New posts watched live, each password checked working, alert to you in seconds, years of past leaks searchable in one place 
Pushed secrets get used in minutes ā this loop watches, proves, and pings ahead of that.
GET: each exposed key seen fast, proved live, pinged to you.
NEED: one watcher running on your code, one alarm wired to your chat.
REFILL: same loop covers each new push, each new day.
Point a watcher at live commits
Run one watcher on your org tonight, see each push as it lands.
- APIRadar ā my live scanner, runs around the clock.
apiradar.bot.nu - ghleak ā reads GH Archive push stream, shows proved hits.
github.com/Nixon-H/ghleak - force-push-scanner ā finds hidden commits after force pushes, uses public BigQuery.
github.com/trufflesecurity/force-push-scanner - git-gud ā lists hidden commits, each branch, each gist version.
github.com/Bjarturl/git-gud - Multi-API-Leaks-Finder ā scans new pushes live, new lines, Telegram pings, 20 AI services.
github.com/sahilpatel0x01/Multi-API-Leaks-Finder - GitHush ā watches Events feed live, writes JSONL for SIEM.
github.com/shodannnn/GitHush - gitGraber ā watches indexed files live, finds 31 token types.
github.com/hisxo/gitGraber - git-leaks-hunter ā polls Gists live, 500 patterns, shows dashboard.
github.com/zahidoverflow/git-leaks-hunter - Githawk ā checks org commits each minute, sends chat pings fast.
github.com/Priyansh-01/Githawk - Harppia ā scans 7 surfaces on schedule, sends strong pings.
github.com/clivoa/harppia - shhgit ā listens to Events stream live, web UI, webhooks.
github.com/eth0izzle/shhgit
Block bad pushes while you still can
Stop secrets at push time, keep them out of history.
- Gitleaks ā scans commits and PRs fast, runs pre-commit.
github.com/gitleaks/gitleaks - ggshield ā finds 500 secret types, pre-commit, pre-push, CI.
github.com/GitGuardian/ggshield - GitHub push protection ā blocks secret pushes, free on public repos.
docs.github.com/en/code-security/concepts/secret-security/secret-scanning - gitleaks-action ā posts commit and PR pings inside CI.
github.com/gitleaks/gitleaks-action
Prove each hit is live
Check each string against the real API, keep working keys.
- TruffleHog ā 800 detectors, checks each key live.
github.com/trufflesecurity/trufflehog - Kingfisher ā Rust scanner, 1,089 rules, shows key reach.
github.com/mongodb/kingfisher - Titus ā 487 rules, checks live, scores scope.
github.com/praetorian-inc/titus - llm-key-validator ā runs alone, checks 12 AI services live.
github.com/jishnu-mohan/llm-key-validator - openai-api-key-verifier ā checks key, access, usage.
github.com/mdeacey/openai-api-key-verifier - KeyHacks ā gives exact check commands, 80 key types.
github.com/streaak/keyhacks - keyleak ā reads key prefix, names service, checks live.
github.com/Lappy000/keyleak - GitHub validity checks ā checks leaked secrets, marks live or spent.
docs.github.com/en/code-security/concepts/secret-security/validity-checks - GitHub partner endpoint ā sends leaked matches to your URL, revokes fast.
docs.github.com/en/code-security/tutorials/secret-scanning-partner-program
Wire an alarm that finds you
Get a ping the second a live key shows, day or night.
- Canarytokens ā planted keys that ping when used.
github.com/thinkst/canarytokens - Canarytokens-Docker ā runs your own alert server, one command.
github.com/thinkst/canarytokens-docker - canarytokens.org ā hosted planted keys, email and webhook pings.
canarytokens.org - GitGuardian Honeytoken ā planted AWS keys, Slack and SIEM pings.
docs.gitguardian.com/honeytoken/configure-alerts - honeytoken-ecosystem ā plant kit, catches use, Telegram IP pings.
github.com/dblanko/honeytoken-ecosystem
Cover registries, pastes and more
Keys leak outside commits too, watch those places.
- Urraca ā watches PyPI, npm, more, live feed.
github.com/Aetsu/Urraca - revelio-scan ā scans packages in batches, sends chat pings.
github.com/lukesudom/revelio-scan - layerleak ā scans registries, layers, deleted layers.
github.com/Brumbelow/layerleak - pastebin-gist-monitor ā watches pastes and snippets live.
github.com/TreRB/pastebin-gist-monitor - Security-Scanner ā scans code, pastes, gists, shows dashboard.
github.com/ossiqn/Security-Scanner - GrayhatWarfare ā searches open cloud buckets.
buckets.grayhatwarfare.com - Hugging Face Secrets Scanning ā scans pushes, emails on proved secrets.
huggingface.co/docs/hub/main/en/security-secrets - LeakScope ā finds Shodan and ZoomEye exposures.
github.com/GainSec/LeakScope - Leakwatch ā scans history, images, cloud, chat, proved.
github.com/HodeTech/Leakwatch
Index it all in one search
Keep each leak in one index, search years later.
- Vooda.ai ā indexes git, tickets, cloud, images, sorts local.
github.com/virantisofficial/vooda.ai - Leaktopus ā watches org words, indexed search, team pings.
github.com/playtikaoss/leaktopus - NASO ā watches breaches and dark web, sorts local.
github.com/fabriziosalmi/naso
ā Tonight: run one watcher, wire one ping. ![]()
!