{"id":15211181,"url":"https://github.com/aydinnyunus/passdetective","last_synced_at":"2025-08-04T18:37:53.887Z","repository":{"id":183037670,"uuid":"669483816","full_name":"aydinnyunus/PassDetective","owner":"aydinnyunus","description":"PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords, API keys, and secrets. Using regular expressions, it helps prevent accidental exposure of sensitive information in your command history. ","archived":false,"fork":false,"pushed_at":"2024-06-19T10:39:39.000Z","size":2771,"stargazers_count":121,"open_issues_count":0,"forks_count":8,"subscribers_count":2,"default_branch":"main","last_synced_at":"2024-12-15T15:11:26.565Z","etag":null,"topics":["bash","bugbounty","bugbounty-tool","bugbountytips","golang","hacking","kali","kali-linux","kali-linux-hacking","linux","red-team","security","security-tools","shell","shell-script","zsh"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/aydinnyunus.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-07-22T12:31:57.000Z","updated_at":"2024-10-20T12:13:23.000Z","dependencies_parsed_at":"2023-11-14T08:25:26.501Z","dependency_job_id":"a12f1786-a40c-4f9b-b7a3-549bd182959a","html_url":"https://github.com/aydinnyunus/PassDetective","commit_stats":null,"previous_names":["aydinnyunus/passdetective"],"tags_count":8,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aydinnyunus%2FPassDetective","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aydinnyunus%2FPassDetective/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aydinnyunus%2FPassDetective/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aydinnyunus%2FPassDetective/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/aydinnyunus","download_url":"https://codeload.github.com/aydinnyunus/PassDetective/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":230859414,"owners_count":18291154,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bash","bugbounty","bugbounty-tool","bugbountytips","golang","hacking","kali","kali-linux","kali-linux-hacking","linux","red-team","security","security-tools","shell","shell-script","zsh"],"created_at":"2024-09-28T08:20:35.048Z","updated_at":"2024-12-22T17:14:41.939Z","avatar_url":"https://github.com/aydinnyunus.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"[![Contributors][contributors-shield]][contributors-url]\n[![Forks][forks-shield]][forks-url]\n[![Stargazers][stars-shield]][stars-url]\n[![Issues][issues-shield]][issues-url]\n[![MIT License][license-shield]][license-url]\n[![LinkedIn][linkedin-shield]][linkedin-url]\n\n\n\n\u003c!-- PROJECT LOGO --\u003e\n\u003cbr /\u003e\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/aydinnyunus/PassDetective\"\u003e\n  \u003c/a\u003e\n\n\u003ch3 align=\"center\"\u003ePassDetective\u003c/h3\u003e\n\n  \u003cp align=\"center\"\u003e\n    \u003cbr /\u003e\n    \u003ca href=\"https://github.com/aydinnyunus/PassDetective\"\u003e\u003cstrong\u003eExplore the docs »\u003c/strong\u003e\u003c/a\u003e\n    \u003cbr /\u003e\n    \u003cbr /\u003e\n    ·\n    \u003ca href=\"https://github.com/aydinnyunus/PassDetective/issues\"\u003eReport Bug\u003c/a\u003e\n    ·\n    \u003ca href=\"https://github.com/aydinnyunus/PassDetective/issues\"\u003eRequest Feature\u003c/a\u003e\n  \u003c/p\u003e\n\u003c/p\u003e\n\n\n\n\u003c!