Skip to content

Vault ProspectorFind any Azure Key Vault secret, across every tenant

A local-first Windows desktop app that indexes Key Vault metadata across all of your Microsoft Entra identities, tenants, and subscriptions — and never reveals a value without an explicit action and a Windows Hello check.

Vault Prospector

⚠️ This is a major work in progress

Vault Prospector is Preview software under active development. Do not use it in production.

Read this before you download anything:

  • The current release is 0.3.0-preview.3 — a preview, published for non-production evaluation only.
  • Direct packages are unsigned. Windows will display Unknown Publisher when you run the installer. You must verify the published SHA-256 and Sigstore bundle before installing. A trusted, signed channel via the Microsoft Store is planned but not yet available.
  • Features land, change shape, and get replaced between previews. Expect breaking changes to the UI, the local database, and configuration between releases.
  • CyberArk support and the native mobile apps are not implemented. They exist as future-roadmap source in this repository and are not part of any current release.
  • Enterprise policy and browser-fill are themselves marked Preview inside a Preview.
  • Documentation on this site is being written alongside the product and will be incomplete in places.

If you hit a problem, file feedback publicly — but report security issues privately per SECURITY.md. Never include credentials, tokens, secret values, or vault names in any report.

Download

Current Preview: 0.3.0-preview.3

Verify before you install — these packages are unsigned. The release verification guide covers the checksum and Sigstore steps.

Requirements

  • Windows 10/11 x64, with Windows Hello configured for verification prompts.
  • A Microsoft Entra account with read access to the Key Vaults you want to index.

Building from source additionally needs PowerShell 7+ and the .NET SDK pinned in global.json.

Where to go next

Preview software. Direct packages are unsigned and display Unknown Publisher — verify the published SHA-256 before installing.