• About Us
  • Announce
  • Privacy Policy
  • Contact us
MasterTrend Info - Technology, News and Tutorials
  • HOME
    • BLOG
  • Tutorials
  • Hardware
  • Gaming
  • Mobile
  • Security
  • Windows
  • IA
  • Software
  • Networks
  • What's new
  • en_USEnglish
    • es_ESSpanish
    • pt_BRPortuguese
    • fr_FRFrench
    • it_ITItalian
    • de_DEGerman
    • ko_KRKorean
    • jaJapanese
    • zh_CNChinese
    • ru_RURussian
    • thThai
    • pl_PLPolish
    • tr_TRTurkish
    • id_IDIndonesian
    • hi_INHindi
    • arArabic
    • sv_SESwedish
    • nl_NLDutch
No result
See all results
  • HOME
    • BLOG
  • Tutorials
  • Hardware
  • Gaming
  • Mobile
  • Security
  • Windows
  • IA
  • Software
  • Networks
  • What's new
  • en_USEnglish
    • es_ESSpanish
    • pt_BRPortuguese
    • fr_FRFrench
    • it_ITItalian
    • de_DEGerman
    • ko_KRKorean
    • jaJapanese
    • zh_CNChinese
    • ru_RURussian
    • thThai
    • pl_PLPolish
    • tr_TRTurkish
    • id_IDIndonesian
    • hi_INHindi
    • arArabic
    • sv_SESwedish
    • nl_NLDutch
No result
See all results
MasterTrend Info - Technology, News and Tutorials
No result
See all results
Start Security

Betterleaks secrets scanner vs. Gitleaks

MasterTrend Insights by MasterTrend Insights
March 19, 2026
in Security
Reading time:5 min read
0
Betterleaks secrets scanner showing a magnifying glass analyzing digital code and encrypted data on a technology network, cybersecurity concept and vulnerability detection.

Betterleaks Secrets Scanner: Advanced data analytics and cybersecurity technology that detects leaks, vulnerabilities, and hidden patterns in real time.

53
SHARED
147
Views
Share on FacebookShare on Twitter

Contents

  1. Betterleaks secrets scanner: architecture and keys
  2. Detection architecture: what changes with Betterleaks
    1. Components that make the difference
    2. What happens when the scanner finds something?
    3. Governance and human-centered approach/AI
    4. Practical implications and limitations

Betterleaks secrets scanner: architecture and keys

The detection of secrets in repositories has changed considerably in recent years. Previously, it was enough to look for suspicious strings or keys with high entropy in the code. Today, the situation is different: larger repositories, faster CI/CD pipelines, and, above all, an increasing amount of code generated by automated tools or AI models.

This has a practical consequence: the problem is no longer just finding secrets, but separating what is truly dangerous from what merely appears to be. Many teams are discovering that the real cost of these scanners lies not in running the analysis, but in reviewing hundreds of false positives.

Betterleaks, a new open-source secrets scanner to replace Gitleaks

Detection architecture: what changes with Betterleaks

Betterleaks appears precisely in this context. It doesn't attempt to completely reinvent secret scanning, but it does challenge a widespread assumption: that detecting patterns is enough.

In many modern repositories it is not.

The project, developed by Zach Rice and maintained with support from Aikido, proposes something slightly different. Instead of focusing solely on detecting matches, it attempts to validate whether the finding makes sense before escalating it as an alert.

This might seem like a minor detail, but it significantly changes the dynamics in large teams. When a scanning system generates too many irrelevant alerts, the team's natural reaction is to ignore them. And in security, an ignored alert can be worse than no alert at all.

To address this problem, Betterleaks introduces two interesting technical pieces: validation using CEL (Common Expression Language) and a metric called “Token Efficiency”, based on BPE tokenization.

The idea is that not everything that appears to be a secret actually is. Some high-entropy strings are simply hashes, identifiers, or automatically generated fragments. The system's goal is to reduce that noise.

