Latest commit

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Blacklight

Screenshot 2025-05-31 at 02 16 47

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Features

  • Multi-Source Scanning

    • Local files and directories
    • Databases (PostgreSQL, MySQL)
    • AWS S3 buckets
    • Slack workspace messages and files
    • Cloud Storage (Google Drive, Dropbox)
    • Git repositories
  • Advanced Detection

    • Pattern-based secret detection
    • Context-aware scanning
    • Multi-language support
    • Configurable severity levels
    • Rule categorization
    • Smart file format detection
  • Supported File Formats

    • Plain text files
    • JSON files (with nested object support)
    • YAML files (with nested object support)
    • XML files (with attribute scanning)
    • INI/Config files
    • Environment files (.env)
    • Configuration files
  • User Experience

    • Cross-platform compatibility (Windows, Linux, macOS)
    • Beautiful table output with go-pretty formatting
    • Color-coded severity indicators
    • Detailed violation reporting
    • Rich context for findings

Installation

Quick Install (Linux/macOS)

# macOS (Apple Silicon)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# macOS (Intel)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (x86_64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (ARM64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Verify installation
blacklight version

Using Go

# Using go install
go install github.com/adaptive-scale/blacklight@latest
# Or clone and build
git clone https://github.com/adaptive-scale/blacklight.git
cd blacklight
make build

Docker

# Pull the latest image
docker pull adaptivescale/blacklight:latest
# Run a scan
docker run -v $(pwd):/workspace adaptivescale/blacklight:latest scan /workspace

Windows

Download the appropriate .exe file from our releases page and add it to your PATH.

Verifying the Installation

After installation, verify that Blacklight is working correctly:

# Check version
blacklight version
# View help
blacklight --help
# Run a test scan
blacklight scan --help

Usage

Basic Usage

# Scan a directory
blacklight scan /path/to/directory
# Scan with verbose output
blacklight scan /path/to/directory --verbose
# Scan a database
blacklight scan --db "postgresql://user:pass@localhost:5432/dbname"# Scan an S3 bucket
blacklight scan --s3 "s3://bucket-name"# Scan cloud storage
blacklight scan --drive "gdrive://folder-id"

Rule Management

# List all rules
blacklight rules list
# List rules by type
blacklight rules list --type cloud
# List rules by severity
blacklight rules list --severity 3
# Add a new rule
blacklight rules add --name "Custom API Key" \
--regex "api_key_[a-zA-Z0-9]{32}" \
--severity 2 \
--type "secret"

Slack Workspace Scanning

Blacklight includes a powerful Slack scanner that can detect secrets and sensitive information in:

  • Channel messages (public and private)
  • Message threads
  • Direct messages (DMs)
  • Group messages
  • Shared files
  • File comments

Setup

  1. Create a Slack App at https://api.slack.com/apps
  2. Add the following OAuth scopes:
    channels:history - View messages and other content in public channels
    channels:read - View basic information about public channels
    files:read - View files shared in channels and conversations
    groups:history - View messages and other content in private channels
    groups:read - View basic information about private channels
    im:history - View messages and other content in direct messages
    im:read - View basic information about direct messages
    mpim:history - View messages and other content in group direct messages
    mpim:read - View basic information about group direct messages
    
  3. Install the app to your workspace
  4. Copy the Bot User OAuth Token (starts with xoxb-)

Usage

# Basic scan of all accessible channels
blacklight slack --token xoxb-your-token
# Scan specific channels
blacklight slack --token xoxb-your-token --channels C01234567,C89012345
# Scan recent messages
blacklight slack --token xoxb-your-token --days 7
# Full scan including threads and files
blacklight slack --token xoxb-your-token --include-threads --include-files

Configuration Options

OptionDescriptionDefault
--tokenSlack Bot User OAuth Token (required)-
--channelsComma-separated list of channel IDsAll accessible
--daysNumber of days of history to scan30
--include-threadsScan message threadsfalse
--include-filesScan file contentsfalse
--exclude-archivedSkip archived channelstrue

Performance Considerations

  • File scanning is disabled by default to improve performance
  • Files larger than 10MB are skipped
  • Use the --days flag to limit the scan window
  • Specify channels to scan for faster results

Cloud Storage Scanning

Blacklight can scan files in various cloud storage services for secrets and sensitive information:

Implemented Providers

  • Google Drive (gdrive://)

    • Scans files in specified folders
    • Supports file content analysis
    • Respects file size limits
    • OAuth2 authentication
    • Automatic file format detection
    • Recursive folder scanning
  • Dropbox (dropbox://)

    • Full folder scanning
    • File content analysis
    • Path-based access
    • Access token authentication
    • Smart file format handling
    • Size-based file filtering

Coming Soon

  • OneDrive (onedrive://) - In development
  • Box (box://) - Planned

Authentication

Each provider requires appropriate authentication:

# Google Drive - OAuth2 client configurationexport CLOUD_TOKEN='{"client_id":"...","client_secret":"...","redirect_uris":["..."]}'# Dropbox - Access Tokenexport CLOUD_TOKEN="your-dropbox-access-token"

Usage Examples

# Scan Google Drive folder
blacklight scan --drive "gdrive://folder-id"# Scan Dropbox folder
blacklight scan --drive "dropbox://path/to/folder"# Include shared files (Google Drive)
blacklight scan --drive "gdrive://folder-id" --include-shared
# Limit scan history
blacklight scan --drive "dropbox://folder" --days 7
# Adjust file size limit
blacklight scan --drive "gdrive://folder-id" --max-size 5242880 # 5MB

Configuration Options

OptionDescriptionDefault
--drive, -rCloud storage URL to scan-
--include-sharedInclude shared filesfalse
--daysDays of history to scan30
--max-sizeMaximum file size (bytes)10MB

File Format Support

The cloud storage scanner automatically detects and processes various file formats:

FormatExtensionsDetection
JSON.jsonExtension + Content
YAML.yaml, .ymlExtension + Content
XML.xmlExtension
INI.ini, .conf, .configExtension
ENV.envExtension
TextothersDefault

Performance Considerations

  • Files larger than the max-size limit are skipped
  • Use --days to limit scan scope
  • Specify precise folder paths for faster scans
  • Token expiration is handled automatically
  • File format detection optimizes scanning

Security Notes

  • Tokens should be kept secure and not shared
  • Use read-only access tokens when possible
  • Consider using environment variables for token storage
  • Regularly rotate access tokens
  • Ensure proper access permissions

Rule Types

Blacklight organizes its scanning rules into the following categories:

Authentication & Authorization

  • auth: Authentication tokens, passwords, OAuth credentials
  • key: Cryptographic keys (RSA, DSA, PGP, SSH)

Cloud & Infrastructure

  • cloud: Cloud provider credentials (AWS, Azure, GCP)
  • container: Container platform secrets (Docker, Kubernetes)
  • iac: Infrastructure as Code secrets (Terraform)
  • cdn: Content Delivery Network tokens

APIs & Services

  • api: Generic and service-specific API keys
  • monitoring: Monitoring service tokens (NewRelic, Rollbar)
  • ci: CI/CD platform credentials
  • vcs: Version Control System tokens (GitHub, GitLab)

Payment & Financial

  • payment: Payment gateway credentials
  • pci: Payment Card Industry data
  • ecommerce: E-commerce platform tokens

Data & Storage

  • database: Database credentials and endpoints
  • messaging: Message queue credentials
  • package: Package registry tokens

Other

  • secret: Generic secrets and environment variables
  • social: Social media platform tokens
  • security: Security-related credentials
  • config: Configuration file secrets
  • ai: AI service credentials

Rule Configuration

Rules are stored in ~/.blacklight/rules.yaml. Each rule has the following properties:

PropertyDescriptionRequired
idUnique identifierYes
nameHuman-readable nameYes
descriptionWhat the rule detectsNo
regexDetection patternYes
severity1 (low) to 3 (high)Yes
typeCategory from aboveYes
disabledSkip this ruleNo

Example Rule File

- id: "aws_access_key"name: "AWS Access Key"description: "Amazon Web Services access key ID"regex: "AKIA[0-9A-Z]{16}"severity: 3type: "cloud"disabled: false
- id: "stripe_key"name: "Stripe API Key"description: "Stripe secret API key"regex: "sk_live_[0-9a-zA-Z]{24}"severity: 3type: "payment"disabled: false

Output Format

Blacklight provides rich, color-coded output:

[Severity 3]: AWS Access Key Found
Location: slack://channel/C0123456/message/1234567890.123
Context: ...config = { accessKeyId: "AKIAXXXXXXXXXXXXXXXX", region: "us-east-1" }...
Match: AKIAXXXXXXXXXXXXXXXX
--------------------------------------------------------------------------------

The table output uses go-pretty for enhanced readability:

╭──────────────────────────┬──────────┬──────────┬─────────┬───────────────────────────────────╮
│ NAME │ TYPE │ SEVERITY │ STATUS │ PATTERN │
├──────────────────────────┼──────────┼──────────┼─────────┼───────────────────────────────────┤
│ AWS Access Key │ cloud │ 3 │ Enabled │ AKIA[0-9A-Z]{16} │
│ Stripe API Key │ payment │ 3 │ Enabled │ sk_live_[0-9a-zA-Z]{24} │
╰──────────────────────────┴──────────┴──────────┴─────────┴───────────────────────────────────╯

Default Rules

Blacklight comes with a comprehensive set of pre-configured rules for detecting various types of secrets and sensitive information:

Authentication & Authorization

Rule NameDescriptionSeverity
AWS Access KeyAmazon Web Services access key IDHigh
AWS Secret KeyAmazon Web Services secret access keyHigh
Generic API KeyGeneric API key patternsMedium
JWT TokenJSON Web TokenMedium
Basic AuthBasic Authentication credentialsHigh
OAuth Client SecretOAuth 2.0 client secretHigh
OAuth Access TokenOAuth 2.0 access tokenHigh
SSH Private KeySSH private key contentHigh

Cloud Services

Rule NameDescriptionSeverity
Azure Storage Account KeyAzure storage account access keyHigh
GCP Service AccountGoogle Cloud Platform service account keyHigh
Firebase Database URLFirebase realtime database URLMedium
Heroku API KeyHeroku platform API keyHigh
Digital Ocean TokenDigitalOcean API tokenHigh
Cloudflare API KeyCloudflare API key and tokenHigh
AWS Session TokenAWS temporary session tokenHigh

Payment & Financial

Rule NameDescriptionSeverity
Stripe API KeyStripe secret API keyHigh
Stripe Restricted KeyStripe restricted API keyHigh
PayPal Access TokenPayPal OAuth2 access tokenHigh
Square Access TokenSquare OAuth2 access tokenHigh
Credit Card NumberCredit card number patternsHigh

Database & Storage

Rule NameDescriptionSeverity
PostgreSQL ConnectionPostgreSQL connection stringHigh
MySQL ConnectionMySQL connection stringHigh
MongoDB ConnectionMongoDB connection URIHigh
Redis ConnectionRedis connection stringHigh
Elasticsearch ConnectionElasticsearch connection stringMedium

Communication & Messaging

Rule NameDescriptionSeverity
Slack TokenSlack API token and webhook URLHigh
Slack WebhookSlack incoming webhook URLMedium
Discord TokenDiscord bot tokenHigh
Discord WebhookDiscord webhook URLMedium
Twilio API KeyTwilio API keyHigh
SendGrid API KeySendGrid API keyHigh

Development & CI/CD

Rule NameDescriptionSeverity
GitHub TokenGitHub personal access tokenHigh
GitLab TokenGitLab personal access tokenHigh
NPM TokenNPM authentication tokenMedium
Docker RegistryDocker registry credentialsMedium
CircleCI TokenCircleCI API tokenHigh
Jenkins TokenJenkins API tokenHigh

AI & Machine Learning

Rule NameDescriptionSeverity
OpenAI API KeyOpenAI API keyHigh
Hugging Face TokenHugging Face API tokenHigh
Anthropic API KeyAnthropic API keyHigh
Cohere API KeyCohere API keyHigh
Replicate API TokenReplicate API tokenHigh

Analytics & Monitoring

Rule NameDescriptionSeverity
Google AnalyticsGoogle Analytics API keyMedium
New Relic KeyNew Relic license keyHigh
Datadog API KeyDatadog API keyHigh
Sentry DSNSentry client keyMedium
Mixpanel TokenMixpanel project tokenMedium

Generic Patterns

Rule NameDescriptionSeverity
Private KeyGeneric private key contentHigh
Password in URLPassword in URL parametersHigh
Environment VariableHardcoded environment variablesMedium
IP AddressPrivate IP addressesLow
Internal PathInternal system pathsLow

Custom Rules

You can add your own custom rules by creating a file at ~/.blacklight/rules.yaml:

- id: "custom_api_key"name: "Custom API Key"description: "Detects custom API key pattern"regex: "myapi_[a-zA-Z0-9]{32}"severity: 2type: "api"disabled: false
- id: "internal_token"name: "Internal Service Token"description: "Internal service authentication token"regex: "int_[a-zA-Z0-9]{24}"severity: 3type: "auth"disabled: false

Rule Properties

PropertyDescriptionRequiredExample
idUnique identifierYesaws_access_key
nameHuman-readable nameYes"AWS Access Key"
descriptionWhat the rule detectsNo"Amazon Web Services access key ID"
regexDetection patternYesAKIA[0-9A-Z]{16}
severity1 (low) to 3 (high)Yes3
typeCategory from types listYes"cloud"
disabledSkip this ruleNofalse

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

Copyright © 2025 Debarshi Basak

Licensed under the Apache License, Version 2.0

About

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Resources

Stars

12 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Blacklight

Screenshot 2025-05-31 at 02 16 47

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Features

  • Multi-Source Scanning

    • Local files and directories
    • Databases (PostgreSQL, MySQL)
    • AWS S3 buckets
    • Slack workspace messages and files
    • Cloud Storage (Google Drive, Dropbox)
    • Git repositories
  • Advanced Detection

    • Pattern-based secret detection
    • Context-aware scanning
    • Multi-language support
    • Configurable severity levels
    • Rule categorization
    • Smart file format detection
  • Supported File Formats

    • Plain text files
    • JSON files (with nested object support)
    • YAML files (with nested object support)
    • XML files (with attribute scanning)
    • INI/Config files
    • Environment files (.env)
    • Configuration files
  • User Experience

    • Cross-platform compatibility (Windows, Linux, macOS)
    • Beautiful table output with go-pretty formatting
    • Color-coded severity indicators
    • Detailed violation reporting
    • Rich context for findings

Installation

Quick Install (Linux/macOS)

# macOS (Apple Silicon)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# macOS (Intel)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (x86_64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (ARM64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Verify installation
blacklight version

Using Go

# Using go install
go install github.com/adaptive-scale/blacklight@latest
# Or clone and build
git clone https://github.com/adaptive-scale/blacklight.git
cd blacklight
make build

Docker

# Pull the latest image
docker pull adaptivescale/blacklight:latest
# Run a scan
docker run -v $(pwd):/workspace adaptivescale/blacklight:latest scan /workspace

Windows

Download the appropriate .exe file from our releases page and add it to your PATH.

