EXPLORE
← Back to Explore
sigmamediumHunting

PUA - TruffleHog Execution - Linux

Detects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.

MITRE ATT&CK

discoverycredential-access

Detection Query

selection_img:
  Image|endswith: /trufflehog
selection_cli_platform:
  CommandLine|contains:
    - " docker --image "
    - " Git "
    - " GitHub "
    - " Jira "
    - " Slack "
    - " Confluence "
    - " SharePoint "
    - " s3 "
    - " gcs "
selection_cli_verified:
  CommandLine|contains: " --results=verified"
condition: selection_img or all of selection_cli_*

Author

Swachchhanda Shrawan Poudel (Nextron Systems)

Created

2025-09-24

Data Sources

linuxProcess Creation Events

Platforms

linux

Tags

attack.discoveryattack.credential-accessattack.t1083attack.t1552.001
Raw Content
title: PUA - TruffleHog Execution - Linux
id: d7a650c4-226c-451e-948f-cc490db506aa
related:
    - id: 44030449-b0df-4c94-aae1-502359ab28ee
      type: similar
status: experimental
description: |
    Detects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously.
    While it is a legitimate tool, intended for use in CI pipelines and security assessments,
    It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.
references:
    - https://github.com/trufflesecurity/trufflehog
    - https://www.getsafety.com/blog-posts/shai-hulud-npm-attack
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-09-24
tags:
    - attack.discovery
    - attack.credential-access
    - attack.t1083
    - attack.t1552.001
logsource:
    category: process_creation
    product: linux
detection:
    selection_img:
        Image|endswith: '/trufflehog'
    selection_cli_platform:
        CommandLine|contains:
            - ' docker --image '
            - ' Git '
            - ' GitHub '
            - ' Jira '
            - ' Slack '
            - ' Confluence '
            - ' SharePoint '
            - ' s3 '
            - ' gcs '
    selection_cli_verified:
        CommandLine|contains: ' --results=verified'
    condition: selection_img or all of selection_cli_*
falsepositives:
    - Legitimate use of TruffleHog by security teams or developers.
level: medium