Skip to content

Geiger

Offensive & Pentesting

A read‑only secret scanner that triages leaked credentials by detecting them, running non‑destructive recon with each credential, and ranking the resulting blast radius.

Go Latest v1.7.0 · 19d ago Security brief →

Features

  • Detects secret strings (AWS keys, GitHub tokens, Vault tokens, SSH private keys, etc.) from stdin, files, or pipeline output
  • Performs read‑only reconnaissance with each credential and ranks impact by blast radius
  • Supports dry‑run mode (default) that shows intended API calls without contacting services
  • Offers an intrusive mode that safely redeems refresh tokens, queries databases, and reads secret managers to reveal deeper reach
  • Handles SSH keys: fingerprints them and optionally tests Git access or correlates potential target hosts

Recent releases

View all 13 releases →
No immediate action
v1.7.0 New feature

Malicious extension model

Review required
v1.5.1 Bug fix
Auth Dependencies

Filestack API key severity change

No immediate action
v1.6.0 New feature

tier and score in JSON

Config change
v1.5.0 New feature
Auth

SSH confirmation + Bedrock validation

No immediate action
v1.4.3 Bugfix

Clears invalid JSON error

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
34
Forks
2
Language
Go

Install & Platforms

Install via
binary go
Platforms
linux

Beta — feedback welcome: [email protected]