Verifying the Installation

After installation, verify that Blacklight is working correctly:

# Check version
blacklight version
# View help
blacklight --help
# Run a test scan
blacklight scan --help

Usage

Basic Usage

# Scan a directory
blacklight scan /path/to/directory
# Scan with verbose output
blacklight scan /path/to/directory --verbose
# Scan a database
blacklight scan --db "postgresql://user:pass@localhost:5432/dbname"# Scan an S3 bucket
blacklight scan --s3 "s3://bucket-name"# Scan cloud storage
blacklight scan --drive "gdrive://folder-id"

Rule Management

# List all rules
blacklight rules list
# List rules by type
blacklight rules list --type cloud
# List rules by severity
blacklight rules list --severity 3
# Add a new rule
blacklight rules add --name "Custom API Key" \
--regex "api_key_[a-zA-Z0-9]{32}" \
--severity 2 \
--type "secret"

Slack Workspace Scanning

Blacklight includes a powerful Slack scanner that can detect secrets and sensitive information in:

  • Channel messages (public and private)
  • Message threads
  • Direct messages (DMs)
  • Group messages
  • Shared files
  • File comments

Setup

  1. Create a Slack App at https://api.slack.com/apps
  2. Add the following OAuth scopes:
    channels:history - View messages and other content in public channels
    channels:read - View basic information about public channels
    files:read - View files shared in channels and conversations
    groups:history - View messages and other content in private channels
    groups:read - View basic information about private channels
    im:history - View messages and other content in direct messages
    im:read - View basic information about direct messages
    mpim:history - View messages and other content in group direct messages
    mpim:read - View basic information about group direct messages
    
  3. Install the app to your workspace
  4. Copy the Bot User OAuth Token (starts with xoxb-)

Usage

# Basic scan of all accessible channels
blacklight slack --token xoxb-your-token
# Scan specific channels
blacklight slack --token xoxb-your-token --channels C01234567,C89012345
# Scan recent messages
blacklight slack --token xoxb-your-token --days 7
# Full scan including threads and files
blacklight slack --token xoxb-your-token --include-threads --include-files

Configuration Options

OptionDescriptionDefault
--tokenSlack Bot User OAuth Token (required)-
--channelsComma-separated list of channel IDsAll accessible
--daysNumber of days of history to scan30
--include-threadsScan message threadsfalse
--include-filesScan file contentsfalse
--exclude-archivedSkip archived channelstrue

Performance Considerations

  • File scanning is disabled by default to improve performance
  • Files larger than 10MB are skipped
  • Use the --days flag to limit the scan window
  • Specify channels to scan for faster results

Cloud Storage Scanning

Blacklight can scan files in various cloud storage services for secrets and sensitive information:

Implemented Providers

  • Google Drive (gdrive://)

    • Scans files in specified folders
    • Supports file content analysis
    • Respects file size limits
    • OAuth2 authentication
    • Automatic file format detection
    • Recursive folder scanning
  • Dropbox (dropbox://)

    • Full folder scanning
    • File content analysis
    • Path-based access
    • Access token authentication
    • Smart file format handling
    • Size-based file filtering

Coming Soon

  • OneDrive (onedrive://) - In development
  • Box (box://) - Planned

Authentication

Each provider requires appropriate authentication:

# Google Drive - OAuth2 client configurationexport CLOUD_TOKEN='{"client_id":"...","client_secret":"...","redirect_uris":["..."]}'# Dropbox - Access Tokenexport CLOUD_TOKEN="your-dropbox-access-token"

Usage Examples

# Scan Google Drive folder
blacklight scan --drive "gdrive://folder-id"# Scan Dropbox folder
blacklight scan --drive "dropbox://path/to/folder"# Include shared files (Google Drive)
blacklight scan --drive "gdrive://folder-id" --include-shared
# Limit scan history
blacklight scan --drive "dropbox://folder" --days 7
# Adjust file size limit
blacklight scan --drive "gdrive://folder-id" --max-size 5242880 # 5MB

Configuration Options

OptionDescriptionDefault
--drive, -rCloud storage URL to scan-
--include-sharedInclude shared filesfalse
--daysDays of history to scan30
--max-sizeMaximum file size (bytes)10MB

File Format Support

The cloud storage scanner automatically detects and processes various file formats:

FormatExtensionsDetection
JSON.jsonExtension + Content
YAML.yaml, .ymlExtension + Content
XML.xmlExtension
INI.ini, .conf, .configExtension
ENV.envExtension
TextothersDefault

Performance Considerations

  • Files larger than the max-size limit are skipped
  • Use --days to limit scan scope
  • Specify precise folder paths for faster scans
  • Token expiration is handled automatically
  • File format detection optimizes scanning

Security Notes

  • Tokens should be kept secure and not shared
  • Use read-only access tokens when possible
  • Consider using environment variables for token storage
  • Regularly rotate access tokens
  • Ensure proper access permissions

Rule Types

Blacklight organizes its scanning rules into the following categories:

Authentication & Authorization

  • auth: Authentication tokens, passwords, OAuth credentials
  • key: Cryptographic keys (RSA, DSA, PGP, SSH)

Cloud & Infrastructure

  • cloud: Cloud provider credentials (AWS, Azure, GCP)
  • container: Container platform secrets (Docker, Kubernetes)
  • iac: Infrastructure as Code secrets (Terraform)
  • cdn: Content Delivery Network tokens

APIs & Services

  • api: Generic and service-specific API keys
  • monitoring: Monitoring service tokens (NewRelic, Rollbar)
  • ci: CI/CD platform credentials
  • vcs: Version Control System tokens (GitHub, GitLab)

Payment & Financial

  • payment: Payment gateway credentials
  • pci: Payment Card Industry data
  • ecommerce: E-commerce platform tokens

Data & Storage

  • database: Database credentials and endpoints
  • messaging: Message queue credentials
  • package: Package registry tokens

Other

  • secret: Generic secrets and environment variables
  • social: Social media platform tokens
  • security: Security-related credentials
  • config: Configuration file secrets
  • ai: AI service credentials

Rule Configuration

Rules are stored in ~/.blacklight/rules.yaml. Each rule has the following properties:

PropertyDescriptionRequired
idUnique identifierYes
nameHuman-readable nameYes
descriptionWhat the rule detectsNo
regexDetection patternYes
severity1 (low) to 3 (high)Yes
typeCategory from aboveYes
disabledSkip this ruleNo

Example Rule File

- id: "aws_access_key"name: "AWS Access Key"description: "Amazon Web Services access key ID"regex: "AKIA[0-9A-Z]{16}"severity: 3type: "cloud"disabled: false
- id: "stripe_key"name: "Stripe API Key"description: "Stripe secret API key"regex: "sk_live_[0-9a-zA-Z]{24}"severity: 3type: "payment"disabled: false

Output Format

Blacklight provides rich, color-coded output:

[Severity 3]: AWS Access Key Found
Location: slack://channel/C0123456/message/1234567890.123
Context: ...config = { accessKeyId: "AKIAXXXXXXXXXXXXXXXX", region: "us-east-1" }...
Match: AKIAXXXXXXXXXXXXXXXX
--------------------------------------------------------------------------------

The table output uses go-pretty for enhanced readability:

╭──────────────────────────┬──────────┬──────────┬─────────┬───────────────────────────────────╮
│ NAME │ TYPE │ SEVERITY │ STATUS │ PATTERN │
├──────────────────────────┼──────────┼──────────┼─────────┼───────────────────────────────────┤
│ AWS Access Key │ cloud │ 3 │ Enabled │ AKIA[0-9A-Z]{16} │
│ Stripe API Key │ payment │ 3 │ Enabled │ sk_live_[0-9a-zA-Z]{24} │
╰──────────────────────────┴──────────┴──────────┴─────────┴───────────────────────────────────╯

Default Rules

Blacklight comes with a comprehensive set of pre-configured rules for detecting various types of secrets and sensitive information:

Authentication & Authorization

Rule NameDescriptionSeverity
AWS Access KeyAmazon Web Services access key IDHigh
AWS Secret KeyAmazon Web Services secret access keyHigh
Generic API KeyGeneric API key patternsMedium
JWT TokenJSON Web TokenMedium
Basic AuthBasic Authentication credentialsHigh
OAuth Client SecretOAuth 2.0 client secretHigh
OAuth Access TokenOAuth 2.0 access tokenHigh
SSH Private KeySSH private key contentHigh

Cloud Services

Rule NameDescriptionSeverity
Azure Storage Account KeyAzure storage account access keyHigh
GCP Service AccountGoogle Cloud Platform service account keyHigh
Firebase Database URLFirebase realtime database URLMedium
Heroku API KeyHeroku platform API keyHigh
Digital Ocean TokenDigitalOcean API tokenHigh
Cloudflare API KeyCloudflare API key and tokenHigh
AWS Session TokenAWS temporary session tokenHigh

Payment & Financial

Rule NameDescriptionSeverity
Stripe API KeyStripe secret API keyHigh
Stripe Restricted KeyStripe restricted API keyHigh
PayPal Access TokenPayPal OAuth2 access tokenHigh
Square Access TokenSquare OAuth2 access tokenHigh
Credit Card NumberCredit card number patternsHigh

Database & Storage

Rule NameDescriptionSeverity
PostgreSQL ConnectionPostgreSQL connection stringHigh
MySQL ConnectionMySQL connection stringHigh
MongoDB ConnectionMongoDB connection URIHigh
Redis ConnectionRedis connection stringHigh
Elasticsearch ConnectionElasticsearch connection stringMedium

Communication & Messaging

Rule NameDescriptionSeverity
Slack TokenSlack API token and webhook URLHigh
Slack WebhookSlack incoming webhook URLMedium
Discord TokenDiscord bot tokenHigh
Discord WebhookDiscord webhook URLMedium
Twilio API KeyTwilio API keyHigh
SendGrid API KeySendGrid API keyHigh

Development & CI/CD

Rule NameDescriptionSeverity
GitHub TokenGitHub personal access tokenHigh
GitLab TokenGitLab personal access tokenHigh
NPM TokenNPM authentication tokenMedium
Docker RegistryDocker registry credentialsMedium
CircleCI TokenCircleCI API tokenHigh
Jenkins TokenJenkins API tokenHigh

AI & Machine Learning

Rule NameDescriptionSeverity
OpenAI API KeyOpenAI API keyHigh
Hugging Face TokenHugging Face API tokenHigh
Anthropic API KeyAnthropic API keyHigh
Cohere API KeyCohere API keyHigh
Replicate API TokenReplicate API tokenHigh

Analytics & Monitoring

Rule NameDescriptionSeverity
Google AnalyticsGoogle Analytics API keyMedium
New Relic KeyNew Relic license keyHigh
Datadog API KeyDatadog API keyHigh
Sentry DSNSentry client keyMedium
Mixpanel TokenMixpanel project tokenMedium

Generic Patterns

Rule NameDescriptionSeverity
Private KeyGeneric private key contentHigh
Password in URLPassword in URL parametersHigh
Environment VariableHardcoded environment variablesMedium
IP AddressPrivate IP addressesLow
Internal PathInternal system pathsLow

Custom Rules

You can add your own custom rules by creating a file at ~/.blacklight/rules.yaml:

- id: "custom_api_key"name: "Custom API Key"description: "Detects custom API key pattern"regex: "myapi_[a-zA-Z0-9]{32}"severity: 2type: "api"disabled: false
- id: "internal_token"name: "Internal Service Token"description: "Internal service authentication token"regex: "int_[a-zA-Z0-9]{24}"severity: 3type: "auth"disabled: false

Rule Properties

PropertyDescriptionRequiredExample
idUnique identifierYesaws_access_key
nameHuman-readable nameYes"AWS Access Key"
descriptionWhat the rule detectsNo"Amazon Web Services access key ID"
regexDetection patternYesAKIA[0-9A-Z]{16}
severity1 (low) to 3 (high)Yes3
typeCategory from types listYes"cloud"
disabledSkip this ruleNofalse

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

Copyright © 2025 Debarshi Basak

Licensed under the Apache License, Version 2.0

About

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Resources

Stars

12 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Blacklight

Screenshot 2025-05-31 at 02 16 47

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Features

  • Multi-Source Scanning

    • Local files and directories
    • Databases (PostgreSQL, MySQL)
    • AWS S3 buckets
    • Slack workspace messages and files
    • Cloud Storage (Google Drive, Dropbox)
    • Git repositories
  • Advanced Detection

    • Pattern-based secret detection
    • Context-aware scanning
    • Multi-language support
    • Configurable severity levels
    • Rule categorization
    • Smart file format detection
  • Supported File Formats

    • Plain text files
    • JSON files (with nested object support)
    • YAML files (with nested object support)
    • XML files (with attribute scanning)
    • INI/Config files
    • Environment files (.env)
    • Configuration files
  • User Experience

    • Cross-platform compatibility (Windows, Linux, macOS)
    • Beautiful table output with go-pretty formatting
    • Color-coded severity indicators
    • Detailed violation reporting
    • Rich context for findings

Installation

Quick Install (Linux/macOS)

# macOS (Apple Silicon)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# macOS (Intel)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (x86_64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (ARM64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Verify installation
blacklight version

Using Go

# Using go install
go install github.com/adaptive-scale/blacklight@latest
# Or clone and build
git clone https://github.com/adaptive-scale/blacklight.git
cd blacklight
make build

Docker

# Pull the latest image
docker pull adaptivescale/blacklight:latest
# Run a scan
docker run -v $(pwd):/workspace adaptivescale/blacklight:latest scan /workspace

Windows

Download the appropriate .exe file from our releases page and add it to your PATH.

