Skip to main content

vamp-secrets-scanner

Static secrets and credential scanner with Git history analysis and SARIF export
VampSecure Labs · Security Research Division


Overview

vamp-secrets-scanner is a static analysis tool that detects hardcoded secrets, credentials, and sensitive data across source code repositories, configuration files, and directory trees. It combines a database of 80+ regex patterns covering cloud keys, payment tokens, PKI material, and PII with Shannon entropy analysis to surface high-entropy strings that elude pattern matching. A dedicated Git history scanner surfaces secrets that were removed from the working tree but remain reachable in commit history.

Designed for pre-deployment code reviews, penetration testing engagements, and CI/CD pipeline integration. All analysis is fully local — no data leaves the machine.

Features

  • 80+ secret patterns across cloud providers (AWS, GCP, Azure), VCS tokens (GitHub PAT, GitLab PAT), payment gateways (Stripe, PayPal, Braintree), messaging platforms (Slack, Telegram, Discord, Twilio), database DSNs, JWT secrets, PEM private keys, and WireGuard private keys
  • PII detection for credit/debit card PANs (Visa, Mastercard, Amex, Discover), IBAN/BIC, CVV codes, US SSN, Spanish DNI/NIE/CIF/NUSS, and NHS numbers
  • Shannon entropy analysis on assignment-context strings — catches generated secrets with no known format (configurable threshold, default 4.5 bits/symbol)
  • Git history scanning — walks all commits across all branches, including deleted content, via git log --all + per-commit diffs
  • Four-tier severity model: CRITICAL / HIGH / MEDIUM / LOW with deduplication by SHA-256 fingerprint
  • Allowlist support to suppress known false positives by fingerprint, pattern name, or file prefix; also generates baseline allowlist JSON from current findings
  • SARIF 2.1.0 export for direct integration with GitHub Advanced Security and VS Code SARIF Viewer
  • Dark-theme HTML report — standalone, zero external dependencies, collapsible context rows per finding
  • Pre-commit hook installer — blocks commits when MEDIUM+ findings are detected
  • Semgrep rule export — converts the full pattern database to a Semgrep-compatible YAML ruleset
  • Unified VSL client report (HTML/PDF) via the shared vampsec_report module

Requirements

pip install -r requirements.txt

Runtime dependencies:

Package Version
rich >= 13.7.0

Standard library only beyond rich: re, os, math, pathlib, hashlib, json, argparse, subprocess.

Installation

git clone https://github.com/belky-me/vamp-secrets-scanner.git
cd vamp-secrets-scanner
pip install -r requirements.txt

Usage

python vamp_secrets_scanner.py --help
usage: vamp-secrets-scanner [-h] [-o FICHERO] [--html FICHERO] [--sarif FICHERO]
                             [--min-severity {CRITICAL,HIGH,MEDIUM,LOW}] [--only-critical]
                             [--all-extensions] [--max-depth N] [--no-entropy]
                             [--entropy-threshold BITS] [--exclude-dir DIR]
                             [--git-history] [--max-commits N]
                             [--allowlist FICHERO] [--generate-allowlist FICHERO]
                             [--install-hook] [--export-semgrep FICHERO]
                             DIRECTORIO

Examples

Scan the current directory (all severities):

python vamp_secrets_scanner.py .

Scan a repository including full Git commit history:

python vamp_secrets_scanner.py /path/to/repo --git-history

Report only CRITICAL and HIGH findings, export SARIF for GitHub Actions:

python vamp_secrets_scanner.py . --min-severity HIGH --sarif results.sarif

Generate a baseline allowlist to suppress known false positives in CI:

python vamp_secrets_scanner.py . --generate-allowlist baseline.json

Apply allowlist, export JSON and standalone HTML report:

python vamp_secrets_scanner.py . --allowlist baseline.json -o findings.json --html report.html

Limit Git history scan to the 100 most recent commits:

python vamp_secrets_scanner.py . --git-history --max-commits 100

Install a pre-commit hook that blocks commits on MEDIUM+ findings:

python vamp_secrets_scanner.py . --install-hook

Export all patterns as a Semgrep YAML ruleset:

python vamp_secrets_scanner.py . --export-semgrep vampsec_rules.yaml

Scan only CRITICAL findings, raising entropy threshold to reduce noise:

python vamp_secrets_scanner.py . --only-critical --entropy-threshold 5.2

Output Formats

Format Flag Description
Console (Rich) (default) Colored table + detailed panels for CRITICAL findings
JSON -o FILE Structured findings with summary counts, full context, and Git metadata
HTML --html FILE Dark-theme standalone report; rows expand to show source context
SARIF 2.1.0 --sarif FILE Compatible with GitHub Advanced Security, VS Code SARIF Viewer
Semgrep YAML --export-semgrep FILE Importable ruleset: semgrep --config FILE DIR

Exit Codes

Code Meaning
0 No findings at the selected severity level
1 One or more HIGH findings detected
2 One or more CRITICAL findings detected
130 Interrupted by user (Ctrl+C)

Part of VampSecure Labs Toolkit

This tool is part of the VampSecure Labs Security Toolkit — a collection of research-grade security tools for authorized penetration testing and red/blue team exercises.


© VampSecure Studios — VampSecure Labs Security Research Division
For authorized security testing only.

Release files for vamp-secrets-scanner 2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-secrets-scanner 2.0
File Size Uploaded
vamp_secrets_scanner-2.0.tar.gz 27.1 kB Details

Release files / vamp_secrets_scanner-2.0.tar.gz

Download URL vamp_secrets_scanner-2.0.tar.gz
Size 27.1 kB
Tags Source
SHA-256 checksum
How to use checksums
0e5498c9f4c4cb6af6d13e70e17f474a81594d793b7253e9dbb688e6ea5fbd44
BLAKE2b-256 checksum
How to use checksums
a9d1ed7340216dddcc058102db54368a08fa4b25835e8911a085683fe966d068
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

2.4

2 release files

2.3

2 release files

2.2

2 release files

2.1

2 release files

This release

2.0 This release

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page