The project documentation mentions a comparison where BPE tokenization achieves a 98.6% recall rate compared to the 70.4% obtained using entropy in the CredData dataset. As with any benchmark, these numbers are indicative. They serve well as a reference point, but do not replace testing in real repositories.

Scanning speed comparison
Scanning speed comparison
Source: GitHub

Components that make the difference

Reviewing the project's characteristics reveals a clear direction: to facilitate deployment in real-world environments without adding too much technical complexity.

Among the most prominent elements are:

  • Rule-defined validation using CEL (Common Expression Language)
  • Token Efficiency Scanning based on BPE tokenization rather than entropy, achieving 98.6% recall vs 70.4% with entropy on the CredData dataset
  • Pure Go implementation (no CGO or Hyperscan dependency)
  • Automatic handling of doubly/triply encoded secrets
  • Expanded rule set for more providers
  • Parallelized Git scanning for faster repository analysis

Although this list may seem like just a set of technical improvements, what's interesting is how they affect everyday use.

For example, a full Go implementation with no native dependencies greatly simplifies integration into CI/CD pipelines. In many teams, small details like that determine whether a tool ends up being used or gets forgotten in a repository.

BPE tokenization also introduces a different approach. Instead of simply measuring the randomness of a chain, it analyzes token patterns that more closely reflect how modern credentials are actually structured.

What happens when the scanner finds something?

When Betterleaks detects a potential secret, the process doesn't end there.

First, the context is evaluated using rules defined in CEL. This allows for the addition of further conditions: for example, checking if the format matches the expected provider or discarding patterns that frequently appear in examples or fictitious data.

This step may seem trivial, but it has a significant practical impact. False positives not only waste time but also reduce the team's confidence in the alert system.

Another interesting aspect is the automatic handling of secrets encoded multiple times. In some repositories, credentials appear transformed using base64 or other encoding schemes, which complicates their detection.

Even so, it's worth remembering something that's sometimes overlooked: no scanner can completely replace human review. Detecting a secret is just the beginning; deciding what to do with it (revoke, rotate, ignore, or investigate) remains a contextual decision.

Governance and human-centered approach/AI

Betterleaks is published under the MIT license and features external contributions from organizations such as Royal Bank of Canada, Red Hat, and Amazon.

The project also attempts to adapt to a reality that is increasingly visible in modern repositories: the mix of code written by developers and code generated by automated tools.

In this context, the tool aims to function well in both human-operated workflows and automated systems that review entire repositories. This aligns with the growing use of automation and tools that analyze code or generate automatic reviews.

The roadmap also includes interesting ideas: integration with data sources beyond GitLanguage model assistance for classifying findings and automatic revocation mechanisms via provider APIs.

This opens up an interesting debate. Automating credential revocation can reduce the time it takes to respond to an incident, but it also means relying on the classification system to be accurate.

If an automatic revocation fails or is triggered by mistake, the operational impact can be considerable.

Practical implications and limitations

From an operational point of view, Betterleaks is attractive to teams looking to reduce false positives and simplify deployments.

But it's also important to keep some limits in mind:

  • Recall metrics depend on the dataset used and can vary considerably between repositories.
  • Automating actions such as key revocation requires additional controls and audit logs.
  • Secret scanners remain just one layer of defense within a broader strategy.

In many cases, the decision to adopt such a tool depends not so much on its theoretical accuracy as on something simpler: whether it integrates well into the team's workflow.

A highly accurate scanner that generates too much friction is usually abandoned. A reasonably accurate one that is easy to integrate is usually retained.

In that sense, Betterleaks attempts to strike a balance. It doesn't promise to eliminate all false positives or replace existing security processes, but it does aim to reduce noise and facilitate integration into modern pipelines.

The project is available on GitHub and is presented as an evolution of the approach used by Gitleaks, with the intention of adapting to repositories where automation, analysis agents and code generated by language models are a regular part of the development flow.