Verifying the Installation

After installation, verify that Blacklight is working correctly:

# Check version
blacklight version
# View help
blacklight --help
# Run a test scan
blacklight scan --help

Usage

Basic Usage

# Scan a directory
blacklight scan /path/to/directory
# Scan with verbose output
blacklight scan /path/to/directory --verbose
# Scan a database
blacklight scan --db "postgresql://user:pass@localhost:5432/dbname"# Scan an S3 bucket
blacklight scan --s3 "s3://bucket-name"# Scan cloud storage
blacklight scan --drive "gdrive://folder-id"

Rule Management

# List all rules
blacklight rules list
# List rules by type
blacklight rules list --type cloud
# List rules by severity
blacklight rules list --severity 3
# Add a new rule
blacklight rules add --name "Custom API Key" \
--regex "api_key_[a-zA-Z0-9]{32}" \
--severity 2 \
--type "secret"

Slack Workspace Scanning

Blacklight includes a powerful Slack scanner that can detect secrets and sensitive information in:

  • Channel messages (public and private)
  • Message threads
  • Direct messages (DMs)
  • Group messages
  • Shared files
  • File comments

Setup

  1. Create a Slack App at https://api.slack.com/apps
  2. Add the following OAuth scopes:
    channels:history - View messages and other content in public channels
    channels:read - View basic information about public channels
    files:read - View files shared in channels and conversations
    groups:history - View messages and other content in private channels
    groups:read - View basic information about private channels
    im:history - View messages and other content in direct messages
    im:read - View basic information about direct messages
    mpim:history - View messages and other content in group direct messages
    mpim:read - View basic information about group direct messages
    
  3. Install the app to your workspace
  4. Copy the Bot User OAuth Token (starts with xoxb-)

Usage

# Basic scan of all accessible channels
blacklight slack --token xoxb-your-token
# Scan specific channels
blacklight slack --token xoxb-your-token --channels C01234567,C89012345
# Scan recent messages
blacklight slack --token xoxb-your-token --days 7
# Full scan including threads and files
blacklight slack --token xoxb-your-token --include-threads --include-files

Configuration Options

OptionDescriptionDefault
--tokenSlack Bot User OAuth Token (required)-
--channelsComma-separated list of channel IDsAll accessible
--daysNumber of days of history to scan30
--include-threadsScan message threadsfalse
--include-filesScan file contentsfalse
--exclude-archivedSkip archived channelstrue

Performance Considerations

  • File scanning is disabled by default to improve performance
  • Files larger than 10MB are skipped
  • Use the --days flag to limit the scan window
  • Specify channels to scan for faster results

Cloud Storage Scanning

Blacklight can scan files in various cloud storage services for secrets and sensitive information:

Implemented Providers

  • Google Drive (gdrive://)

    • Scans files in specified folders
    • Supports file content analysis
    • Respects file size limits
    • OAuth2 authentication
    • Automatic file format detection
    • Recursive folder scanning
  • Dropbox (dropbox://)

    • Full folder scanning
    • File content analysis
    • Path-based access
    • Access token authentication
    • Smart file format handling
    • Size-based file filtering

Coming Soon

  • OneDrive (onedrive://) - In development
  • Box (box://) - Planned

Authentication

Each provider requires appropriate authentication:

# Google Drive - OAuth2 client configurationexport CLOUD_TOKEN='{"client_id":"...","client_secret":"...","redirect_uris":["..."]}'# Dropbox - Access Tokenexport CLOUD_TOKEN="your-dropbox-access-token"

Usage Examples

# Scan Google Drive folder
blacklight scan --drive "gdrive://folder-id"# Scan Dropbox folder
blacklight scan --drive "dropbox://path/to/folder"# Include shared files (Google Drive)
blacklight scan --drive "gdrive://folder-id" --include-shared
# Limit scan history
blacklight scan --drive "dropbox://folder" --days 7
# Adjust file size limit
blacklight scan --drive "gdrive://folder-id" --max-size 5242880 # 5MB

Configuration Options

OptionDescriptionDefault
--drive, -rCloud storage URL to scan-
--include-sharedInclude shared filesfalse
--daysDays of history to scan30
--max-sizeMaximum file size (bytes)10MB

File Format Support

The cloud storage scanner automatically detects and processes various file formats:

FormatExtensionsDetection
JSON.jsonExtension + Content
YAML.yaml, .ymlExtension + Content
XML.xmlExtension
INI.ini, .conf, .configExtension
ENV.envExtension
TextothersDefault

Performance Considerations

  • Files larger than the max-size limit are skipped
  • Use --days to limit scan scope
  • Specify precise folder paths for faster scans
  • Token expiration is handled automatically
  • File format detection optimizes scanning

Security Notes

  • Tokens should be kept secure and not shared
  • Use read-only access tokens when possible
  • Consider using environment variables for token storage
  • Regularly rotate access tokens
  • Ensure proper access permissions

Rule Types

Blacklight organizes its scanning rules into the following categories:

Authentication & Authorization

  • auth: Authentication tokens, passwords, OAuth credentials
  • key: Cryptographic keys (RSA, DSA, PGP, SSH)

Cloud & Infrastructure

  • cloud: Cloud provider credentials (AWS, Azure, GCP)
  • container: Container platform secrets (Docker, Kubernetes)
  • iac: Infrastructure as Code secrets (Terraform)
  • cdn: Content Delivery Network tokens

APIs & Services

  • api: Generic and service-specific API keys
  • monitoring: Monitoring service tokens (NewRelic, Rollbar)
  • ci: CI/CD platform credentials
  • vcs: Version Control System tokens (GitHub, GitLab)

Payment & Financial

  • payment: Payment gateway credentials
  • pci: Payment Card Industry data
  • ecommerce: E-commerce platform tokens

Data & Storage

  • database: Database credentials and endpoints
  • messaging: Message queue credentials
  • package: Package registry tokens

Other

  • secret: Generic secrets and environment variables
  • social: Social media platform tokens
  • security: Security-related credentials
  • config: Configuration file secrets
  • ai: AI service credentials

Rule Configuration

Rules are stored in ~/.blacklight/rules.yaml. Each rule has the following properties:

PropertyDescriptionRequired
idUnique identifierYes
nameHuman-readable nameYes
descriptionWhat the rule detectsNo
regexDetection patternYes
severity1 (low) to 3 (high)Yes
typeCategory from aboveYes
disabledSkip this ruleNo

Example Rule File

- id: "aws_access_key"name: "AWS Access Key"description: "Amazon Web Services access key ID"regex: "AKIA[0-9A-Z]{16}"severity: 3type: "cloud"disabled: false
- id: "stripe_key"name: "Stripe API Key"description: "Stripe secret API key"regex: "sk_live_[0-9a-zA-Z]{24}"severity: 3type: "payment"disabled: false

Output Format

Blacklight provides rich, color-coded output:

[Severity 3]: AWS Access Key Found
Location: slack://channel/C0123456/message/1234567890.123
Context: ...config = { accessKeyId: "AKIAXXXXXXXXXXXXXXXX", region: "us-east-1" }...
Match: AKIAXXXXXXXXXXXXXXXX
--------------------------------------------------------------------------------

The table output uses go-pretty for enhanced readability:

╭──────────────────────────┬──────────┬──────────┬─────────┬───────────────────────────────────╮
│ NAME │ TYPE │ SEVERITY │ STATUS │ PATTERN │
├──────────────────────────┼──────────┼──────────┼─────────┼───────────────────────────────────┤
│ AWS Access Key │ cloud │ 3 │ Enabled │ AKIA[0-9A-Z]{16} │
│ Stripe API Key │ payment │ 3 │ Enabled │ sk_live_[0-9a-zA-Z]{24} │
╰──────────────────────────┴──────────┴──────────┴─────────┴───────────────────────────────────╯

Default Rules

Blacklight comes with a comprehensive set of pre-configured rules for detecting various types of secrets and sensitive information:

Authentication & Authorization

Rule NameDescriptionSeverity
AWS Access KeyAmazon Web Services access key IDHigh
AWS Secret KeyAmazon Web Services secret access keyHigh
Generic API KeyGeneric API key patternsMedium
JWT TokenJSON Web TokenMedium
Basic AuthBasic Authentication credentialsHigh
OAuth Client SecretOAuth 2.0 client secretHigh
OAuth Access TokenOAuth 2.0 access tokenHigh
SSH Private KeySSH private key contentHigh

Cloud Services

Rule NameDescriptionSeverity
Azure Storage Account KeyAzure storage account access keyHigh
GCP Service AccountGoogle Cloud Platform service account keyHigh
Firebase Database URLFirebase realtime database URLMedium
Heroku API KeyHeroku platform API keyHigh
Digital Ocean TokenDigitalOcean API tokenHigh
Cloudflare API KeyCloudflare API key and tokenHigh
AWS Session TokenAWS temporary session tokenHigh

Payment & Financial

Rule NameDescriptionSeverity
Stripe API KeyStripe secret API keyHigh
Stripe Restricted KeyStripe restricted API keyHigh
PayPal Access TokenPayPal OAuth2 access tokenHigh
Square Access TokenSquare OAuth2 access tokenHigh
Credit Card NumberCredit card number patternsHigh

Database & Storage

Rule NameDescriptionSeverity
PostgreSQL ConnectionPostgreSQL connection stringHigh
MySQL ConnectionMySQL connection stringHigh
MongoDB ConnectionMongoDB connection URIHigh
Redis ConnectionRedis connection stringHigh
Elasticsearch ConnectionElasticsearch connection stringMedium

Communication & Messaging

Rule NameDescriptionSeverity
Slack TokenSlack API token and webhook URLHigh
Slack WebhookSlack incoming webhook URLMedium
Discord TokenDiscord bot tokenHigh
Discord WebhookDiscord webhook URLMedium
Twilio API KeyTwilio API keyHigh
SendGrid API KeySendGrid API keyHigh

Development & CI/CD

Rule NameDescriptionSeverity
GitHub TokenGitHub personal access tokenHigh
GitLab TokenGitLab personal access tokenHigh
NPM TokenNPM authentication tokenMedium
Docker RegistryDocker registry credentialsMedium
CircleCI TokenCircleCI API tokenHigh
Jenkins TokenJenkins API tokenHigh

AI & Machine Learning

Rule NameDescriptionSeverity
OpenAI API KeyOpenAI API keyHigh
Hugging Face TokenHugging Face API tokenHigh
Anthropic API KeyAnthropic API keyHigh
Cohere API KeyCohere API keyHigh
Replicate API TokenReplicate API tokenHigh

Analytics & Monitoring

Rule NameDescriptionSeverity
Google AnalyticsGoogle Analytics API keyMedium
New Relic KeyNew Relic license keyHigh
Datadog API KeyDatadog API keyHigh
Sentry DSNSentry client keyMedium
Mixpanel TokenMixpanel project tokenMedium

Generic Patterns

Rule NameDescriptionSeverity
Private KeyGeneric private key contentHigh
Password in URLPassword in URL parametersHigh
Environment VariableHardcoded environment variablesMedium
IP AddressPrivate IP addressesLow
Internal PathInternal system pathsLow

Custom Rules

You can add your own custom rules by creating a file at ~/.blacklight/rules.yaml:

- id: "custom_api_key"name: "Custom API Key"description: "Detects custom API key pattern"regex: "myapi_[a-zA-Z0-9]{32}"severity: 2type: "api"disabled: false
- id: "internal_token"name: "Internal Service Token"description: "Internal service authentication token"regex: "int_[a-zA-Z0-9]{24}"severity: 3type: "auth"disabled: false

Rule Properties

PropertyDescriptionRequiredExample
idUnique identifierYesaws_access_key
nameHuman-readable nameYes"AWS Access Key"
descriptionWhat the rule detectsNo"Amazon Web Services access key ID"
regexDetection patternYesAKIA[0-9A-Z]{16}
severity1 (low) to 3 (high)Yes3
typeCategory from types listYes"cloud"
disabledSkip this ruleNofalse

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

Copyright © 2025 Debarshi Basak

Licensed under the Apache License, Version 2.0

About

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Resources

Stars

12 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Blacklight

Screenshot 2025-05-31 at 02 16 47

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Features

  • Multi-Source Scanning

    • Local files and directories
    • Databases (PostgreSQL, MySQL)
    • AWS S3 buckets
    • Slack workspace messages and files
    • Cloud Storage (Google Drive, Dropbox)
    • Git repositories
  • Advanced Detection

    • Pattern-based secret detection
    • Context-aware scanning
    • Multi-language support
    • Configurable severity levels
    • Rule categorization
    • Smart file format detection
  • Supported File Formats

    • Plain text files
    • JSON files (with nested object support)
    • YAML files (with nested object support)
    • XML files (with attribute scanning)
    • INI/Config files
    • Environment files (.env)
    • Configuration files
  • User Experience

    • Cross-platform compatibility (Windows, Linux, macOS)
    • Beautiful table output with go-pretty formatting
    • Color-coded severity indicators
    • Detailed violation reporting
    • Rich context for findings

Installation

Quick Install (Linux/macOS)

# macOS (Apple Silicon)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# macOS (Intel)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (x86_64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (ARM64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Verify installation
blacklight version

Using Go

# Using go install
go install github.com/adaptive-scale/blacklight@latest
# Or clone and build
git clone https://github.com/adaptive-scale/blacklight.git
cd blacklight
make build

Docker

# Pull the latest image
docker pull adaptivescale/blacklight:latest
# Run a scan
docker run -v $(pwd):/workspace adaptivescale/blacklight:latest scan /workspace

Windows

Download the appropriate .exe file from our releases page and add it to your PATH.

