TruffleHog Secrets Scanner Execution by Interactive Non-CI/CD Process

Detects the execution of the TruffleHog tool, which is used for scanning Git repositories and codebases to discover exposed sensitive information, such as API keys and passwords. The rule monitors process execution command lines and filters out common CI/CD and automation service accounts to identify potentially malicious or unauthorized use of the tool on endpoints.