Skip to main content

ggscout

GitGuardian CLI tool for NHI (Non-Human Identity) discovery and remediation

ggscout is a Rust-powered command-line tool by GitGuardian that discovers and inventories Non-Human Identities (NHIs) across your production infrastructure. NHIs include services, applications, containers, and automation scripts that authenticate and access resources without human intervention. ggscout maps these identities, their permissions, and associated secrets to help organizations understand their NHI landscape and bootstrap incident remediation.

Installation

# Using uv (recommended)
uv tool install ggscout

# Using pip
pip install ggscout

Note: This is a Rust binary packaged for distribution via PyPI

Basic Usage

# Display help
ggscout --help

# Fetch secrets from configuration
ggscout fetch config.toml

# Run with debug logging
ggscout --verbose DEBUG fetch config.toml

Supported Platforms

ggscout inventories Non-Human Identities from:

  • HashiCorp Vault - KV stores, dynamic secrets, auth methods
  • AWS Secrets Manager - Secrets and associated IAM roles
  • Azure Key Vault - Keys, secrets, and managed identities
  • Google Cloud Secret Manager - Secrets and service accounts
  • Kubernetes/OpenShift - Secrets, ConfigMaps, Deployments, ServiceAccounts, Environment Variables
  • Akeyless Vault - Static and dynamic secrets
  • CyberArk SaaS / CyberArk Self-Hosted - Application identities and secrets
  • Delinea Secret Server - Machine accounts and credentials
  • GitLab CI - Project variables and pipeline identities

Key Features

  • Comprehensive NHI Discovery - Inventories services, roles, and secrets across platforms
  • Production-ready - Built for production environments with secure data handling
  • Multi-platform Support - Works with major secret management and orchestration platforms
  • Secure Transfer - Optional hashing before transmission to GitGuardian platform
  • High Performance - Rust implementation optimized for large-scale inventories
  • Flexible Configuration - TOML-based config with environment variable interpolation

Configuration Example

[sources.vault]
type = "hashicorpvault"
vault_address = "${VAULT_ADDR}"

[sources.vault.auth]
auth_mode = "token"
token = "${VAULT_TOKEN}"

[sources.k8s]
type = "k8s"
kubeconfig_path = "~/.kube/config"

Documentation

Official ggscout Documentation

About GitGuardian

GitGuardian is the code security platform for automated secrets detection and remediation across all environments from source code to production.

ggscout integrates with GitGuardian's platform to provide comprehensive visibility and control over Non-Human Identities in your production infrastructure, enabling better security posture management and incident remediation.

License

This project is licensed under a Proprietary License.

Support

Release files for ggscout 0.32.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for ggscout 0.32.0
File
ggscout-0.32.0-py3-none-musllinux_1_2_x86_64.whl Python 3 none Linux musl 1.2+ x86-64 Details
ggscout-0.32.0-py3-none-musllinux_1_2_aarch64.whl Python 3 none Linux musl 1.2+ ARM64 Details
ggscout-0.32.0-py3-none-manylinux_2_28_x86_64.whl Python 3 none Linux glibc 2.28+ x86-64 Details
ggscout-0.32.0-py3-none-manylinux_2_28_aarch64.whl Python 3 none Linux glibc 2.28+ ARM64 Details
ggscout-0.32.0-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
ggscout-0.32.0-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 99.9 MB

Release files / ggscout-0.32.0-py3-none-musllinux_1_2_x86_64.whl

Download URL ggscout-0.32.0-py3-none-musllinux_1_2_x86_64.whl
Size 17.7 MB
Tags Linux musl 1.2+ x86-64 Python 3
SHA-256 checksum
How to use checksums
29e1361237196191882372a53583e5b98b1a6a272783c83f27c83e3a5f1b952f
BLAKE2b-256 checksum
How to use checksums
6904fd11965b1c5a6196878dfa9dc9d087f9be6d556c51a726737d2f40fe7f89
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release files / ggscout-0.32.0-py3-none-musllinux_1_2_aarch64.whl

Download URL ggscout-0.32.0-py3-none-musllinux_1_2_aarch64.whl
Size 16.7 MB
Tags Linux musl 1.2+ ARM64 Python 3
SHA-256 checksum
How to use checksums
8112723d5c08dad5729117c615027d531f7cca8ca3ab6f4212fb81377239dbeb
BLAKE2b-256 checksum
How to use checksums
2caf3441c0eac31d5d54ebf466ecbadf63c5015e8a2ffcce55d0b4a42be27e00
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release files / ggscout-0.32.0-py3-none-manylinux_2_28_x86_64.whl

Download URL ggscout-0.32.0-py3-none-manylinux_2_28_x86_64.whl
Size 17.3 MB
Tags Linux glibc 2.28+ x86-64 Python 3
SHA-256 checksum
How to use checksums
0fe9488cc73744ae43a088c65a7ee12405e5c8e2da3413ff785152ca6b676e1f
BLAKE2b-256 checksum
How to use checksums
0e5e8c9aabe702e3383057f7b80c5d2651c0f2adf0acfb99becb30b93a1f3154
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release files / ggscout-0.32.0-py3-none-manylinux_2_28_aarch64.whl

Download URL ggscout-0.32.0-py3-none-manylinux_2_28_aarch64.whl
Size 16.2 MB
Tags Linux glibc 2.28+ ARM64 Python 3
SHA-256 checksum
How to use checksums
4a9fa926e28cd8d2b132c254f6d9f7fb72c35d91ae7e1b4cb3bc3cf959aa115e
BLAKE2b-256 checksum
How to use checksums
4e4f44c4a1303bccc39e4a160c483070fc6ca74630f95352901217485cbd2543
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release files / ggscout-0.32.0-py3-none-macosx_11_0_arm64.whl

Download URL ggscout-0.32.0-py3-none-macosx_11_0_arm64.whl
Size 15.5 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
8b99ea6b1e403f0e41137008fb1de409aa2dc5fe6cc2acdfc834dca4c7726ea0
BLAKE2b-256 checksum
How to use checksums
ee4488670cc7355bb3075b14b18174d184e9a60c14003a7520c587366819711b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release files / ggscout-0.32.0-py3-none-macosx_10_12_x86_64.whl

Download URL ggscout-0.32.0-py3-none-macosx_10_12_x86_64.whl
Size 16.5 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
0b317e34573c1da917a38cf436bfa3b0ae43cdc3d8486f39697980a158e05b08
BLAKE2b-256 checksum
How to use checksums
0998b3035ed0d8e218ce9763c271bb2b4fefa1d57d32a5d6e8bc082a0370ea7f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.25

Release history Release notifications | RSS feed

This release

0.32.0 This release

6 release files

0.30.0

6 release files

0.29.0

6 release files

0.28.1

6 release files

0.28.0

6 release files

0.25.1

6 release files

0.25.0

6 release files

0.24.0

6 release files

0.23.1

6 release files

0.23.0

6 release files

0.21.1

6 release files

0.21.0

6 release files

0.20.0

6 release files

0.19.0

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page