Verifying the Installation

After installation, verify that Blacklight is working correctly:

# Check version
blacklight version
# View help
blacklight --help
# Run a test scan
blacklight scan --help

Usage

Basic Usage

# Scan a directory
blacklight scan /path/to/directory
# Scan with verbose output
blacklight scan /path/to/directory --verbose
# Scan a database
blacklight scan --db "postgresql://user:pass@localhost:5432/dbname"# Scan an S3 bucket
blacklight scan --s3 "s3://bucket-name"# Scan cloud storage
blacklight scan --drive "gdrive://folder-id"

Rule Management

# List all rules
blacklight rules list
# List rules by type
blacklight rules list --type cloud
# List rules by severity
blacklight rules list --severity 3
# Add a new rule
blacklight rules add --name "Custom API Key" \
--regex "api_key_[a-zA-Z0-9]{32}" \
--severity 2 \
--type "secret"

Slack Workspace Scanning

Blacklight includes a powerful Slack scanner that can detect secrets and sensitive information in:

  • Channel messages (public and private)
  • Message threads
  • Direct messages (DMs)
  • Group messages
  • Shared files
  • File comments

Setup

  1. Create a Slack App at https://api.slack.com/apps
  2. Add the following OAuth scopes:
    channels:history - View messages and other content in public channels
    channels:read - View basic information about public channels
    files:read - View files shared in channels and conversations
    groups:history - View messages and other content in private channels
    groups:read - View basic information about private channels
    im:history - View messages and other content in direct messages
    im:read - View basic information about direct messages
    mpim:history - View messages and other content in group direct messages
    mpim:read - View basic information about group direct messages
    
  3. Install the app to your workspace
  4. Copy the Bot User OAuth Token (starts with xoxb-)

Usage

# Basic scan of all accessible channels
blacklight slack --token xoxb-your-token
# Scan specific channels
blacklight slack --token xoxb-your-token --channels C01234567,C89012345
# Scan recent messages
blacklight slack --token xoxb-your-token --days 7
# Full scan including threads and files
blacklight slack --token xoxb-your-token --include-threads --include-files

Configuration Options

OptionDescriptionDefault
--tokenSlack Bot User OAuth Token (required)-
--channelsComma-separated list of channel IDsAll accessible
--daysNumber of days of history to scan30
--include-threadsScan message threadsfalse
--include-filesScan file contentsfalse
--exclude-archivedSkip archived channelstrue

Performance Considerations

  • File scanning is disabled by default to improve performance
  • Files larger than 10MB are skipped
  • Use the --days flag to limit the scan window
  • Specify channels to scan for faster results

Cloud Storage Scanning

Blacklight can scan files in various cloud storage services for secrets and sensitive information:

Implemented Providers

  • Google Drive (gdrive://)

    • Scans files in specified folders
    • Supports file content analysis
    • Respects file size limits
    • OAuth2 authentication
    • Automatic file format detection
    • Recursive folder scanning
  • Dropbox (dropbox://)

    • Full folder scanning
    • File content analysis
    • Path-based access
    • Access token authentication
    • Smart file format handling
    • Size-based file filtering

Coming Soon

  • OneDrive (onedrive://) - In development
  • Box (box://) - Planned

Authentication

Each provider requires appropriate authentication:

# Google Drive - OAuth2 client configurationexport CLOUD_TOKEN='{"client_id":"...","client_secret":"...","redirect_uris":["..."]}'# Dropbox - Access Tokenexport CLOUD_TOKEN="your-dropbox-access-token"

Usage Examples

# Scan Google Drive folder
blacklight scan --drive "gdrive://folder-id"# Scan Dropbox folder
blacklight scan --drive "dropbox://path/to/folder"# Include shared files (Google Drive)
blacklight scan --drive "gdrive://folder-id" --include-shared
# Limit scan history
blacklight scan --drive "dropbox://folder" --days 7
# Adjust file size limit
blacklight scan --drive "gdrive://folder-id" --max-size 5242880 # 5MB

Configuration Options

OptionDescriptionDefault
--drive, -rCloud storage URL to scan-
--include-sharedInclude shared filesfalse
--daysDays of history to scan30
--max-sizeMaximum file size (bytes)10MB

File Format Support

The cloud storage scanner automatically detects and processes various file formats:

FormatExtensionsDetection
JSON.jsonExtension + Content
YAML.yaml, .ymlExtension + Content
XML.xmlExtension
INI.ini, .conf, .configExtension
ENV.envExtension
TextothersDefault

Performance Considerations

  • Files larger than the max-size limit are skipped
  • Use --days to limit scan scope
  • Specify precise folder paths for faster scans
  • Token expiration is handled automatically
  • File format detection optimizes scanning

Security Notes

  • Tokens should be kept secure and not shared
  • Use read-only access tokens when possible
  • Consider using environment variables for token storage
  • Regularly rotate access tokens
  • Ensure proper access permissions

Rule Types

Blacklight organizes its scanning rules into the following categories:

Authentication & Authorization

  • auth: Authentication tokens, passwords, OAuth credentials
  • key: Cryptographic keys (RSA, DSA, PGP, SSH)

Cloud & Infrastructure

  • cloud: Cloud provider credentials (AWS, Azure, GCP)
  • container: Container platform secrets (Docker, Kubernetes)
  • iac: Infrastructure as Code secrets (Terraform)
  • cdn: Content Delivery Network tokens

APIs & Services

  • api: Generic and service-specific API keys
  • monitoring: Monitoring service tokens (NewRelic, Rollbar)
  • ci: CI/CD platform credentials
  • vcs: Version Control System tokens (GitHub, GitLab)

Payment & Financial

  • payment: Payment gateway credentials
  • pci: Payment Card Industry data
  • ecommerce: E-commerce platform tokens

Data & Storage

  • database: Database credentials and endpoints
  • messaging: Message queue credentials
  • package: Package registry tokens

Other

  • secret: Generic secrets and environment variables
  • social: Social media platform tokens
  • security: Security-related credentials
  • config: Configuration file secrets
  • ai: AI service credentials

Rule Configuration

Rules are stored in ~/.blacklight/rules.yaml. Each rule has the following properties:

PropertyDescriptionRequired
idUnique identifierYes
nameHuman-readable nameYes
descriptionWhat the rule detectsNo
regexDetection patternYes
severity1 (low) to 3 (high)Yes
typeCategory from aboveYes
disabledSkip this ruleNo

Example Rule File

- id: "aws_access_key"name: "AWS Access Key"description: "Amazon Web Services access key ID"regex: "AKIA[0-9A-Z]{16}"severity: 3type: "cloud"disabled: false
- id: "stripe_key"name: "Stripe API Key"description: "Stripe secret API key"regex: "sk_live_[0-9a-zA-Z]{24}"severity: 3type: "payment"disabled: false

Output Format

Blacklight provides rich, color-coded output:

[Severity 3]: AWS Access Key Found
Location: slack://channel/C0123456/message/1234567890.123
Context: ...config = { accessKeyId: "AKIAXXXXXXXXXXXXXXXX", region: "us-east-1" }...
Match: AKIAXXXXXXXXXXXXXXXX
--------------------------------------------------------------------------------

The table output uses go-pretty for enhanced readability:

╭──────────────────────────┬──────────┬──────────┬─────────┬───────────────────────────────────╮
│ NAME │ TYPE │ SEVERITY │ STATUS │ PATTERN │
├──────────────────────────┼──────────┼──────────┼─────────┼───────────────────────────────────┤
│ AWS Access Key │ cloud │ 3 │ Enabled │ AKIA[0-9A-Z]{16} │
│ Stripe API Key │ payment │ 3 │ Enabled │ sk_live_[0-9a-zA-Z]{24} │
╰──────────────────────────┴──────────┴──────────┴─────────┴───────────────────────────────────╯

Default Rules

Blacklight comes with a comprehensive set of pre-configured rules for detecting various types of secrets and sensitive information:

Authentication & Authorization

Rule NameDescriptionSeverity
AWS Access KeyAmazon Web Services access key IDHigh
AWS Secret KeyAmazon Web Services secret access keyHigh
Generic API KeyGeneric API key patternsMedium
JWT TokenJSON Web TokenMedium
Basic AuthBasic Authentication credentialsHigh
OAuth Client SecretOAuth 2.0 client secretHigh
OAuth Access TokenOAuth 2.0 access tokenHigh
SSH Private KeySSH private key contentHigh

Cloud Services

Rule NameDescriptionSeverity
Azure Storage Account KeyAzure storage account access keyHigh
GCP Service AccountGoogle Cloud Platform service account keyHigh
Firebase Database URLFirebase realtime database URLMedium
Heroku API KeyHeroku platform API keyHigh
Digital Ocean TokenDigitalOcean API tokenHigh
Cloudflare API KeyCloudflare API key and tokenHigh
AWS Session TokenAWS temporary session tokenHigh

Payment & Financial

Rule NameDescriptionSeverity
Stripe API KeyStripe secret API keyHigh
Stripe Restricted KeyStripe restricted API keyHigh
PayPal Access TokenPayPal OAuth2 access tokenHigh
Square Access TokenSquare OAuth2 access tokenHigh
Credit Card NumberCredit card number patternsHigh

Database & Storage

Rule NameDescriptionSeverity
PostgreSQL ConnectionPostgreSQL connection stringHigh
MySQL ConnectionMySQL connection stringHigh
MongoDB ConnectionMongoDB connection URIHigh
Redis ConnectionRedis connection stringHigh
Elasticsearch ConnectionElasticsearch connection stringMedium

Communication & Messaging

Rule NameDescriptionSeverity
Slack TokenSlack API token and webhook URLHigh
Slack WebhookSlack incoming webhook URLMedium
Discord TokenDiscord bot tokenHigh
Discord WebhookDiscord webhook URLMedium
Twilio API KeyTwilio API keyHigh
SendGrid API KeySendGrid API keyHigh

Development & CI/CD

Rule NameDescriptionSeverity
GitHub TokenGitHub personal access tokenHigh
GitLab TokenGitLab personal access tokenHigh
NPM TokenNPM authentication tokenMedium
Docker RegistryDocker registry credentialsMedium
CircleCI TokenCircleCI API tokenHigh
Jenkins TokenJenkins API tokenHigh

AI & Machine Learning

Rule NameDescriptionSeverity
OpenAI API KeyOpenAI API keyHigh
Hugging Face TokenHugging Face API tokenHigh
Anthropic API KeyAnthropic API keyHigh
Cohere API KeyCohere API keyHigh
Replicate API TokenReplicate API tokenHigh

Analytics & Monitoring

Rule NameDescriptionSeverity
Google AnalyticsGoogle Analytics API keyMedium
New Relic KeyNew Relic license keyHigh
Datadog API KeyDatadog API keyHigh
Sentry DSNSentry client keyMedium
Mixpanel TokenMixpanel project tokenMedium

Generic Patterns

Rule NameDescriptionSeverity
Private KeyGeneric private key contentHigh
Password in URLPassword in URL parametersHigh
Environment VariableHardcoded environment variablesMedium
IP AddressPrivate IP addressesLow
Internal PathInternal system pathsLow

Custom Rules

You can add your own custom rules by creating a file at ~/.blacklight/rules.yaml:

- id: "custom_api_key"name: "Custom API Key"description: "Detects custom API key pattern"regex: "myapi_[a-zA-Z0-9]{32}"severity: 2type: "api"disabled: false
- id: "internal_token"name: "Internal Service Token"description: "Internal service authentication token"regex: "int_[a-zA-Z0-9]{24}"severity: 3type: "auth"disabled: false

Rule Properties

PropertyDescriptionRequiredExample
idUnique identifierYesaws_access_key
nameHuman-readable nameYes"AWS Access Key"
descriptionWhat the rule detectsNo"Amazon Web Services access key ID"
regexDetection patternYesAKIA[0-9A-Z]{16}
severity1 (low) to 3 (high)Yes3
typeCategory from types listYes"cloud"
disabledSkip this ruleNofalse

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

Copyright © 2025 Debarshi Basak

Licensed under the Apache License, Version 2.0

About

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Resources

Stars

12 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Blacklight

Screenshot 2025-05-31 at 02 16 47

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Features

  • Multi-Source Scanning

    • Local files and directories
    • Databases (PostgreSQL, MySQL)
    • AWS S3 buckets
    • Slack workspace messages and files
    • Cloud Storage (Google Drive, Dropbox)
    • Git repositories
  • Advanced Detection

    • Pattern-based secret detection
    • Context-aware scanning
    • Multi-language support
    • Configurable severity levels
    • Rule categorization
    • Smart file format detection
  • Supported File Formats

    • Plain text files
    • JSON files (with nested object support)
    • YAML files (with nested object support)
    • XML files (with attribute scanning)
    • INI/Config files
    • Environment files (.env)
    • Configuration files
  • User Experience

    • Cross-platform compatibility (Windows, Linux, macOS)
    • Beautiful table output with go-pretty formatting
    • Color-coded severity indicators
    • Detailed violation reporting
    • Rich context for findings

Installation

Quick Install (Linux/macOS)

# macOS (Apple Silicon)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# macOS (Intel)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (x86_64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (ARM64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Verify installation
blacklight version

Using Go

# Using go install
go install github.com/adaptive-scale/blacklight@latest
# Or clone and build
git clone https://github.com/adaptive-scale/blacklight.git
cd blacklight
make build

Docker

# Pull the latest image
docker pull adaptivescale/blacklight:latest
# Run a scan
docker run -v $(pwd):/workspace adaptivescale/blacklight:latest scan /workspace

Windows

Download the appropriate .exe file from our releases page and add it to your PATH.