-- TABLE OF CONTENTS --\u003e\n\u003cdetails open=\"open\"\u003e\n  \u003csummary\u003eTable of Contents\u003c/summary\u003e\n  \u003col\u003e\n    \u003cli\u003e\n      \u003ca href=\"#getting-started\"\u003eGetting Started\u003c/a\u003e\n      \u003cul\u003e\n        \u003cli\u003e\u003ca href=\"#installation\"\u003eInstallation\u003c/a\u003e\u003c/li\u003e\n      \u003c/ul\u003e\n    \u003c/li\u003e\n    \u003cli\u003e\n      \u003ca href=\"#usage\"\u003eUsage\u003c/a\u003e\n         \u003cul\u003e\n            \u003cli\u003e\u003ca href=\"#extract-shell-history\"\u003eAnalyze ZSH History\u003c/a\u003e\u003c/li\u003e\n           \u003cli\u003e\u003ca href=\"#extract-secrets\"\u003eRegex Scan on Shell History\u003c/a\u003e\u003c/li\u003e\n         \u003c/ul\u003e\n   \u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#reports\"\u003eReports\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#roadmap\"\u003eRoadmap\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#contributing\"\u003eContributing\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#license\"\u003eLicense\u003c/a\u003e\u003c/li\u003e\n    \u003cli\u003e\u003ca href=\"#contact\"\u003eContact\u003c/a\u003e\u003c/li\u003e\n  \u003c/ol\u003e\n\u003c/details\u003e\n\n\n\u003c!-- GETTING STARTED --\u003e\n\n## Getting Started\n\nPassDetective is a command-line tool that scans your shell command history for mistakenly written passwords, API keys, and secrets. It uses regular expressions to identify potential sensitive information and helps you avoid accidentally exposing sensitive data in your command history.\n\n\n## Installation\n\n```bash\ngo install github.com/aydinnyunus/PassDetective@latest\n```\n\n[Kali Linux](https://www.kali.org/tools/passdetective/)\n\n```bash\nsudo apt install PassDetective\n```\n\n\u003cimg width=\"1727\" alt=\"image\" src=\"https://github.com/aydinnyunus/PassDetective/assets/52822869/dc12e543-3454-423b-b3fe-0511f93e2c3e\"\u003e\n\nFor Nix or NixOS is [pre-packed module](https://search.nixos.org/packages?channel=unstable\u0026query=passdetective)\navailable. The lastest release is usually present in the ``unstable`` channel.\n\n```bash\n$ nix-env -iA nixpkgs.passdetective\n```\n\n## Features\n\n- Scans shell command history to detect mistakenly written passwords\n- Identifies API keys and secrets using regular expressions\n- Provides a secure way to review your command history and prevent accidental exposure of sensitive information\n\n\u003c!-- USAGE EXAMPLES --\u003e\n\n## Usage\n\n![PassDetective Help](https://i.imgur.com/UeMRWTd.png)\n\n### Extract Shell History\n\n![Extract History](https://i.imgur.com/M1IRYt7.png)\n\nAfter you have install requirements , you can simply analyze the image via:\n\n```shell\n   $ PassDetective extract -all\n```\n\n![Extract All](https://i.imgur.com/zKjs3p8.png)\n\n\n### Extract Secrets\n\nIf you want to specify directory use this command:\n\n```shell\n   $ PassDetective extract --secrets --zsh\n```\n\n![Secrets](https://i.imgur.com/yw3v0RI.png)\n\n## Regular Expressions\nPassDetective uses the following regular expressions to identify potential sensitive information:\n\n```\n  \"Cloudinary\"  : \"cloudinary://.