Sift: the open-source tool that reveals hidden credentials in Microsoft 365, Slack, and Jira
Sift, a free open-source tool developed by Stratus Security, has discovered thousands of exposed credentials in Jira ticket comments during a recent penetration test. The tool, designed to search for passwords, API keys, and other sensitive data, scans local files, Windows shares, Active Directory domains, SharePoint, OneDrive, Teams files, Slack messages, Jira, and Confluence.
Quick Answer
- Sift is a free open-source tool for scanning sensitive credentials
- It has discovered thousands of exposed credentials in Jira ticket comments
- Scans local files, SharePoint, OneDrive, Teams, Slack, Jira, and Confluence
- It is faster and less memory-intensive than Snaffler
- Can be integrated with local language models to reduce false positives
Hidden credentials in Jira tickets
Colin Watson, CTO of Stratus Security, revealed that during a recent penetration test, Sift identified thousands of credentials in Jira ticket comments. This type of discovery had been missed by previous tests because it did not fall within the standard tools and methods used.
No service is an absolute priority
Watson emphasized that the discovery changed the advice provided by his company, but did not create a hierarchy of dangers. "It has absolutely changed the advice, but none of the services are a priority over the others. We recommend checking all possible services equally," he stated.
Superior performance compared to Snaffler
Stratus compared Sift with Snaffler 1.0.244 on synthetic file repositories on August 24, 2026, running three tests per scenario. The results showed that Sift is significantly faster:
- Scanning 250,000 small files: 10.61 seconds vs. 25.48 for Snaffler
Sift also used less memory: an average of 92 MiB compared to 337 MiB for Snaffler.
Throughput control and checkpoint recovery
Sift allows controlling the number of threads and read speed to avoid overloading production servers. Each scan command also writes checkpoints, allowing a interrupted scan to be resumed without starting over.
Filtering false positives with local language models
Scanning for secrets can generate false positives. Sift can pass the results to a local language model, run via Ollama on a user-controlled machine, to filter them. This is particularly important when the scanned data includes all passwords left unguarded by the client.
The challenge of open-source maintenance
Stratus maintained a fork of Snaffler before developing Sift. Now, the tool's maintenance is managed by Stratus, which also has clients to serve. Watson acknowledges the risk that all open-source tools may stop being maintained, but is motivated to keep it active due to its regular use and growing popularity.
Adding custom detection rules
Sift's detection rules are simple JSON files that can be modified with a text editor. A custom directory of rules can replace the provided catalog. Currently, release binaries are not signed, so it is important to verify the published SHA256 hashes before downloading.
Availability and community
Sift is freely available on GitHub. Watson encourages external contributions and suggestions to improve the tool, emphasizing that all open-source tools are better as a community project.
The importance of secret scanning
The discovery of exposed credentials in Jira tickets underscores the importance of tools like Sift for information security. The ability to scan a wide range of services and files, combined with superior performance and the ability to integrate local language models, makes Sift a valuable tool for cybersecurity teams.
To stay updated on the latest news and open-source tools for cybersecurity, you can subscribe to Help Net Security's monthly newsletter.
The adoption of Sift in companies
The adoption of Sift is growing among companies seeking to improve their cybersecurity practices. According to Watson, many organizations are beginning to integrate Sift into their audit and compliance processes, recognizing the value of a tool that can scan a wide range of services and identify compromised credentials. However, adoption requires a certain maturity in security management, as scan results must be interpreted and managed correctly.
The role of Sift in risk mitigation
Sift's ability to identify exposed credentials in environments like Jira, Slack, and Microsoft 365 makes it a crucial tool for risk mitigation. Watson emphasizes that while other tools focus on individual services, Sift offers a holistic view, allowing companies to address vulnerabilities more effectively. This integrated approach is particularly useful for organizations using multiple platforms for project management and collaboration.
The importance of the open-source community
The open-source community plays a fundamental role in the development and improvement of tools like Sift. Watson actively encourages external contributions, emphasizing that feedback and patches from community members can help identify and resolve bugs, improve performance, and add new features. This collaborative development model is essential to keep the tool relevant and useful for a wide range of users.
Future challenges for Sift
Despite its advantages, Sift faces several future challenges. One of the main ones is ensuring the long-term sustainability of the project. Watson acknowledges that while Stratus Security is currently motivated to maintain Sift, continued support will depend on community growth and user interest. Additionally, integrating with new services and platforms will require constant updates to detection rules, ensuring that Sift remains a versatile and indispensable tool for cybersecurity teams.
Advice for effective use of Sift
To maximize the effectiveness of Sift, Watson recommends running regular scans and integrating the results into the company's risk management process. It is also important to train staff on the correct interpretation of results and the necessary actions to mitigate identified vulnerabilities. Additionally, adopting best practices for credential management, such as using complex passwords and implementing two-factor authentication, can further improve overall security.
The future of Sift and scanning technologies
The future of Sift and secret scanning technologies is promising, with the potential for further improvements and integrations. Watson sees an opportunity for the integration of artificial intelligence and machine learning, which could help reduce false positives and identify complex patterns of credential exposure. Additionally, expanding compatibility with new services and platforms will continue to be a priority, ensuring that Sift remains a versatile and indispensable tool for cybersecurity teams.
Additional resources for cybersecurity
For those interested in delving deeper into cybersecurity topics, Help Net Security offers a wide range of resources, including articles, guides, and webinars. Subscribing to the monthly newsletter can be a useful way to stay updated on the latest news and industry trends. Additionally, exploring other open-source platforms like GitHub can provide additional tools and resources to improve organizational security.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.