Share this:
FacebookLinkedInPinterestXRedditTumblrBlueskyThreadsShareChatGPTClaudeGoogle AIGrok
Tags: AutomationCybersecurityEvergreenContent
Previous Publication

Google Voice Recording: What it saves and how to disable it

next post

Windows 11 God Mode: What it is and when it adds value

MasterTrend Insights

MasterTrend Insights

Our editorial team shares a deep-dive analysis, tutorials and recommendations for getting the most out of your devices and digital tools.

RelatedPublications

DMARC lookup tool to protect your domain with security verification, email authentication, and a cybersecurity dashboard with padlock and shield icons on the digital screen.
Security

DMARC lookup tool to protect your domain

May 19, 2026
92
Private DNS on Android: Woman showing location settings disabled on her smartphone next to the Android logo and no tracking symbol, illustrating how to reduce tracking and improve privacy on Android.
Security

Private DNS on Android: How to reduce tracking

May 2, 2026
220
C2 botnet infrastructure represented by a network of connected red-eyed robots, symbolizing command and control servers used in malware and cybersecurity attacks.
Security

C2 botnet infrastructure: impact after the international operation

April 19, 2026
167
Advanced Flow Android: Woman holding the Android mascot with a shield in front of Google's offices, representing the balance between openness, security, and control in the Android operating system.
Security

Advanced Flow Android: a balance between openness and control

May 2, 2026
195
Secure Boot Expiration in Windows 11 showing expired SB certificate warning on laptop screen in corporate office.
Security

Secure Boot Expiration 2026 in Windows 11

March 29, 2026
191
Google Voice Recording - Women conversing at a table while a smartphone displays a microphone and audio waveform interface, illustrating the **Google Voice Recording** feature and potential privacy warnings when recording conversations.
Security

Google Voice Recording: What it saves and how to disable it

March 11, 2026
159
next post
Windows 11 God Mode: Woman holding laptop with "God Mode" folder and advanced system options for configuration, administrative tools and PC optimization.

Windows 11 God Mode: What it is and when it adds value

5 1 vote
Article Rating
Subscribe
Access
Notify of
guest
guest
0 Comments
Oldest
Newest Most voted
Online Comments
See all comments

Stay Connected

  • 976 Fans
  • 118 Followers
  • 1.4 k Followers
  • 1.8 k Subscribers
  • Trends
  • Comments
  • Last
🖥️ How to open 'Devices and printers' in Windows 11: 4 simple steps

🌟 How to open ‘Devices and printers’ in Windows 11: ¡Amazing trick!

April 28, 2026
Windows 11 Persistent Clock

Windows 11 Persistent Clock: Options, Limits, and Real Decisions

April 28, 2026
Ethernet not working in Windows 11: 9 easy tricks

Ethernet not working in Windows 11: 3-minute solution ⚡🌐

13 November 2025
How to save game in REPO

How to save game in REPO 🔥 Discover the secret to not losing progress

7 July 2025
Features of Gmail on Android: Save time with 5 tips

Features of Gmail in Android: you 5 tricks you did not know! 📱✨

12
Repair of motherboards - Repair MotherBoards

Repair of motherboards of Laptops

10
Install Windows 11 Home without Internet

Install Windows 11 Home without Internet

10
How to backup drivers in Windows 11/10 in 4 steps!

How to backup drivers in Windows 11/10 It Prevents errors! 🚨💾

10
Saros Endings: A. Devraj in futuristic Soltari armor in a dark and dramatic scene, analysis of the main ending and secret ending of the video game.

Saros Endings: Analysis of the Main and Secret

June 14, 2026
AMD UDNA architecture for PS6 and Xbox Next, detail of next-generation GPU chip with advanced design for high-performance gaming consoles.

