Skip to main content

ggscout

GitGuardian CLI tool for NHI (Non-Human Identity) discovery and remediation

ggscout is a Rust-powered command-line tool by GitGuardian that discovers and inventories Non-Human Identities (NHIs) across your production infrastructure. NHIs include services, applications, containers, and automation scripts that authenticate and access resources without human intervention. ggscout maps these identities, their permissions, and associated secrets to help organizations understand their NHI landscape and bootstrap incident remediation.

Installation

# Using uv (recommended)
uv tool install ggscout

# Using pip
pip install ggscout

Note: This is a Rust binary packaged for distribution via PyPI

Basic Usage

# Display help
ggscout --help

# Fetch secrets from configuration
ggscout fetch config.toml

# Run with debug logging
ggscout --verbose DEBUG fetch config.toml

Supported Platforms

ggscout inventories Non-Human Identities from:

  • HashiCorp Vault - KV stores, dynamic secrets, auth methods
  • AWS Secrets Manager - Secrets and associated IAM roles
  • Azure Key Vault - Keys, secrets, and managed identities
  • Google Cloud Secret Manager - Secrets and service accounts
  • Kubernetes/OpenShift - Secrets, ConfigMaps, Deployments, ServiceAccounts, Environment Variables
  • Akeyless Vault - Static and dynamic secrets
  • CyberArk SaaS / CyberArk Self-Hosted - Application identities and secrets
  • Delinea Secret Server - Machine accounts and credentials
  • GitLab CI - Project variables and pipeline identities

Key Features

  • Comprehensive NHI Discovery - Inventories services, roles, and secrets across platforms
  • Production-ready - Built for production environments with secure data handling
  • Multi-platform Support - Works with major secret management and orchestration platforms
  • Secure Transfer - Optional hashing before transmission to GitGuardian platform
  • High Performance - Rust implementation optimized for large-scale inventories
  • Flexible Configuration - TOML-based config with environment variable interpolation

Configuration Example

[sources.vault]
type = "hashicorpvault"
vault_address = "${VAULT_ADDR}"

[sources.vault.auth]
auth_mode = "token"
token = "${VAULT_TOKEN}"

[sources.k8s]
type = "k8s"
kubeconfig_path = "~/.kube/config"

Documentation

Official ggscout Documentation

About GitGuardian

GitGuardian is the code security platform for automated secrets detection and remediation across all environments from source code to production.

ggscout integrates with GitGuardian's platform to provide comprehensive visibility and control over Non-Human Identities in your production infrastructure, enabling better security posture management and incident remediation.

License

This project is licensed under a Proprietary License.

Support

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

ggscout-0.31.0-py3-none-musllinux_1_2_x86_64.whl (10.1 MB view details)

Uploaded Python 3musllinux: musl 1.2+ x86-64

ggscout-0.31.0-py3-none-musllinux_1_2_aarch64.whl (9.3 MB view details)

Uploaded Python 3musllinux: musl 1.2+ ARM64

ggscout-0.31.0-py3-none-manylinux_2_28_x86_64.whl (10.0 MB view details)

Uploaded Python 3manylinux: glibc 2.28+ x86-64

ggscout-0.31.0-py3-none-manylinux_2_28_aarch64.whl (9.3 MB view details)

Uploaded Python 3manylinux: glibc 2.28+ ARM64

ggscout-0.31.0-py3-none-macosx_11_0_arm64.whl (8.7 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

ggscout-0.31.0-py3-none-macosx_10_12_x86_64.whl (9.6 MB view details)

Uploaded Python 3macOS 10.12+ x86-64

File details

Details for the file ggscout-0.31.0-py3-none-musllinux_1_2_x86_64.whl.

File metadata

File hashes

Hashes for ggscout-0.31.0-py3-none-musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 71643caef1442936126c47b6dcb0ccc930de15ab97bd3c4206fa4f931f44269b
MD5 db84e4e64e39ec6d3430a8f69d00bc54
BLAKE2b-256 02667436754049da1eacbf19c5f4f4176d92c1c6fdbbb90ad776ad81a6618d2c

See more details on using hashes here.

File details

Details for the file ggscout-0.31.0-py3-none-musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for ggscout-0.31.0-py3-none-musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 7619eb72e79cb7edd544329fdaca84520ee57ae1848fa75829c2175675a3d5ce
MD5 0c7e29b50496d53cbc4827ec8d70541e
BLAKE2b-256 f40986eb88d82f3d251d6aa86062311b4d57b66c4a6c40f5d3a6774aaefebc3e

See more details on using hashes here.

File details

Details for the file ggscout-0.31.0-py3-none-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for ggscout-0.31.0-py3-none-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 af541bb4eb78097176979953a53730e538505fadb54ef866a063e9d486021740
MD5 3961f0c845de79d494d88ddc084aa9c0
BLAKE2b-256 a649ea53cf10bebddff440aa64504af86b1301b22a1ec8770cc70ac3d47f1e13

See more details on using hashes here.

File details

Details for the file ggscout-0.31.0-py3-none-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for ggscout-0.31.0-py3-none-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 49f5994b4b879b0be084e56cafa49b648243b51f5f91a1a973e40cc5cef235e0
MD5 bc05c414544812d3d685980ad8e3cd45
BLAKE2b-256 eb222f4999cb53485e06e29266f33436002b0c27974308742727e65902262f6f

See more details on using hashes here.

File details

Details for the file ggscout-0.31.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for ggscout-0.31.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 72a3aa78401dc5acb5ca4ebfa50c2b516e2fde46a52976d5aed7b34981c1dd59
MD5 1ad65276b50689bd1c4ba4c472dd45e8
BLAKE2b-256 42c4b2f2b99627c6045b9cfb2b8338f0b481b4dacdce4a9e98a36f4b135c0fb7

See more details on using hashes here.

File details

Details for the file ggscout-0.31.0-py3-none-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for ggscout-0.31.0-py3-none-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 ebacf7448163d73e36b4f3766775fabe3ed43c6f2df8ed02a2d7c6b4e4e82965
MD5 52b451bb2936d957b961e3e894f4640b
BLAKE2b-256 c2851324129c7a9697c7438129bb97f7a2ef998d3f99e4ecdab39697a877a549

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page