Verifying the Installation

After installation, verify that Blacklight is working correctly:

# Check version
blacklight version
# View help
blacklight --help
# Run a test scan
blacklight scan --help

Usage

Basic Usage

# Scan a directory
blacklight scan /path/to/directory
# Scan with verbose output
blacklight scan /path/to/directory --verbose
# Scan a database
blacklight scan --db "postgresql://user:pass@localhost:5432/dbname"# Scan an S3 bucket
blacklight scan --s3 "s3://bucket-name"# Scan cloud storage
blacklight scan --drive "gdrive://folder-id"

Rule Management

# List all rules
blacklight rules list
# List rules by type
blacklight rules list --type cloud
# List rules by severity
blacklight rules list --severity 3
# Add a new rule
blacklight rules add --name "Custom API Key" \
--regex "api_key_[a-zA-Z0-9]{32}" \
--severity 2 \
--type "secret"

Slack Workspace Scanning

Blacklight includes a powerful Slack scanner that can detect secrets and sensitive information in:

  • Channel messages (public and private)
  • Message threads
  • Direct messages (DMs)
  • Group messages
  • Shared files
  • File comments

Setup

  1. Create a Slack App at https://api.slack.com/apps
  2. Add the following OAuth scopes:
    channels:history - View messages and other content in public channels
    channels:read - View basic information about public channels
    files:read - View files shared in channels and conversations
    groups:history - View messages and other content in private channels
    groups:read - View basic information about private channels
    im:history - View messages and other content in direct messages
    im:read - View basic information about direct messages
    mpim:history - View messages and other content in group direct messages
    mpim:read - View basic information about group direct messages
    
  3. Install the app to your workspace
  4. Copy the Bot User OAuth Token (starts with xoxb-)

Usage

# Basic scan of all accessible channels
blacklight slack --token xoxb-your-token
# Scan specific channels
blacklight slack --token xoxb-your-token --channels C01234567,C89012345
# Scan recent messages
blacklight slack --token xoxb-your-token --days 7
# Full scan including threads and files
blacklight slack --token xoxb-your-token --include-threads --include-files

Configuration Options

OptionDescriptionDefault
--tokenSlack Bot User OAuth Token (required)-
--channelsComma-separated list of channel IDsAll accessible
--daysNumber of days of history to scan30
--include-threadsScan message threadsfalse
--include-filesScan file contentsfalse
--exclude-archivedSkip archived channelstrue

Performance Considerations

  • File scanning is disabled by default to improve performance
  • Files larger than 10MB are skipped
  • Use the --days flag to limit the scan window
  • Specify channels to scan for faster results

Cloud Storage Scanning

Blacklight can scan files in various cloud storage services for secrets and sensitive information:

Implemented Providers

  • Google Drive (gdrive://)

    • Scans files in specified folders
    • Supports file content analysis
    • Respects file size limits
    • OAuth2 authentication
    • Automatic file format detection
    • Recursive folder scanning
  • Dropbox (dropbox://)

    • Full folder scanning
    • File content analysis
    • Path-based access
    • Access token authentication
    • Smart file format handling
    • Size-based file filtering

Coming Soon

  • OneDrive (onedrive://) - In development
  • Box (box://) - Planned

Authentication

Each provider requires appropriate authentication:

# Google Drive - OAuth2 client configurationexport CLOUD_TOKEN='{"client_id":"...","client_secret":"...","redirect_uris":["..."]}'# Dropbox - Access Tokenexport CLOUD_TOKEN="your-dropbox-access-token"

Usage Examples

# Scan Google Drive folder
blacklight scan --drive "gdrive://folder-id"# Scan Dropbox folder
blacklight scan --drive "dropbox://path/to/folder"# Include shared files (Google Drive)
blacklight scan --drive "gdrive://folder-id" --include-shared
# Limit scan history
blacklight scan --drive "dropbox://folder" --days 7
# Adjust file size limit
blacklight scan --drive "gdrive://folder-id" --max-size 5242880 # 5MB

Configuration Options

OptionDescriptionDefault
--drive, -rCloud storage URL to scan-
--include-sharedInclude shared filesfalse
--daysDays of history to scan30
--max-sizeMaximum file size (bytes)10MB

File Format Support

The cloud storage scanner automatically detects and processes various file formats:

FormatExtensionsDetection
JSON.jsonExtension + Content
YAML.yaml, .ymlExtension + Content
XML.xmlExtension
INI.ini, .conf, .configExtension
ENV.envExtension
TextothersDefault

Performance Considerations

  • Files larger than the max-size limit are skipped
  • Use --days to limit scan scope
  • Specify precise folder paths for faster scans
  • Token expiration is handled automatically
  • File format detection optimizes scanning

Security Notes

  • Tokens should be kept secure and not shared
  • Use read-only access tokens when possible
  • Consider using environment variables for token storage
  • Regularly rotate access tokens
  • Ensure proper access permissions

Rule Types

Blacklight organizes its scanning rules into the following categories:

Authentication & Authorization

  • auth: Authentication tokens, passwords, OAuth credentials
  • key: Cryptographic keys (RSA, DSA, PGP, SSH)

Cloud & Infrastructure

  • cloud: Cloud provider credentials (AWS, Azure, GCP)
  • container: Container platform secrets (Docker, Kubernetes)
  • iac: Infrastructure as Code secrets (Terraform)
  • cdn: Content Delivery Network tokens

APIs & Services

  • api: Generic and service-specific API keys
  • monitoring: Monitoring service tokens (NewRelic, Rollbar)
  • ci: CI/CD platform credentials
  • vcs: Version Control System tokens (GitHub, GitLab)

Payment & Financial

  • payment: Payment gateway credentials
  • pci: Payment Card Industry data
  • ecommerce: E-commerce platform tokens

Data & Storage

  • database: Database credentials and endpoints
  • messaging: Message queue credentials
  • package: Package registry tokens

Other

  • secret: Generic secrets and environment variables
  • social: Social media platform tokens
  • security: Security-related credentials
  • config: Configuration file secrets
  • ai: AI service credentials

Rule Configuration

Rules are stored in ~/.blacklight/rules.yaml. Each rule has the following properties:

PropertyDescriptionRequired
idUnique identifierYes
nameHuman-readable nameYes
descriptionWhat the rule detectsNo
regexDetection patternYes
severity1 (low) to 3 (high)Yes
typeCategory from aboveYes
disabledSkip this ruleNo

Example Rule File

- id: "aws_access_key"name: "AWS Access Key"description: "Amazon Web Services access key ID"regex: "AKIA[0-9A-Z]{16}"severity: 3type: "cloud"disabled: false
- id: "stripe_key"name: "Stripe API Key"description: "Stripe secret API key"regex: "sk_live_[0-9a-zA-Z]{24}"severity: 3type: "payment"disabled: false

Output Format

Blacklight provides rich, color-coded output:

[Severity 3]: AWS Access Key Found
Location: slack://channel/C0123456/message/1234567890.123
Context: ...config = { accessKeyId: "AKIAXXXXXXXXXXXXXXXX", region: "us-east-1" }...
Match: AKIAXXXXXXXXXXXXXXXX
--------------------------------------------------------------------------------

The table output uses go-pretty for enhanced readability:

╭──────────────────────────┬──────────┬──────────┬─────────┬───────────────────────────────────╮
│ NAME │ TYPE │ SEVERITY │ STATUS │ PATTERN │
├──────────────────────────┼──────────┼──────────┼─────────┼───────────────────────────────────┤
│ AWS Access Key │ cloud │ 3 │ Enabled │ AKIA[0-9A-Z]{16} │
│ Stripe API Key │ payment │ 3 │ Enabled │ sk_live_[0-9a-zA-Z]{24} │
╰──────────────────────────┴──────────┴──────────┴─────────┴───────────────────────────────────╯

Default Rules

Blacklight comes with a comprehensive set of pre-configured rules for detecting various types of secrets and sensitive information:

Authentication & Authorization

Rule NameDescriptionSeverity
AWS Access KeyAmazon Web Services access key IDHigh
AWS Secret KeyAmazon Web Services secret access keyHigh
Generic API KeyGeneric API key patternsMedium
JWT TokenJSON Web TokenMedium
Basic AuthBasic Authentication credentialsHigh
OAuth Client SecretOAuth 2.0 client secretHigh
OAuth Access TokenOAuth 2.0 access tokenHigh
SSH Private KeySSH private key contentHigh

Cloud Services

Rule NameDescriptionSeverity
Azure Storage Account KeyAzure storage account access keyHigh
GCP Service AccountGoogle Cloud Platform service account keyHigh
Firebase Database URLFirebase realtime database URLMedium
Heroku API KeyHeroku platform API keyHigh
Digital Ocean TokenDigitalOcean API tokenHigh
Cloudflare API KeyCloudflare API key and tokenHigh
AWS Session TokenAWS temporary session tokenHigh

Payment & Financial

Rule NameDescriptionSeverity
Stripe API KeyStripe secret API keyHigh
Stripe Restricted KeyStripe restricted API keyHigh
PayPal Access TokenPayPal OAuth2 access tokenHigh
Square Access TokenSquare OAuth2 access tokenHigh
Credit Card NumberCredit card number patternsHigh

Database & Storage

Rule NameDescriptionSeverity
PostgreSQL ConnectionPostgreSQL connection stringHigh
MySQL ConnectionMySQL connection stringHigh
MongoDB ConnectionMongoDB connection URIHigh
Redis ConnectionRedis connection stringHigh
Elasticsearch ConnectionElasticsearch connection stringMedium

Communication & Messaging

Rule NameDescriptionSeverity
Slack TokenSlack API token and webhook URLHigh
Slack WebhookSlack incoming webhook URLMedium
Discord TokenDiscord bot tokenHigh
Discord WebhookDiscord webhook URLMedium
Twilio API KeyTwilio API keyHigh
SendGrid API KeySendGrid API keyHigh

Development & CI/CD

Rule NameDescriptionSeverity
GitHub TokenGitHub personal access tokenHigh
GitLab TokenGitLab personal access tokenHigh
NPM TokenNPM authentication tokenMedium
Docker RegistryDocker registry credentialsMedium
CircleCI TokenCircleCI API tokenHigh
Jenkins TokenJenkins API tokenHigh

AI & Machine Learning

Rule NameDescriptionSeverity
OpenAI API KeyOpenAI API keyHigh
Hugging Face TokenHugging Face API tokenHigh
Anthropic API KeyAnthropic API keyHigh
Cohere API KeyCohere API keyHigh
Replicate API TokenReplicate API tokenHigh

Analytics & Monitoring

Rule NameDescriptionSeverity
Google AnalyticsGoogle Analytics API keyMedium
New Relic KeyNew Relic license keyHigh
Datadog API KeyDatadog API keyHigh
Sentry DSNSentry client keyMedium
Mixpanel TokenMixpanel project tokenMedium

Generic Patterns

Rule NameDescriptionSeverity
Private KeyGeneric private key contentHigh
Password in URLPassword in URL parametersHigh
Environment VariableHardcoded environment variablesMedium
IP AddressPrivate IP addressesLow
Internal PathInternal system pathsLow

Custom Rules

You can add your own custom rules by creating a file at ~/.blacklight/rules.yaml:

- id: "custom_api_key"name: "Custom API Key"description: "Detects custom API key pattern"regex: "myapi_[a-zA-Z0-9]{32}"severity: 2type: "api"disabled: false
- id: "internal_token"name: "Internal Service Token"description: "Internal service authentication token"regex: "int_[a-zA-Z0-9]{24}"severity: 3type: "auth"disabled: false

Rule Properties

PropertyDescriptionRequiredExample
idUnique identifierYesaws_access_key
nameHuman-readable nameYes"AWS Access Key"
descriptionWhat the rule detectsNo"Amazon Web Services access key ID"
regexDetection patternYesAKIA[0-9A-Z]{16}
severity1 (low) to 3 (high)Yes3
typeCategory from types listYes"cloud"
disabledSkip this ruleNofalse

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

Copyright © 2025 Debarshi Basak

Licensed under the Apache License, Version 2.0

About

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Resources

Stars

12 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Blacklight

Screenshot 2025-05-31 at 02 16 47

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Features

  • Multi-Source Scanning

    • Local files and directories
    • Databases (PostgreSQL, MySQL)
    • AWS S3 buckets
    • Slack workspace messages and files
    • Cloud Storage (Google Drive, Dropbox)
    • Git repositories
  • Advanced Detection

    • Pattern-based secret detection
    • Context-aware scanning
    • Multi-language support
    • Configurable severity levels
    • Rule categorization
    • Smart file format detection
  • Supported File Formats

    • Plain text files
    • JSON files (with nested object support)
    • YAML files (with nested object support)
    • XML files (with attribute scanning)
    • INI/Config files
    • Environment files (.env)
    • Configuration files
  • User Experience

    • Cross-platform compatibility (Windows, Linux, macOS)
    • Beautiful table output with go-pretty formatting
    • Color-coded severity indicators
    • Detailed violation reporting
    • Rich context for findings

Installation

Quick Install (Linux/macOS)

# macOS (Apple Silicon)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# macOS (Intel)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (x86_64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (ARM64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Verify installation
blacklight version

Using Go

# Using go install
go install github.com/adaptive-scale/blacklight@latest
# Or clone and build
git clone https://github.com/adaptive-scale/blacklight.git
cd blacklight
make build

Docker

# Pull the latest image
docker pull adaptivescale/blacklight:latest
# Run a scan
docker run -v $(pwd):/workspace adaptivescale/blacklight:latest scan /workspace

Windows

Download the appropriate .exe file from our releases page and add it to your PATH.

