PUA: TruffleHog Execution on Windows via trufflehog.exe Process Launch

Flags Windows execution of trufflehog.exe, especially when targeting common code and collaboration platforms and using --results=verified.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-09-24
Updated
2026-07-30

ATT&CK techniques

Cred Access → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows processes where the executable path ends with trufflehog.exe, including command lines that reference multiple supported platforms (e.g., Git, GitHub, Jira, Slack, SharePoint) and cloud/storage targets (s3, gcs). It also matches executions that include the flag --results=verified, indicating focused secret verification behavior. Although TruffleHog can be used legitimately for security assessments and CI workflows, attackers may leverage it to discover and validate exposed credentials or secrets across repositories and services.

Related detections9 linkedT1552.001 — drag to rearrange
Linux Process Execution of TruffleHog with Secret-Scanning Platforms
Suspicious UAT-10608 Hidden Credential Harvesting Script Execution via nohup
Suspicious Access to Cloud and Database Credential Files via Process
Suspicious Credential Exfiltration to webhook.site (via dns_query)
Suspicious Shai-Hulud Worm Stager Execution from Temp (via process_creation)
Suspicious prt-scan Campaign Credential Harvesting via proc environ Scan (via process_creation)
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious Double Base64 Decoded Payload Piped to Shell in CI (reviewdog Supply Chain)
Malicious Winlogon Automatic Logon Persistence via Registry AutoAdminLogon (via process_creation)
PUA: TruffleHog Execution on Windows via trufflehog.exe Process Launch
Pivot detection · T1552.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.