> For the complete documentation index, see [llms.txt](https://davidtancredi.gitbook.io/pentesting-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidtancredi.gitbook.io/pentesting-notes/r3dcl1ff/webapp-pentest/assorted/secretsfinder.md).

# SecretsFinder

Find sectrets within files

<pre><code>git clone https://github.com/m4ll0k/SecretFinder.git
<strong>cd SecretFinder
</strong>pip3 install -r requirements.txt
chmod +x SecretFinder.py
python3 SecretFinder.py -h


#workflow

1)Run gau and katana on http.txt, sort unique urls into "gaukatana_partial.txt" 
2)cat gaukatana_partial.txt | uro -o filterparams.txt
3)cat filterparams.txt | grep ".js$" > js.txt
4)cat js.txt | uro | anew > jsfiles.txt
5)cat jsfiles.txt | while read url; do python3 SecretFinder.py -i $url -o cli >> secret.txt ; done

</code></pre>