Verifying the Installation

After installation, verify that Blacklight is working correctly:

# Check version
blacklight version
# View help
blacklight --help
# Run a test scan
blacklight scan --help

Usage

Basic Usage

# Scan a directory
blacklight scan /path/to/directory
# Scan with verbose output
blacklight scan /path/to/directory --verbose
# Scan a database
blacklight scan --db "postgresql://user:pass@localhost:5432/dbname"# Scan an S3 bucket
blacklight scan --s3 "s3://bucket-name"# Scan cloud storage
blacklight scan --drive "gdrive://folder-id"

Rule Management

# List all rules
blacklight rules list
# List rules by type
blacklight rules list --type cloud
# List rules by severity
blacklight rules list --severity 3
# Add a new rule
blacklight rules add --name "Custom API Key" \
--regex "api_key_[a-zA-Z0-9]{32}" \
--severity 2 \
--type "secret"

Slack Workspace Scanning

Blacklight includes a powerful Slack scanner that can detect secrets and sensitive information in:

  • Channel messages (public and private)
  • Message threads
  • Direct messages (DMs)
  • Group messages
  • Shared files
  • File comments

Setup

  1. Create a Slack App at https://api.slack.com/apps
  2. Add the following OAuth scopes:
    channels:history - View messages and other content in public channels
    channels:read - View basic information about public channels
    files:read - View files shared in channels and conversations
    groups:history - View messages and other content in private channels
    groups:read - View basic information about private channels
    im:history - View messages and other content in direct messages
    im:read - View basic information about direct messages
    mpim:history - View messages and other content in group direct messages
    mpim:read - View basic information about group direct messages
    
  3. Install the app to your workspace
  4. Copy the Bot User OAuth Token (starts with xoxb-)

Usage

# Basic scan of all accessible channels
blacklight slack --token xoxb-your-token
# Scan specific channels
blacklight slack --token xoxb-your-token --channels C01234567,C89012345
# Scan recent messages
blacklight slack --token xoxb-your-token --days 7
# Full scan including threads and files
blacklight slack --token xoxb-your-token --include-threads --include-files

Configuration Options

OptionDescriptionDefault
--tokenSlack Bot User OAuth Token (required)-
--channelsComma-separated list of channel IDsAll accessible
--daysNumber of days of history to scan30
--include-threadsScan message threadsfalse
--include-filesScan file contentsfalse
--exclude-archivedSkip archived channelstrue

Performance Considerations

  • File scanning is disabled by default to improve performance
  • Files larger than 10MB are skipped
  • Use the --days flag to limit the scan window
  • Specify channels to scan for faster results

Cloud Storage Scanning

Blacklight can scan files in various cloud storage services for secrets and sensitive information:

Implemented Providers

  • Google Drive (gdrive://)

    • Scans files in specified folders
    • Supports file content analysis
    • Respects file size limits
    • OAuth2 authentication
    • Automatic file format detection
    • Recursive folder scanning
  • Dropbox (dropbox://)

    • Full folder scanning
    • File content analysis
    • Path-based access
    • Access token authentication
    • Smart file format handling
    • Size-based file filtering

Coming Soon

  • OneDrive (onedrive://) - In development
  • Box (box://) - Planned

Authentication

Each provider requires appropriate authentication:

# Google Drive - OAuth2 client configurationexport CLOUD_TOKEN='{"client_id":"...","client_secret":"...","redirect_uris":["..."]}'# Dropbox - Access Tokenexport CLOUD_TOKEN="your-dropbox-access-token"

Usage Examples

# Scan Google Drive folder
blacklight scan --drive "gdrive://folder-id"# Scan Dropbox folder
blacklight scan --drive "dropbox://path/to/folder"# Include shared files (Google Drive)
blacklight scan --drive "gdrive://folder-id" --include-shared
# Limit scan history
blacklight scan --drive "dropbox://folder" --days 7
# Adjust file size limit
blacklight scan --drive "gdrive://folder-id" --max-size 5242880 # 5MB

Configuration Options

OptionDescriptionDefault
--drive, -rCloud storage URL to scan-
--include-sharedInclude shared filesfalse
--daysDays of history to scan30
--max-sizeMaximum file size (bytes)10MB

File Format Support

The cloud storage scanner automatically detects and processes various file formats:

FormatExtensionsDetection
JSON.jsonExtension + Content
YAML.yaml, .ymlExtension + Content
XML.xmlExtension
INI.ini, .conf, .configExtension
ENV.envExtension
TextothersDefault

Performance Considerations

  • Files larger than the max-size limit are skipped
  • Use --days to limit scan scope
  • Specify precise folder paths for faster scans
  • Token expiration is handled automatically
  • File format detection optimizes scanning

Security Notes

  • Tokens should be kept secure and not shared
  • Use read-only access tokens when possible
  • Consider using environment variables for token storage
  • Regularly rotate access tokens
  • Ensure proper access permissions

Rule Types

Blacklight organizes its scanning rules into the following categories:

Authentication & Authorization

  • auth: Authentication tokens, passwords, OAuth credentials
  • key: Cryptographic keys (RSA, DSA, PGP, SSH)

Cloud & Infrastructure

  • cloud: Cloud provider credentials (AWS, Azure, GCP)
  • container: Container platform secrets (Docker, Kubernetes)
  • iac: Infrastructure as Code secrets (Terraform)
  • cdn: Content Delivery Network tokens

APIs & Services

  • api: Generic and service-specific API keys
  • monitoring: Monitoring service tokens (NewRelic, Rollbar)
  • ci: CI/CD platform credentials
  • vcs: Version Control System tokens (GitHub, GitLab)

Payment & Financial

  • payment: Payment gateway credentials
  • pci: Payment Card Industry data
  • ecommerce: E-commerce platform tokens

Data & Storage

  • database: Database credentials and endpoints
  • messaging: Message queue credentials
  • package: Package registry tokens

Other

  • secret: Generic secrets and environment variables
  • social: Social media platform tokens
  • security: Security-related credentials
  • config: Configuration file secrets
  • ai: AI service credentials

Rule Configuration

Rules are stored in ~/.blacklight/rules.yaml. Each rule has the following properties:

PropertyDescriptionRequired
idUnique identifierYes
nameHuman-readable nameYes
descriptionWhat the rule detectsNo
regexDetection patternYes
severity1 (low) to 3 (high)Yes
typeCategory from aboveYes
disabledSkip this ruleNo

Example Rule File

- id: "aws_access_key"name: "AWS Access Key"description: "Amazon Web Services access key ID"regex: "AKIA[0-9A-Z]{16}"severity: 3type: "cloud"disabled: false
- id: "stripe_key"name: "Stripe API Key"description: "Stripe secret API key"regex: "sk_live_[0-9a-zA-Z]{24}"severity: 3type: "payment"disabled: false

Output Format

Blacklight provides rich, color-coded output:

[Severity 3]: AWS Access Key Found
Location: slack://channel/C0123456/message/1234567890.123
Context: ...config = { accessKeyId: "AKIAXXXXXXXXXXXXXXXX", region: "us-east-1" }...
Match: AKIAXXXXXXXXXXXXXXXX
--------------------------------------------------------------------------------

The table output uses go-pretty for enhanced readability:

╭──────────────────────────┬──────────┬──────────┬─────────┬───────────────────────────────────╮
│ NAME │ TYPE │ SEVERITY │ STATUS │ PATTERN │
├──────────────────────────┼──────────┼──────────┼─────────┼───────────────────────────────────┤
│ AWS Access Key │ cloud │ 3 │ Enabled │ AKIA[0-9A-Z]{16} │
│ Stripe API Key │ payment │ 3 │ Enabled │ sk_live_[0-9a-zA-Z]{24} │
╰──────────────────────────┴──────────┴──────────┴─────────┴───────────────────────────────────╯

Default Rules

Blacklight comes with a comprehensive set of pre-configured rules for detecting various types of secrets and sensitive information:

Authentication & Authorization

Rule NameDescriptionSeverity
AWS Access KeyAmazon Web Services access key IDHigh
AWS Secret KeyAmazon Web Services secret access keyHigh
Generic API KeyGeneric API key patternsMedium
JWT TokenJSON Web TokenMedium
Basic AuthBasic Authentication credentialsHigh
OAuth Client SecretOAuth 2.0 client secretHigh
OAuth Access TokenOAuth 2.0 access tokenHigh
SSH Private KeySSH private key contentHigh

Cloud Services

Rule NameDescriptionSeverity
Azure Storage Account KeyAzure storage account access keyHigh
GCP Service AccountGoogle Cloud Platform service account keyHigh
Firebase Database URLFirebase realtime database URLMedium
Heroku API KeyHeroku platform API keyHigh
Digital Ocean TokenDigitalOcean API tokenHigh
Cloudflare API KeyCloudflare API key and tokenHigh
AWS Session TokenAWS temporary session tokenHigh

Payment & Financial

Rule NameDescriptionSeverity
Stripe API KeyStripe secret API keyHigh
Stripe Restricted KeyStripe restricted API keyHigh
PayPal Access TokenPayPal OAuth2 access tokenHigh
Square Access TokenSquare OAuth2 access tokenHigh
Credit Card NumberCredit card number patternsHigh

Database & Storage

Rule NameDescriptionSeverity
PostgreSQL ConnectionPostgreSQL connection stringHigh
MySQL ConnectionMySQL connection stringHigh
MongoDB ConnectionMongoDB connection URIHigh
Redis ConnectionRedis connection stringHigh
Elasticsearch ConnectionElasticsearch connection stringMedium

Communication & Messaging

Rule NameDescriptionSeverity
Slack TokenSlack API token and webhook URLHigh
Slack WebhookSlack incoming webhook URLMedium
Discord TokenDiscord bot tokenHigh
Discord WebhookDiscord webhook URLMedium
Twilio API KeyTwilio API keyHigh
SendGrid API KeySendGrid API keyHigh

Development & CI/CD

Rule NameDescriptionSeverity
GitHub TokenGitHub personal access tokenHigh
GitLab TokenGitLab personal access tokenHigh
NPM TokenNPM authentication tokenMedium
Docker RegistryDocker registry credentialsMedium
CircleCI TokenCircleCI API tokenHigh
Jenkins TokenJenkins API tokenHigh

AI & Machine Learning

Rule NameDescriptionSeverity
OpenAI API KeyOpenAI API keyHigh
Hugging Face TokenHugging Face API tokenHigh
Anthropic API KeyAnthropic API keyHigh
Cohere API KeyCohere API keyHigh
Replicate API TokenReplicate API tokenHigh

Analytics & Monitoring

Rule NameDescriptionSeverity
Google AnalyticsGoogle Analytics API keyMedium
New Relic KeyNew Relic license keyHigh
Datadog API KeyDatadog API keyHigh
Sentry DSNSentry client keyMedium
Mixpanel TokenMixpanel project tokenMedium

Generic Patterns

Rule NameDescriptionSeverity
Private KeyGeneric private key contentHigh
Password in URLPassword in URL parametersHigh
Environment VariableHardcoded environment variablesMedium
IP AddressPrivate IP addressesLow
Internal PathInternal system pathsLow

Custom Rules

You can add your own custom rules by creating a file at ~/.blacklight/rules.yaml:

- id: "custom_api_key"name: "Custom API Key"description: "Detects custom API key pattern"regex: "myapi_[a-zA-Z0-9]{32}"severity: 2type: "api"disabled: false
- id: "internal_token"name: "Internal Service Token"description: "Internal service authentication token"regex: "int_[a-zA-Z0-9]{24}"severity: 3type: "auth"disabled: false

Rule Properties

PropertyDescriptionRequiredExample
idUnique identifierYesaws_access_key
nameHuman-readable nameYes"AWS Access Key"
descriptionWhat the rule detectsNo"Amazon Web Services access key ID"
regexDetection patternYesAKIA[0-9A-Z]{16}
severity1 (low) to 3 (high)Yes3
typeCategory from types listYes"cloud"
disabledSkip this ruleNofalse

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

Copyright © 2025 Debarshi Basak

Licensed under the Apache License, Version 2.0

About

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Resources

Stars

12 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Blacklight

Screenshot 2025-05-31 at 02 16 47

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Features

  • Multi-Source Scanning

    • Local files and directories
    • Databases (PostgreSQL, MySQL)
    • AWS S3 buckets
    • Slack workspace messages and files
    • Cloud Storage (Google Drive, Dropbox)
    • Git repositories
  • Advanced Detection

    • Pattern-based secret detection
    • Context-aware scanning
    • Multi-language support
    • Configurable severity levels
    • Rule categorization
    • Smart file format detection
  • Supported File Formats

    • Plain text files
    • JSON files (with nested object support)
    • YAML files (with nested object support)
    • XML files (with attribute scanning)
    • INI/Config files
    • Environment files (.env)
    • Configuration files
  • User Experience

    • Cross-platform compatibility (Windows, Linux, macOS)
    • Beautiful table output with go-pretty formatting
    • Color-coded severity indicators
    • Detailed violation reporting
    • Rich context for findings

Installation

Quick Install (Linux/macOS)

# macOS (Apple Silicon)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# macOS (Intel)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (x86_64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (ARM64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Verify installation
blacklight version

Using Go

# Using go install
go install github.com/adaptive-scale/blacklight@latest
# Or clone and build
git clone https://github.com/adaptive-scale/blacklight.git
cd blacklight
make build

Docker

# Pull the latest image
docker pull adaptivescale/blacklight:latest
# Run a scan
docker run -v $(pwd):/workspace adaptivescale/blacklight:latest scan /workspace

Windows

Download the appropriate .exe file from our releases page and add it to your PATH.

