Quick Start¶
Install Kingfisher, scan a target, and inspect the results.
1. Install Kingfisher¶
For all installation options, see the Installation Guide.
2. Scan a Directory¶
Kingfisher automatically detects whether the path is a Git repo or plain directory.
3. View Results in Your Browser¶
You can also open existing Kingfisher, Gitleaks, or TruffleHog JSON reports with kingfisher view <report.json>.
If you want a shareable upload-based version, the docs site also hosts the report viewer.
4. Show Only Live Secrets¶
Filter to only secrets confirmed active by provider APIs:
To include live credentials plus high-signal findings such as private keys that require manual review, use:
5. Map the Blast Radius (aka Access Map)¶
Inspect the identities, permissions, and resources visible to a supported credential:
6. Revoke a Compromised Secret¶
Use a finding’s generated revoke command for supported credentials:
Kingfisher custom YAML rules may also define revocation:.
7. Scan a GitHub Organization¶
8. Output JSON for CI/CD¶
What's Next?¶
- Basic Scanning — full scanning guide with all options
- Platform Integrations — GitHub, GitLab, S3, Docker, Slack, and more
- Custom Rules — load Kingfisher YAML or Betterleaks TOML and create custom detections
- Blast Radius — blast radius mapping for 43 providers
- Report Viewer & Triager — local and hosted viewer for Kingfisher, Gitleaks, and TruffleHog JSON reports