UDNA architecture in PS6 and Xbox Next: more than just numbers

May 4, 2026
FBC Firebreak Weapons: Unlock and Priorities - Tactical operators with shotguns and flamethrowers in combat surrounded by fire in intense video game scene.

FBC Firebreak Weapons: Unlocking and Priorities

May 3, 2026
Strategy Heroes Olden Era: White-haired warrior heroine making key decisions in an epic fantasy battle that change the course of the game.

Heroes Olden Era Strategy: Game-Changing Decisions

May 3, 2026

Recent News

Saros Endings: A. Devraj in futuristic Soltari armor in a dark and dramatic scene, analysis of the main ending and secret ending of the video game.

Saros Endings: Analysis of the Main and Secret

June 14, 2026
86
AMD UDNA architecture for PS6 and Xbox Next, detail of next-generation GPU chip with advanced design for high-performance gaming consoles.

UDNA architecture in PS6 and Xbox Next: more than just numbers

May 4, 2026
131
FBC Firebreak Weapons: Unlock and Priorities - Tactical operators with shotguns and flamethrowers in combat surrounded by fire in intense video game scene.

FBC Firebreak Weapons: Unlocking and Priorities

May 3, 2026
112
Strategy Heroes Olden Era: White-haired warrior heroine making key decisions in an epic fantasy battle that change the course of the game.

Heroes Olden Era Strategy: Game-Changing Decisions

May 3, 2026
161
MasterTrend Info logo

MasterTrend Info is your source of reference in technology: discover news, tutorials, and analysis of hardware, software, gaming, mobile, and artificial intelligence. Subscribe to our newsletter and don't miss any trend.

Follow us

Browse by Category

  • Gaming
  • Hardware
  • IA
  • Mobile
  • What's new
  • Networks
  • Security
  • Software
  • Tutorials
  • Windows

Recent News

Saros Endings: A. Devraj in futuristic Soltari armor in a dark and dramatic scene, analysis of the main ending and secret ending of the video game.

Saros Endings: Analysis of the Main and Secret

June 14, 2026
AMD UDNA architecture for PS6 and Xbox Next, detail of next-generation GPU chip with advanced design for high-performance gaming consoles.

UDNA architecture in PS6 and Xbox Next: more than just numbers

May 4, 2026
  • About Us
  • Announce
  • Privacy Policy
  • Contact us

Copyright © 2025 https://mastertrend.info/ - All rights reserved. All trademarks are property of their respective owners.

We've detected you might be speaking a different language. Do you want to change to:
es_ES Spanish
es_ES Spanish
en_US English
pt_BR Portuguese
fr_FR French
it_IT Italian
ru_RU Russian
de_DE German
zh_CN Chinese
ko_KR Korean
ja Japanese
th Thai
hi_IN Hindi
ar Arabic
tr_TR Turkish
pl_PL Polish
id_ID Indonesian
nl_NL Dutch
sv_SE Swedish
Change Language
Close and do not switch language
No result
See all results
  • en_USEnglish
    • es_ESSpanish
    • pt_BRPortuguese
    • fr_FRFrench
    • it_ITItalian
    • de_DEGerman
    • ko_KRKorean
    • jaJapanese
    • zh_CNChinese
    • ru_RURussian
    • pl_PLPolish
    • id_IDIndonesian
    • tr_TRTurkish
    • hi_INHindi
    • thThai
    • arArabic
    • sv_SESwedish
    • nl_NLDutch
  • Gaming
  • Hardware
  • IA
  • Mobile
  • What's new
  • Networks
  • Security
  • Software
  • Tutorials
  • Windows

Copyright © 2025 https://mastertrend.info/ - All rights reserved. All trademarks are property of their respective owners.

wpDiscuz
RedditBlueskyXMastodonHacker News
Share this:
MastodonVKWhatsAppTelegramSMSLineMessengerFlipboardHacker NewsMixNextdoorPerplexityXingYummly
Your Mastodon Instance