Verifying the Installation

After installation, verify that Blacklight is working correctly:

# Check version
blacklight version
# View help
blacklight --help
# Run a test scan
blacklight scan --help

Usage

Basic Usage

# Scan a directory
blacklight scan /path/to/directory
# Scan with verbose output
blacklight scan /path/to/directory --verbose
# Scan a database
blacklight scan --db "postgresql://user:pass@localhost:5432/dbname"# Scan an S3 bucket
blacklight scan --s3 "s3://bucket-name"# Scan cloud storage
blacklight scan --drive "gdrive://folder-id"

Rule Management

# List all rules
blacklight rules list
# List rules by type
blacklight rules list --type cloud
# List rules by severity
blacklight rules list --severity 3
# Add a new rule
blacklight rules add --name "Custom API Key" \
--regex "api_key_[a-zA-Z0-9]{32}" \
--severity 2 \
--type "secret"

Slack Workspace Scanning

Blacklight includes a powerful Slack scanner that can detect secrets and sensitive information in:

  • Channel messages (public and private)
  • Message threads
  • Direct messages (DMs)
  • Group messages
  • Shared files
  • File comments

Setup

  1. Create a Slack App at https://api.slack.com/apps
  2. Add the following OAuth scopes:
    channels:history - View messages and other content in public channels
    channels:read - View basic information about public channels
    files:read - View files shared in channels and conversations
    groups:history - View messages and other content in private channels
    groups:read - View basic information about private channels
    im:history - View messages and other content in direct messages
    im:read - View basic information about direct messages
    mpim:history - View messages and other content in group direct messages
    mpim:read - View basic information about group direct messages
    
  3. Install the app to your workspace
  4. Copy the Bot User OAuth Token (starts with xoxb-)

Usage

# Basic scan of all accessible channels
blacklight slack --token xoxb-your-token
# Scan specific channels
blacklight slack --token xoxb-your-token --channels C01234567,C89012345
# Scan recent messages
blacklight slack --token xoxb-your-token --days 7
# Full scan including threads and files
blacklight slack --token xoxb-your-token --include-threads --include-files

Configuration Options

OptionDescriptionDefault
--tokenSlack Bot User OAuth Token (required)-
--channelsComma-separated list of channel IDsAll accessible
--daysNumber of days of history to scan30
--include-threadsScan message threadsfalse
--include-filesScan file contentsfalse
--exclude-archivedSkip archived channelstrue

Performance Considerations

  • File scanning is disabled by default to improve performance
  • Files larger than 10MB are skipped
  • Use the --days flag to limit the scan window
  • Specify channels to scan for faster results

Cloud Storage Scanning

Blacklight can scan files in various cloud storage services for secrets and sensitive information:

Implemented Providers

  • Google Drive (gdrive://)

    • Scans files in specified folders
    • Supports file content analysis
    • Respects file size limits
    • OAuth2 authentication
    • Automatic file format detection
    • Recursive folder scanning
  • Dropbox (dropbox://)

    • Full folder scanning
    • File content analysis
    • Path-based access
    • Access token authentication
    • Smart file format handling
    • Size-based file filtering

Coming Soon

  • OneDrive (onedrive://) - In development
  • Box (box://) - Planned

Authentication

Each provider requires appropriate authentication:

# Google Drive - OAuth2 client configurationexport CLOUD_TOKEN='{"client_id":"...","client_secret":"...","redirect_uris":["..."]}'# Dropbox - Access Tokenexport CLOUD_TOKEN="your-dropbox-access-token"

Usage Examples

# Scan Google Drive folder
blacklight scan --drive "gdrive://folder-id"# Scan Dropbox folder
blacklight scan --drive "dropbox://path/to/folder"# Include shared files (Google Drive)
blacklight scan --drive "gdrive://folder-id" --include-shared
# Limit scan history
blacklight scan --drive "dropbox://folder" --days 7
# Adjust file size limit
blacklight scan --drive "gdrive://folder-id" --max-size 5242880 # 5MB

Configuration Options

OptionDescriptionDefault
--drive, -rCloud storage URL to scan-
--include-sharedInclude shared filesfalse
--daysDays of history to scan30
--max-sizeMaximum file size (bytes)10MB

File Format Support

The cloud storage scanner automatically detects and processes various file formats:

FormatExtensionsDetection
JSON.jsonExtension + Content
YAML.yaml, .ymlExtension + Content
XML.xmlExtension
INI.ini, .conf, .configExtension
ENV.envExtension
TextothersDefault

Performance Considerations

  • Files larger than the max-size limit are skipped
  • Use --days to limit scan scope
  • Specify precise folder paths for faster scans
  • Token expiration is handled automatically
  • File format detection optimizes scanning

Security Notes

  • Tokens should be kept secure and not shared
  • Use read-only access tokens when possible
  • Consider using environment variables for token storage
  • Regularly rotate access tokens
  • Ensure proper access permissions

Rule Types

Blacklight organizes its scanning rules into the following categories:

Authentication & Authorization

  • auth: Authentication tokens, passwords, OAuth credentials
  • key: Cryptographic keys (RSA, DSA, PGP, SSH)

Cloud & Infrastructure

  • cloud: Cloud provider credentials (AWS, Azure, GCP)
  • container: Container platform secrets (Docker, Kubernetes)
  • iac: Infrastructure as Code secrets (Terraform)
  • cdn: Content Delivery Network tokens

APIs & Services

  • api: Generic and service-specific API keys
  • monitoring: Monitoring service tokens (NewRelic, Rollbar)
  • ci: CI/CD platform credentials
  • vcs: Version Control System tokens (GitHub, GitLab)

Payment & Financial

  • payment: Payment gateway credentials
  • pci: Payment Card Industry data
  • ecommerce: E-commerce platform tokens

Data & Storage

  • database: Database credentials and endpoints
  • messaging: Message queue credentials
  • package: Package registry tokens

Other

  • secret: Generic secrets and environment variables
  • social: Social media platform tokens
  • security: Security-related credentials
  • config: Configuration file secrets
  • ai: AI service credentials

Rule Configuration

Rules are stored in ~/.blacklight/rules.yaml. Each rule has the following properties:

PropertyDescriptionRequired
idUnique identifierYes
nameHuman-readable nameYes
descriptionWhat the rule detectsNo
regexDetection patternYes
severity1 (low) to 3 (high)Yes
typeCategory from aboveYes
disabledSkip this ruleNo

Example Rule File

- id: "aws_access_key"name: "AWS Access Key"description: "Amazon Web Services access key ID"regex: "AKIA[0-9A-Z]{16}"severity: 3type: "cloud"disabled: false
- id: "stripe_key"name: "Stripe API Key"description: "Stripe secret API key"regex: "sk_live_[0-9a-zA-Z]{24}"severity: 3type: "payment"disabled: false

Output Format

Blacklight provides rich, color-coded output:

[Severity 3]: AWS Access Key Found
Location: slack://channel/C0123456/message/1234567890.123
Context: ...config = { accessKeyId: "AKIAXXXXXXXXXXXXXXXX", region: "us-east-1" }...
Match: AKIAXXXXXXXXXXXXXXXX
--------------------------------------------------------------------------------

The table output uses go-pretty for enhanced readability:

╭──────────────────────────┬──────────┬──────────┬─────────┬───────────────────────────────────╮
│ NAME │ TYPE │ SEVERITY │ STATUS │ PATTERN │
├──────────────────────────┼──────────┼──────────┼─────────┼───────────────────────────────────┤
│ AWS Access Key │ cloud │ 3 │ Enabled │ AKIA[0-9A-Z]{16} │
│ Stripe API Key │ payment │ 3 │ Enabled │ sk_live_[0-9a-zA-Z]{24} │
╰──────────────────────────┴──────────┴──────────┴─────────┴───────────────────────────────────╯

Default Rules

Blacklight comes with a comprehensive set of pre-configured rules for detecting various types of secrets and sensitive information:

Authentication & Authorization

Rule NameDescriptionSeverity
AWS Access KeyAmazon Web Services access key IDHigh
AWS Secret KeyAmazon Web Services secret access keyHigh
Generic API KeyGeneric API key patternsMedium
JWT TokenJSON Web TokenMedium
Basic AuthBasic Authentication credentialsHigh
OAuth Client SecretOAuth 2.0 client secretHigh
OAuth Access TokenOAuth 2.0 access tokenHigh
SSH Private KeySSH private key contentHigh

Cloud Services

Rule NameDescriptionSeverity
Azure Storage Account KeyAzure storage account access keyHigh
GCP Service AccountGoogle Cloud Platform service account keyHigh
Firebase Database URLFirebase realtime database URLMedium
Heroku API KeyHeroku platform API keyHigh
Digital Ocean TokenDigitalOcean API tokenHigh
Cloudflare API KeyCloudflare API key and tokenHigh
AWS Session TokenAWS temporary session tokenHigh

Payment & Financial

Rule NameDescriptionSeverity
Stripe API KeyStripe secret API keyHigh
Stripe Restricted KeyStripe restricted API keyHigh
PayPal Access TokenPayPal OAuth2 access tokenHigh
Square Access TokenSquare OAuth2 access tokenHigh
Credit Card NumberCredit card number patternsHigh

Database & Storage

Rule NameDescriptionSeverity
PostgreSQL ConnectionPostgreSQL connection stringHigh
MySQL ConnectionMySQL connection stringHigh
MongoDB ConnectionMongoDB connection URIHigh
Redis ConnectionRedis connection stringHigh
Elasticsearch ConnectionElasticsearch connection stringMedium

Communication & Messaging

Rule NameDescriptionSeverity
Slack TokenSlack API token and webhook URLHigh
Slack WebhookSlack incoming webhook URLMedium
Discord TokenDiscord bot tokenHigh
Discord WebhookDiscord webhook URLMedium
Twilio API KeyTwilio API keyHigh
SendGrid API KeySendGrid API keyHigh

Development & CI/CD

Rule NameDescriptionSeverity
GitHub TokenGitHub personal access tokenHigh
GitLab TokenGitLab personal access tokenHigh
NPM TokenNPM authentication tokenMedium
Docker RegistryDocker registry credentialsMedium
CircleCI TokenCircleCI API tokenHigh
Jenkins TokenJenkins API tokenHigh

AI & Machine Learning

Rule NameDescriptionSeverity
OpenAI API KeyOpenAI API keyHigh
Hugging Face TokenHugging Face API tokenHigh
Anthropic API KeyAnthropic API keyHigh
Cohere API KeyCohere API keyHigh
Replicate API TokenReplicate API tokenHigh

Analytics & Monitoring

Rule NameDescriptionSeverity
Google AnalyticsGoogle Analytics API keyMedium
New Relic KeyNew Relic license keyHigh
Datadog API KeyDatadog API keyHigh
Sentry DSNSentry client keyMedium
Mixpanel TokenMixpanel project tokenMedium

Generic Patterns

Rule NameDescriptionSeverity
Private KeyGeneric private key contentHigh
Password in URLPassword in URL parametersHigh
Environment VariableHardcoded environment variablesMedium
IP AddressPrivate IP addressesLow
Internal PathInternal system pathsLow

Custom Rules

You can add your own custom rules by creating a file at ~/.blacklight/rules.yaml:

- id: "custom_api_key"name: "Custom API Key"description: "Detects custom API key pattern"regex: "myapi_[a-zA-Z0-9]{32}"severity: 2type: "api"disabled: false
- id: "internal_token"name: "Internal Service Token"description: "Internal service authentication token"regex: "int_[a-zA-Z0-9]{24}"severity: 3type: "auth"disabled: false

Rule Properties

PropertyDescriptionRequiredExample
idUnique identifierYesaws_access_key
nameHuman-readable nameYes"AWS Access Key"
descriptionWhat the rule detectsNo"Amazon Web Services access key ID"
regexDetection patternYesAKIA[0-9A-Z]{16}
severity1 (low) to 3 (high)Yes3
typeCategory from types listYes"cloud"
disabledSkip this ruleNofalse

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

Copyright © 2025 Debarshi Basak

Licensed under the Apache License, Version 2.0

About

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Resources

Stars

12 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Blacklight

Screenshot 2025-05-31 at 02 16 47

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Features

  • Multi-Source Scanning

    • Local files and directories
    • Databases (PostgreSQL, MySQL)
    • AWS S3 buckets
    • Slack workspace messages and files
    • Cloud Storage (Google Drive, Dropbox)
    • Git repositories
  • Advanced Detection

    • Pattern-based secret detection
    • Context-aware scanning
    • Multi-language support
    • Configurable severity levels
    • Rule categorization
    • Smart file format detection
  • Supported File Formats

    • Plain text files
    • JSON files (with nested object support)
    • YAML files (with nested object support)
    • XML files (with attribute scanning)
    • INI/Config files
    • Environment files (.env)
    • Configuration files
  • User Experience

    • Cross-platform compatibility (Windows, Linux, macOS)
    • Beautiful table output with go-pretty formatting
    • Color-coded severity indicators
    • Detailed violation reporting
    • Rich context for findings

Installation

Quick Install (Linux/macOS)

# macOS (Apple Silicon)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# macOS (Intel)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-darwin-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (x86_64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-amd64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Linux (ARM64)
curl -Lo blacklight https://github.com/adaptive-scale/blacklight/releases/latest/download/blacklight-linux-arm64 && \
chmod +x blacklight && \
sudo mv blacklight /usr/local/bin/
# Verify installation
blacklight version

Using Go

# Using go install
go install github.com/adaptive-scale/blacklight@latest
# Or clone and build
git clone https://github.com/adaptive-scale/blacklight.git
cd blacklight
make build

Docker

# Pull the latest image
docker pull adaptivescale/blacklight:latest
# Run a scan
docker run -v $(pwd):/workspace adaptivescale/blacklight:latest scan /workspace

Windows

Download the appropriate .exe file from our releases page and add it to your PATH.

