Truffle Security has introduced TruffleHog AWS Analyze, an expansion of its TruffleHog Enterprise platform designed to accelerate the remediation of leaked AWS credentials. This new feature enriches discovered AWS keys with detailed information on their permissions and access levels, enabling security teams to better assess risk and prioritize their response efforts.
TruffleHog Enterprise already identifies and verifies over 800 types of leaked secrets. With the addition of AWS Analyze, it now provides identity and access context for AWS, alongside existing support for SaaS platforms and Google Cloud. This allows organizations operating in multi-cloud environments to quickly understand the potential impact of a leaked secret and prioritize its remediation across all three platforms.
When an AWS credential is leaked, determining its potential impact often requires manual investigation into identity, permissions, and IAM relationships. TruffleHog AWS Analyze automates this process by identifying the AWS user or role associated with the credential, mapping its effective permissions, and revealing any roles it can assume to gain further access. This provides a clearer picture of the potential "blast radius." The tool also indicates when AWS returns incomplete results, alerting teams to a partial view of the analysis.
According to Dylan Ayrey, CEO of Truffle Security, the rapid creation and exposure of AWS credentials through agentic workflows often outpace a security team's ability to track them. Once embedded in automated processes, keys can be copied and reused extensively, persisting long after their original purpose is forgotten. TruffleHog AWS Analyze aims to provide the necessary context within the same workflow, helping teams understand exactly what has been exposed for quicker remediation.
AWS keys are frequently leaked, and many remain active long after exposure. A single AWS key can grant access to compute, storage, and databases, meaning a leak can expose the permissions controlling numerous systems, not just one. Recent research by Truffle Security found 64,024 unique leaked AWS keys from public code, container images, and datasets, with 88% still active. The median active leaked key had been exposed for five years, and only 14% had ever been rotated.
Among the closely examined keys, 84% had full administrator access, and one in six was a root key, granting full access to an AWS account. Surprisingly, 929 of these credentials had been flagged by AWS's own compromised-key quarantine policy, some more than three years prior, yet all remained authenticable. This indicated that despite AWS detecting the exposure, no remediation had occurred.
A scan of 7.6 petabytes of public AI training data on Hugging Face by TruffleHog revealed similar widespread exposure, with 3,343 live AWS keys still active. Over 900 of these keys could list S3 buckets containing at least 51.7 TB of private data. Julien Chaumond, CTO of Hugging Face, noted that while they proactively scan their platform with TruffleHog and notify publishers of verified secrets, an alert is just the beginning. He emphasized that a leaked key remains vulnerable until it is rotated, and showing teams the identity and access behind a credential helps translate notifications into action. Hugging Face users are advised to confirm their notification settings and rotate, rather than delete, any exposed keys.
By combining TruffleHog Enterprise's ability to find and verify every instance of a leaked key with the new access context provided by TruffleHog AWS Analyze, security teams are expected to achieve faster remediation of critical vulnerabilities.






