant?)
6. If there's an exposed .git/ on the web, reconstruct the code (see fund-git)
GitLab, Bitbucket same problems
Postman public workspaces collections with tokens/endpoints
Docker Hub images with secrets in layers/ENV
npm / PyPI internal packages published by mistake (dependency confusion)
Pastebin / similar credential dumps

Prevention: secret scanning in the pipeline (GitHub Advanced Security, gitleaks pre-commit), .gitignore for .env/keys, immediately rotate any secret that reached a repo (deleting from history isn’t enough: rotate it), train employees about personal repos, and monitor org mentions with the same tools.

  • Org’s public repos identified
  • Code dorks (org:, “password”, filename:.env, “AKIA”)
  • History and gists reviewed (“deleted” secrets)
  • trufflehog/gitleaks over repos and commits
  • Employees’ personal accounts scanned
  • Secrets verified (live? what do they open?)
  • Postman/Docker Hub/npm reviewed
  • Exposed .git/ on the web reconstructed