Code Repository OSINT
GitHub, GitLab, and the like are among the most rewarding recon sources there are: a company’s developers (and their employees personally) push code that, by mistake, contains credentials, API keys, tokens, internal paths, infrastructure names, and sensitive logic. And remember: Git keeps the history, so a “deleted” secret is still there. Searching repos well finds access no scan would reveal.
What to look for
Section titled “What to look for”- Secrets: API keys (AWS, GCP, Stripe…), passwords, tokens, SSH/PGP private keys.
- Infrastructure: internal URLs, hostnames, IPs, non-public API endpoints.
- Logic: how authentication works, custom algorithms, validations (to break them).
- Employee repos: dotfiles, personal projects with work credentials.
GitHub code search (code dorking)
Section titled “GitHub code search (code dorking)”# by organizationorg:target-inc passwordorg:target-inc "api_key"# by domain/hostname in the code"target.com" password"internal.target.local"# by secret type"AKIA" (AWS access key id) "-----BEGIN RSA PRIVATE KEY-----"filename:.env DB_PASSWORDfilename:config.php password# combining language/pathextension:yml password path:/.github/workflows secretAlso in the history and in gists (public snippets people forget).
Automated tools
Section titled “Automated tools”# scan repos/history for secretstrufflehog github --org=target-inc # high recall, verifies live keysgitleaks detect --source .# automated GitHub dorkinggithub-search / gitrob / gitdorker# by commits and organizationstrufflehog git https://github.com/target-inc/repoTruffleHog also verifies whether the found key is still active, reducing false positives.
Methodology
Section titled “Methodology”1. Identify the org on GitHub/GitLab and its public repos2. Enumerate employees (see recon-personas) and their personal accounts3. Scan repos + history + gists with trufflehog/gitleaks4. Manually search specific dorks (domain, "password", filename:.env)5. Verify each secret (still live? what does it grant?)6. If there's an exposed .git/ on the web, reconstruct the code (see fund-git)Beyond GitHub
Section titled “Beyond GitHub”GitLab, Bitbucket same problemsPostman public workspaces collections with tokens/endpointsDocker Hub images with secrets in layers/ENVnpm / PyPI internal packages published by mistake (dependency confusion)Pastebin / similar credential dumpsFor the defense
Section titled “For the defense”Prevention: secret scanning in the pipeline (GitHub Advanced Security, gitleaks pre-commit), .gitignore for .env/keys, immediately rotate any secret that reached a repo (deleting from history isn’t enough: rotate it), train employees about personal repos, and monitor org mentions with the same tools.
Testing checklist
Section titled “Testing checklist”- Org’s public repos identified
- Code dorks (org:, “password”, filename:.env, “AKIA”)
- History and gists reviewed (“deleted” secrets)
- trufflehog/gitleaks over repos and commits
- Employees’ personal accounts scanned
- Secrets verified (live? what do they open?)
- Postman/Docker Hub/npm reviewed
- Exposed
.git/on the web reconstructed