ShadowHound is a browser extension that automatically detects leaked secrets and credentials in code while browsing.
-
Detects various types of leaked credentials (API keys, OAuth tokens, private keys, etc.).
-
Supports major platforms like AWS, Google, GitHub, Slack, and more.
-
Provides real-time alerts and notifications for detected leaks.
-
Allows users to manage and export findings in CSV format.
-
Offers customization options to enable/disable specific detection rules.
- Clone this repository:
git clone https://github.com/piyush295/ShadowHound.git
-
Open your browser's extensions page:
-
Chrome: Navigate to chrome://extensions/
-
Enable "Developer Mode" (if required by the browser).
-
Click on "Load Unpacked" and select the cloned ShadowHound directory.
Once installed, ShadowHound runs automatically in the background.
If any leaked secrets are found, they will appear in the extension popup.
Users can export findings as a CSV file.
Adjust settings via the popup to enable or disable specific detections.
ShadowHound detects secrets such as:
AWS keys
Google API keys
GitHub OAuth tokens
Slack Webhooks
Stripe API keys
Telegram bot tokens
SSH/RSA private keys
And more...
Contributions are welcome! Feel free to open issues or submit pull requests.
This project is licensed under the MIT License.