golddigger: quickly discover sensitive information in files recursively
Gold Digger
Search files for gold
Gold Digger is a simple tool used to help quickly discover sensitive information in files recursively. Originally written to assist in rapidly searching files obtained during a penetration test.
Installation
Gold Digger requires Python3.
git clone https://github.com/ustayready/golddigger.git
virtualenv -p python3 .
source bin/activate
python dig.py –help
Use
Example Usage
Gold Digger will recursively go through all folders and files in search of content matching items listed in the gold.json file. Additionally, you can leverage an exclusion file called exclusions.json for skipping files matching specific extensions. Provide the root folder as the –directory flag.
An example structure could be:
You would provide the following command to parse all 3 account reports:
Results
The tool will create a log file containing the scanning results. Due to the nature of using regular expressions, there may be numerous false positives. Despite this, the tool has been proven to increase productivity when processing thousands of files.
Source: https://github.com/ustayready/