Skip to content

About

Finds sensitive data like .env files on github

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

 
 

Repository files navigation

env-finder logo

EnvFinder

EnvFinder is a security research tool that helps identify accidentally exposed configuration files (.env files) in public github repositories to support responsible disclosure and defensive analysis.


Run Locally using Docker

  1. Clone the Repository
  git clone https://github.com/RealGalaxyCat/env-finder

  1. Go into the project directory
  cd env-finder

  1. Add an .env file and set GITHUB_PAT to your personal access token
ℹ️ How do I generate a PAT? Click on your Github avatar in the top right corner → Settings → Developer Settings → Personal access tokens → Tokens (classic) → Generate new token → select a classic token
GITHUB_PAT=<your_pat>

  1. Start the service
  docker compose up

Responsible Use

This tool is intended for ethical security research and defensive analysis only.

Users are responsible for complying with:

  • GitHub Terms of Service
  • Applicable laws and regulations
  • Responsible disclosure practices

Do not use this tool to access systems without authorization.

About

Finds sensitive data like .env files on github

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages