Leek.Core 0.0.0.1-alpha

This is a prerelease version of Leek.Core.
dotnet add package Leek.Core --version 0.0.0.1-alpha
                    
NuGet\Install-Package Leek.Core -Version 0.0.0.1-alpha
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Leek.Core" Version="0.0.0.1-alpha" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Leek.Core" Version="0.0.0.1-alpha" />
                    
Directory.Packages.props
<PackageReference Include="Leek.Core" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Leek.Core --version 0.0.0.1-alpha
                    
#r "nuget: Leek.Core, 0.0.0.1-alpha"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Leek.Core@0.0.0.1-alpha
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Leek.Core&version=0.0.0.1-alpha&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=Leek.Core&version=0.0.0.1-alpha&prerelease
                    
Install as a Cake Tool

πŸ₯¬ Leek - Hash Auditor for Security Hygiene

Build and Test Source: GPL v3 Binaries: MIT

Leek is a CLI and .NET toolset for detecting breached or weak secrets such as passwords.
Inspired by "There's a leek in the boat!" -Cloudy with a Chance of Meatballs, it helps you plug security holes before your system sinks.

πŸ“¦ .NET API – Integrate into your applications for real-time hash auditing and response. <br/> πŸ’» CLI Tool – Use via terminal to import, scan, and analyze existing hash databases.

Features

  • πŸ” Hash-based breach detection <small>(e.g. SHA1)</small>
  • πŸ› οΈ Wordlist imports and reading
  • βš™οΈ EF Core integration with flexible data access <small>(support list below)</small>
  • πŸ”„ Works online or offline β€” leverage databases, APIs, or wordlists from local or remote sources
  • 🌐 ASP.NET demo web app included

Use cases

  • Enforce secure password policies by blocking weak or breached credentials at login, signup, or during password changes.
  • Audit stored password hashes to proactively identify accounts at risk before a breach occurs.
  • Integrate into CI/CD pipelines to prevent known or default credentials from being used in development or deployments.
  • Automate hash database updates by syncing with trusted online breach or wordlist sources.

Philosophy

Leek focuses on the hash β€” not the password, and this means:

  • Any hashed value can be audited (not just passwords)
  • It works across various platforms and runtimes, while allowing extensibility.
  • It integrates where you need it β€” login-time, scan-time, or CI/CD-time

Supported Data Sources

Leek is built using one or more Data Providers that can be injected at runtime β€” below are the defaults supported:

Frequently Asked Questions

How does it work, will my secrets be exposed?

By default Leek will always assume inputs are secret and will produce a hash for each algorithm, which will subsequently be used to check with the local or remote databases.

What if my input is already hashed?

You would instead supply a filter to the check command or API you are using. This will allow you to provide a flag to indicate what your hash algorithm is, allowing efficient and secure auditing.

Have a suggestion or issue?

Please ensure you check existing issues first! You're welcome to also read the CONTRIBUTING.md if you are interested in contributing to the project.


CLI Usage

# Show help
leek -h
# Show the current apps full version.
leek --version

# Check a secret or hash
leek check <secret> [--type=<enter>] --provider=<enter> --connection-string=<enter>

# Copies hashes from one provider/connection to another
leek copy --from-provider=mssql --from-connection="enter" --to-provider=sqlite --to-connection="enter"

# Loads online hash data into the destination provider/connection.
# nb. this could take hours-days until our sources allow differentials
leek update --provider=<enter> --connection-string=<enter>

API Usage

// register services with DI
builder.Services.AddLeekServices()
    .AddDefaultServices(); // adds all providers, e.g. HIBP, db, directory
// configure your options
builder.Services.Configure<MyOptions>(); // customise as needed

// inject and use the IAuditor interface
public class Example(IAuditor auditor, IOptions<MyOptions> options)
{
    async Task CheckSecret(string secret)
    {
        LeekSearchResponse response = await auditor.SearchBreaches(options.Value.Connections, new LeekSearchRequest(secret));
        // do something with response.IsBreached
        Console.WriteLine($"Secret is{(response.IsBreached ? "" : " not")} breached");
    }
}
public class MyOptions
{
    public required ConnectionContext[] Connections { get; set; }
}

See here and here for an example use in a ASP.NET application.

External Hash Sources

Leek currently supports the following online sources:

Of course, online features are optional and instead you can read from wordlists you may already have, or existing databases if they match the Leek schema (table or view adapter).


Considerations

Leek is built with extensibility in mind. Future enhancements may include:

  • --output json|csv|sarif: For use with audit tooling & CI pipelines
  • Integration with external scanning tools and log systems
  • Auto-redaction alerts (log scanning)
  • Agent/daemon mode for long-running environments
  • Table/schema inference via adapters (e.g. WordPress, Laravel, etc.)
  • Additional hash methods, e.g. NTLM
  • Shortcut flags, e.g. -p=provider://connection-string

License and more

Leek is licensed under the GPLv3 for source code to protect community contributions.

However, to make it easier for real-world adoption:

  • All official NuGet packages and CLI binaries are MIT licensed
  • This means you can safely use them in closed-source projects, CI pipelines, and internal systems
  • All we ask for is a star, mention, or shout-out to help raise awareness
Component License
Source code (this repo) GPLv3
NuGet packages (e.g., Leek.Core) MIT
CLI binaries MIT
Modifying the source GPLv3 applies

For full policy details, see LICENSE_POLICY.md

⚠️ Note: While Leek is not a certified security product, it provides practical tooling to help integrate hash auditing into existing security workflows and improve the overall posture of .NET applications.
It’s designed to be accessible and extensible, making it easier for teams to adopt better security hygiene β€” especially when faced with limited time, budget, or tooling.

No warranties or official support provided. Use ethically at your own risk.

Product Compatible and additional computed target framework versions.
.NET net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net9.0

    • No dependencies.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on Leek.Core:

Package Downloads
Leek.Services

Package Description

Leek.AspNet

Package Description

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.0.0.1-alpha 126 6/28/2025