CyberLearn
← Back to intermediate
Intermediate

Secrets Scanner

Scan codebases and git history for leaked secrets

Log in to track progress
1–2dGo

What you'll learn

  • Secret detection
  • Shannon entropy
  • HIBP k-anonymity
  • SARIF output
██████╗  ██████╗ ██████╗ ████████╗██╗ █████╗
██╔══██╗██╔═══██╗██╔══██╗╚══██╔══╝██║██╔══██╗
██████╔╝██║   ██║██████╔╝   ██║   ██║███████║
██╔═══╝ ██║   ██║██╔══██╗   ██║   ██║██╔══██║
██║     ╚██████╔╝██║  ██║   ██║   ██║██║  ██║
╚═╝      ╚═════╝ ╚═╝  ╚═╝   ╚═╝   ╚═╝╚═╝  ╚═╝

Cybersecurity Projects Go License: AGPLv3 HIBP

Secrets scanner for codebases and git repositories, written in Go.

This is a quick overview. Security theory, architecture, and full walkthroughs are in the learn modules.

What It Does

  • 150 detection rules covering AWS, GitHub, GitLab, GCP, Azure, Slack, Stripe, Twilio, SendGrid, SSH/PGP keys, passwords, connection strings, JWTs, and 100+ more
  • Shannon entropy analysis for detecting high-randomness strings
  • HIBP breach verification via k-anonymity protocol (your secrets never leave your machine)
  • Directory scanning and full git history scanning (branches, depth, date ranges)
  • Output as colored terminal tables, JSON, or SARIF v2.1.0
  • 5-layer false positive defense: keyword pre-filter, structural validation, stopwords, allowlists, entropy
  • Concurrent pipeline with bounded worker pools
  • TOML configuration via .portia.toml or pyproject.toml

Install

curl -fsSL https://raw.githubusercontent.com/CarterPerez-dev/portia/main/install.sh | bash

Or with Go:

go install github.com/CarterPerez-dev/portia/cmd/portia@latest

Quick Start

portia scan .

[!TIP] This project uses just as a command runner. Type just to see all available commands.

Install: curl -sSf https://just.systems/install.sh | bash -s -- --to ~/.local/bin

Commands

CommandDescription
portia scan [path]Scan a directory for secrets
portia git [repo]Scan git history for secrets
portia initInitialize .portia.toml configuration
portia pyprojectCreate pyproject.toml with [tool.portia] config
portia config rulesList all 150 detection rules
portia config showShow active configuration

Flags: --format (terminal/json/sarif), --verbose, --no-color, --exclude, --max-size, --hibp, --config

Git flags: --branch, --since, --depth, --staged

Learn

This project includes step-by-step learning materials covering security theory, architecture, and implementation.

ModuleTopic
00 - OverviewPrerequisites and quick start
01 - ConceptsSecret sprawl, entropy, and breach databases
02 - ArchitectureSystem design and data flow
03 - ImplementationCode walkthrough
04 - ChallengesExtension ideas and exercises

License

AGPL 3.0