*\",\n  \"Firebase URL\": \".*firebaseio\\.com\",\n  \"Slack Token\": \"(xox[p|b|o|a]-[0-9]{12}-[0-9]{12}-[0-9]{12}-[a-z0-9]{32})\",\n  \"RSA private key\": \"-----BEGIN RSA PRIVATE KEY-----\",\n  \"SSH (DSA) private key\": \"-----BEGIN DSA PRIVATE KEY-----\",\n  \"SSH (EC) private key\": \"-----BEGIN EC PRIVATE KEY-----\",\n  \"PGP private key block\": \"-----BEGIN PGP PRIVATE KEY BLOCK-----\",\n  \"Amazon AWS Access Key ID\": \"AKIA[0-9A-Z]{16}\",\n  \"Amazon MWS Auth Token\": \"amzn\\\\.mws\\\\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}\",\n  \"AWS API Key\": \"AKIA[0-9A-Z]{16}\",\n  \"Facebook Access Token\": \"EAACEdEose0cBA[0-9A-Za-z]+\",\n  \"Facebook OAuth\": \"[f|F][a|A][c|C][e|E][b|B][o|O][o|O][k|K].*['|\\\"][0-9a-f]{32}['|\\\"]\",\n  \"GitHub\": \"[g|G][i|I][t|T][h|H][u|U][b|B].*['|\\\"][0-9a-zA-Z]{35,40}['|\\\"]\",\n  \"Generic API Key\": \"[a|A][p|P][i|I][_]?[k|K][e|E][y|Y].*['|\\\"][0-9a-zA-Z]{32,45}['|\\\"]\",\n  \"Generic Secret\": \"[s|S][e|E][c|C][r|R][e|E][t|T].*['|\\\"][0-9a-zA-Z]{32,45}['|\\\"]\",\n  \"Google API Key\": \"AIza[0-9A-Za-z\\\\-_]{35}\",\n  \"Google Cloud Platform API Key\": \"AIza[0-9A-Za-z\\\\-_]{35}\",\n  \"Google Cloud Platform OAuth\": \"[0-9]+-[0-9A-Za-z_]{32}\\\\.apps\\\\.googleusercontent\\\\.com\",\n  \"Google Drive API Key\": \"AIza[0-9A-Za-z\\\\-_]{35}\",\n  \"Google Drive OAuth\": \"[0-9]+-[0-9A-Za-z_]{32}\\\\.apps\\\\.googleusercontent\\\\.com\",\n  \"Google (GCP) Service-account\": \"\\\"type\\\": \\\"service_account\\\"\",\n  \"Google Gmail API Key\": \"AIza[0-9A-Za-z\\\\-_]{35}\",\n  \"Google Gmail OAuth\": \"[0-9]+-[0-9A-Za-z_]{32}\\\\.apps\\\\.googleusercontent\\\\.com\",\n  \"Google OAuth Access Token\": \"ya29\\\\.[0-9A-Za-z\\\\-_]+\",\n  \"Google YouTube API Key\": \"AIza[0-9A-Za-z\\\\-_]{35}\",\n  \"Google YouTube OAuth\": \"[0-9]+-[0-9A-Za-z_]{32}\\\\.apps\\\\.googleusercontent\\\\.com\",\n  \"Heroku API Key\": \"[h|H][e|E][r|R][o|O][k|K][u|U].*[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}\",\n  \"MailChimp API Key\": \"[0-9a-f]{32}-us[0-9]{1,2}\",\n  \"Mailgun API Key\": \"key-[0-9a-zA-Z]{32}\",\n  \"Password in URL\": \"[a-zA-Z]{3,10}://[^/\\\\s:@]{3,20}:[^/\\\\s:@]{3,20}@.{1,100}[\\\"'\\\\s]\",\n  \"PayPal Braintree Access Token\": \"access_token\\\\$production\\\\$[0-9a-z]{16}\\\\$[0-9a-f]{32}\",\n  \"Picatic API Key\": \"sk_live_[0-9a-z]{32}\",\n  \"Slack Webhook\": \"https://hooks.slack.com/services/T[a-zA-Z0-9_]{8}/B[a-zA-Z0-9_]{8}/[a-zA-Z0-9_]{24}\",\n  \"Stripe API Key\": \"sk_live_[0-9a-zA-Z]{24}\",\n  \"Stripe Restricted API Key\": \"rk_live_[0-9a-zA-Z]{24}\",\n  \"Square Access Token\": \"sq0atp-[0-9A-Za-z\\\\-_]{22}\",\n  \"Square OAuth Secret\": \"sq0csp-[0-9A-Za-z\\\\-_]{43}\",\n  \"Twilio API Key\": \"SK[0-9a-fA-F]{32}\",\n  \"Twitter Access Token\": \"[t|T][w|W][i|I][t|T][t|T][e|E][r|R].*[1-9][0-9]+-[0-9a-zA-Z]{40}\",\n  \"Twitter OAuth\": \"[t|T][w|W][i|I][t|T][t|T][e|E][r|R].*['|\\\"][0-9a-zA-Z]{35,44}['|\\\"]\"\n\n```\n\n**Source** : https://github.com/h33tlit/secret-regex-list\n\n## Roadmap\n\nSee the [open issues](https://github.com/aydinnyunus/PassDetective/issues) for a list of proposed features (and known issues).\n\n\n\n\u003c!-- CONTRIBUTING --\u003e\n\n## Contributing\n\nContributions are what makes the open source community such an amazing place to learn, inspire, and create. Any\ncontributions you make are **greatly appreciated**.\n\n1. Fork the Project\n2. Create your Feature Branch (`git checkout -b feature/AmazingFeature`)\n3. Commit your Changes (`git commit -m 'Add some AmazingFeature'`)\n4. Push to the Branch (`git push origin feature/AmazingFeature`)\n5. Open a Pull Request\n\n\u003c!-- LICENSE --\u003e\n\n## License\n\nDistributed under the Apache License 2.0 License. See `LICENSE` for more information.\n\n\n\n\u003c!-- CONTACT --\u003e\n\n## Contact\n\n[\u003cimg target=\"_blank\" src=\"https://img.icons8.com/bubbles/100/000000/linkedin.png\" title=\"LinkedIn\"\u003e](https://linkedin.com/in/yunus-ayd%C4%B1n-b9b01a18a/) [\u003cimg target=\"_blank\" src=\"https://img.icons8.com/bubbles/100/000000/github.png\" title=\"Github\"\u003e](https://github.com/aydinnyunus/) [\u003cimg target=\"_blank\" src=\"https://img.icons8.com/bubbles/100/000000/instagram-new.png\" title=\"Instagram\"\u003e](https://instagram.com/aydinyunus_/) [\u003cimg target=\"_blank\" src=\"https://img.icons8.com/bubbles/100/000000/twitter-squared.png\" title=\"LinkedIn\"\u003e](https://twitter.com/aydinnyunuss)\n\n\u003c!-- MARKDOWN LINKS \u0026 IMAGES --\u003e\n\u003c!-- https://www.markdownguide.org/basic-syntax/#reference-style-links --\u003e\n\n[contributors-shield]: https://img.shields.io/github/contributors/usestrix/cli.svg?style=for-the-badge\n\n[contributors-url]: https://github.com/aydinnyunus/PassDetective/graphs/contributors\n\n[forks-shield]: https://img.shields.io/github/forks/usestrix/cli.svg?style=for-the-badge\n\n[forks-url]: https://github.com/aydinnyunus/PassDetective/network/members\n\n[stars-shield]: https://img.shields.io/github/stars/usestrix/cli?style=for-the-badge\n\n[stars-url]: https://github.com/aydinnyunus/PassDetective/stargazers\n\n[issues-shield]: https://img.shields.io/github/issues/usestrix/cli.svg?style=for-the-badge\n\n[issues-url]: https://github.com/aydinnyunus/PassDetective/issues\n\n[license-shield]: https://img.shields.io/github/license/usestrix/cli.svg?style=for-the-badge\n\n[license-url]: https://github.com/aydinnyunus/PassDetective/blob/master/LICENSE.txt\n\n[linkedin-shield]: https://img.shields.io/badge/-LinkedIn-black.svg?style=for-the-badge\u0026logo=linkedin\u0026colorB=555\n\n[linkedin-url]: https://linkedin.com/in/aydinnyunus\n\n[product-screenshot]: data/images/base_command.png\n\n[latest-release]: https://github.com/aydinnyunus/PassDetective/releases\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faydinnyunus%2Fpassdetective","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Faydinnyunus%2Fpassdetective","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faydinnyunus%2Fpassdetective/lists"}