Verifying the Installation

After installation, verify that Blacklight is working correctly:

# Check version
blacklight version
# View help
blacklight --help
# Run a test scan
blacklight scan --help

Usage

Basic Usage

# Scan a directory
blacklight scan /path/to/directory
# Scan with verbose output
blacklight scan /path/to/directory --verbose
# Scan a database
blacklight scan --db "postgresql://user:pass@localhost:5432/dbname"# Scan an S3 bucket
blacklight scan --s3 "s3://bucket-name"# Scan cloud storage
blacklight scan --drive "gdrive://folder-id"

Rule Management

# List all rules
blacklight rules list
# List rules by type
blacklight rules list --type cloud
# List rules by severity
blacklight rules list --severity 3
# Add a new rule
blacklight rules add --name "Custom API Key" \
--regex "api_key_[a-zA-Z0-9]{32}" \
--severity 2 \
--type "secret"

Slack Workspace Scanning

Blacklight includes a powerful Slack scanner that can detect secrets and sensitive information in:

  • Channel messages (public and private)
  • Message threads
  • Direct messages (DMs)
  • Group messages
  • Shared files
  • File comments

Setup

  1. Create a Slack App at https://api.slack.com/apps
  2. Add the following OAuth scopes:
    channels:history - View messages and other content in public channels
    channels:read - View basic information about public channels
    files:read - View files shared in channels and conversations
    groups:history - View messages and other content in private channels
    groups:read - View basic information about private channels
    im:history - View messages and other content in direct messages
    im:read - View basic information about direct messages
    mpim:history - View messages and other content in group direct messages
    mpim:read - View basic information about group direct messages
    
  3. Install the app to your workspace
  4. Copy the Bot User OAuth Token (starts with xoxb-)

Usage

# Basic scan of all accessible channels
blacklight slack --token xoxb-your-token
# Scan specific channels
blacklight slack --token xoxb-your-token --channels C01234567,C89012345
# Scan recent messages
blacklight slack --token xoxb-your-token --days 7
# Full scan including threads and files
blacklight slack --token xoxb-your-token --include-threads --include-files

Configuration Options

OptionDescriptionDefault
--tokenSlack Bot User OAuth Token (required)-
--channelsComma-separated list of channel IDsAll accessible
--daysNumber of days of history to scan30
--include-threadsScan message threadsfalse
--include-filesScan file contentsfalse
--exclude-archivedSkip archived channelstrue

Performance Considerations

  • File scanning is disabled by default to improve performance
  • Files larger than 10MB are skipped
  • Use the --days flag to limit the scan window
  • Specify channels to scan for faster results

Cloud Storage Scanning

Blacklight can scan files in various cloud storage services for secrets and sensitive information:

Implemented Providers

  • Google Drive (gdrive://)

    • Scans files in specified folders
    • Supports file content analysis
    • Respects file size limits
    • OAuth2 authentication
    • Automatic file format detection
    • Recursive folder scanning
  • Dropbox (dropbox://)

    • Full folder scanning
    • File content analysis
    • Path-based access
    • Access token authentication
    • Smart file format handling
    • Size-based file filtering

Coming Soon

  • OneDrive (onedrive://) - In development
  • Box (box://) - Planned

Authentication

Each provider requires appropriate authentication:

# Google Drive - OAuth2 client configurationexport CLOUD_TOKEN='{"client_id":"...","client_secret":"...","redirect_uris":["..."]}'# Dropbox - Access Tokenexport CLOUD_TOKEN="your-dropbox-access-token"

Usage Examples

# Scan Google Drive folder
blacklight scan --drive "gdrive://folder-id"# Scan Dropbox folder
blacklight scan --drive "dropbox://path/to/folder"# Include shared files (Google Drive)
blacklight scan --drive "gdrive://folder-id" --include-shared
# Limit scan history
blacklight scan --drive "dropbox://folder" --days 7
# Adjust file size limit
blacklight scan --drive "gdrive://folder-id" --max-size 5242880 # 5MB

Configuration Options

OptionDescriptionDefault
--drive, -rCloud storage URL to scan-
--include-sharedInclude shared filesfalse
--daysDays of history to scan30
--max-sizeMaximum file size (bytes)10MB

File Format Support

The cloud storage scanner automatically detects and processes various file formats:

FormatExtensionsDetection
JSON.jsonExtension + Content
YAML.yaml, .ymlExtension + Content
XML.xmlExtension
INI.ini, .conf, .configExtension
ENV.envExtension
TextothersDefault

Performance Considerations

  • Files larger than the max-size limit are skipped
  • Use --days to limit scan scope
  • Specify precise folder paths for faster scans
  • Token expiration is handled automatically
  • File format detection optimizes scanning

Security Notes

  • Tokens should be kept secure and not shared
  • Use read-only access tokens when possible
  • Consider using environment variables for token storage
  • Regularly rotate access tokens
  • Ensure proper access permissions

Rule Types

Blacklight organizes its scanning rules into the following categories:

Authentication & Authorization

  • auth: Authentication tokens, passwords, OAuth credentials
  • key: Cryptographic keys (RSA, DSA, PGP, SSH)

Cloud & Infrastructure

  • cloud: Cloud provider credentials (AWS, Azure, GCP)
  • container: Container platform secrets (Docker, Kubernetes)
  • iac: Infrastructure as Code secrets (Terraform)
  • cdn: Content Delivery Network tokens

APIs & Services

  • api: Generic and service-specific API keys
  • monitoring: Monitoring service tokens (NewRelic, Rollbar)
  • ci: CI/CD platform credentials
  • vcs: Version Control System tokens (GitHub, GitLab)

Payment & Financial

  • payment: Payment gateway credentials
  • pci: Payment Card Industry data
  • ecommerce: E-commerce platform tokens

Data & Storage

  • database: Database credentials and endpoints
  • messaging: Message queue credentials
  • package: Package registry tokens

Other

  • secret: Generic secrets and environment variables
  • social: Social media platform tokens
  • security: Security-related credentials
  • config: Configuration file secrets
  • ai: AI service credentials

Rule Configuration

Rules are stored in ~/.blacklight/rules.yaml. Each rule has the following properties:

PropertyDescriptionRequired
idUnique identifierYes
nameHuman-readable nameYes
descriptionWhat the rule detectsNo
regexDetection patternYes
severity1 (low) to 3 (high)Yes
typeCategory from aboveYes
disabledSkip this ruleNo

Example Rule File

- id: "aws_access_key"name: "AWS Access Key"description: "Amazon Web Services access key ID"regex: "AKIA[0-9A-Z]{16}"severity: 3type: "cloud"disabled: false
- id: "stripe_key"name: "Stripe API Key"description: "Stripe secret API key"regex: "sk_live_[0-9a-zA-Z]{24}"severity: 3type: "payment"disabled: false

Output Format

Blacklight provides rich, color-coded output:

[Severity 3]: AWS Access Key Found
Location: slack://channel/C0123456/message/1234567890.123
Context: ...config = { accessKeyId: "AKIAXXXXXXXXXXXXXXXX", region: "us-east-1" }...
Match: AKIAXXXXXXXXXXXXXXXX
--------------------------------------------------------------------------------

The table output uses go-pretty for enhanced readability:

╭──────────────────────────┬──────────┬──────────┬─────────┬───────────────────────────────────╮
│ NAME │ TYPE │ SEVERITY │ STATUS │ PATTERN │
├──────────────────────────┼──────────┼──────────┼─────────┼───────────────────────────────────┤
│ AWS Access Key │ cloud │ 3 │ Enabled │ AKIA[0-9A-Z]{16} │
│ Stripe API Key │ payment │ 3 │ Enabled │ sk_live_[0-9a-zA-Z]{24} │
╰──────────────────────────┴──────────┴──────────┴─────────┴───────────────────────────────────╯

Default Rules

Blacklight comes with a comprehensive set of pre-configured rules for detecting various types of secrets and sensitive information:

Authentication & Authorization

Rule NameDescriptionSeverity
AWS Access KeyAmazon Web Services access key IDHigh
AWS Secret KeyAmazon Web Services secret access keyHigh
Generic API KeyGeneric API key patternsMedium
JWT TokenJSON Web TokenMedium
Basic AuthBasic Authentication credentialsHigh
OAuth Client SecretOAuth 2.0 client secretHigh
OAuth Access TokenOAuth 2.0 access tokenHigh
SSH Private KeySSH private key contentHigh

Cloud Services

Rule NameDescriptionSeverity
Azure Storage Account KeyAzure storage account access keyHigh
GCP Service AccountGoogle Cloud Platform service account keyHigh
Firebase Database URLFirebase realtime database URLMedium
Heroku API KeyHeroku platform API keyHigh
Digital Ocean TokenDigitalOcean API tokenHigh
Cloudflare API KeyCloudflare API key and tokenHigh
AWS Session TokenAWS temporary session tokenHigh

Payment & Financial

Rule NameDescriptionSeverity
Stripe API KeyStripe secret API keyHigh
Stripe Restricted KeyStripe restricted API keyHigh
PayPal Access TokenPayPal OAuth2 access tokenHigh
Square Access TokenSquare OAuth2 access tokenHigh
Credit Card NumberCredit card number patternsHigh

Database & Storage

Rule NameDescriptionSeverity
PostgreSQL ConnectionPostgreSQL connection stringHigh
MySQL ConnectionMySQL connection stringHigh
MongoDB ConnectionMongoDB connection URIHigh
Redis ConnectionRedis connection stringHigh
Elasticsearch ConnectionElasticsearch connection stringMedium

Communication & Messaging

Rule NameDescriptionSeverity
Slack TokenSlack API token and webhook URLHigh
Slack WebhookSlack incoming webhook URLMedium
Discord TokenDiscord bot tokenHigh
Discord WebhookDiscord webhook URLMedium
Twilio API KeyTwilio API keyHigh
SendGrid API KeySendGrid API keyHigh

Development & CI/CD

Rule NameDescriptionSeverity
GitHub TokenGitHub personal access tokenHigh
GitLab TokenGitLab personal access tokenHigh
NPM TokenNPM authentication tokenMedium
Docker RegistryDocker registry credentialsMedium
CircleCI TokenCircleCI API tokenHigh
Jenkins TokenJenkins API tokenHigh

AI & Machine Learning

Rule NameDescriptionSeverity
OpenAI API KeyOpenAI API keyHigh
Hugging Face TokenHugging Face API tokenHigh
Anthropic API KeyAnthropic API keyHigh
Cohere API KeyCohere API keyHigh
Replicate API TokenReplicate API tokenHigh

Analytics & Monitoring

Rule NameDescriptionSeverity
Google AnalyticsGoogle Analytics API keyMedium
New Relic KeyNew Relic license keyHigh
Datadog API KeyDatadog API keyHigh
Sentry DSNSentry client keyMedium
Mixpanel TokenMixpanel project tokenMedium

Generic Patterns

Rule NameDescriptionSeverity
Private KeyGeneric private key contentHigh
Password in URLPassword in URL parametersHigh
Environment VariableHardcoded environment variablesMedium
IP AddressPrivate IP addressesLow
Internal PathInternal system pathsLow

Custom Rules

You can add your own custom rules by creating a file at ~/.blacklight/rules.yaml:

- id: "custom_api_key"name: "Custom API Key"description: "Detects custom API key pattern"regex: "myapi_[a-zA-Z0-9]{32}"severity: 2type: "api"disabled: false
- id: "internal_token"name: "Internal Service Token"description: "Internal service authentication token"regex: "int_[a-zA-Z0-9]{24}"severity: 3type: "auth"disabled: false

Rule Properties

PropertyDescriptionRequiredExample
idUnique identifierYesaws_access_key
nameHuman-readable nameYes"AWS Access Key"
descriptionWhat the rule detectsNo"Amazon Web Services access key ID"
regexDetection patternYesAKIA[0-9A-Z]{16}
severity1 (low) to 3 (high)Yes3
typeCategory from types listYes"cloud"
disabledSkip this ruleNofalse

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

Copyright © 2025 Debarshi Basak

Licensed under the Apache License, Version 2.0

About

Blacklight is a powerful secret, keys and sensitive data scanning tool that helps you detect and prevent sensitive information leaks in your codebase, databases, cloud storage, and communication platforms.

Resources

Stars

12 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages