27 مستودعات
Automated testing of authentication credentials to evaluate system security.
Distinct from Security Testing: Distinct from general security testing: focuses specifically on credential-based brute-force assessment.
Explore 27 awesome GitHub repositories matching security & cryptography · Credential Brute-Forcing. Refine with filters or upvote what's useful.
SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log
Provides large collections of common credentials for testing system resilience against brute-force attacks.
Hashcat is a high-performance hash cracking software and OpenCL compute application used to recover plain-text passwords from hashed data. It functions as a GPU-accelerated recovery tool and distributed password cracker, leveraging CPUs and GPUs to perform intensive cryptographic computations. The system differentiates itself through a distributed cracking workflow that coordinates tasks across multiple machines via an overlay network to share computational load. It further optimizes recovery speed using Markov chain keyspace optimization to prioritize the most likely password candidates. Th
Iterates through all possible combinations of characters based on a specified mask to find a matching hash.
Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor
Evaluates system access security by performing automated credential brute-force attempts.
RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers
Provides automated testing of authentication credentials through dictionary-based brute-force attacks against network services.
fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram
Executes automated dictionary and brute-force attacks to evaluate authentication strength.
Hydra is a network login password cracker and authentication tester designed to identify valid usernames and passwords through automated brute-force and dictionary attacks. It serves as a multi-protocol authentication tester capable of verifying credentials across a wide range of remote network services, including SSH, SMB, FTP, and various database listeners. The project is distinguished by its ability to execute parallelized password attacks against multiple servers and protocols simultaneously. It features a modular system for implementing diverse network authentication schemes, allowing f
Performs automated brute-force and dictionary attacks to identify valid usernames and passwords for remote services.
Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan
Provides automated testing of authentication credentials through systematic brute-force attacks.
This repository contains the source code for a C-based network botnet designed to compromise Internet of Things devices. It serves as a functional implementation of malware used for security research, behavioral analysis, and the development of threat detection signatures. The project includes a command and control server architecture that manages infected devices via a custom binary protocol and TCP-based command distribution. It employs a cross-compilation toolchain to build and deliver architecture-specific binary payloads across multiple hardware platforms. The codebase covers capabiliti
Spreads across network ports by attempting to authenticate using a predefined list of common default credentials.
fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i
Provides libraries of common passwords and default vendor credentials for testing authentication strength.
Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism
Cycles through username and password payloads to automate credential guessing against login forms and HTTP authentication.
Bjorn is a penetration testing framework that automates network scanning, credential brute-forcing, vulnerability assessment, and data exfiltration, all coordinated through an event-driven task pipeline and controlled via a web-based dashboard. Its modular plugin architecture allows independent security modules to be loaded and chained together, with an asynchronous network scanner discovering live hosts and open ports without blocking the main execution flow. The framework distinguishes itself by integrating a credential brute-force engine that systematically attempts login combinations agai
Integrates a credential brute-force engine that systematically attempts login combinations against network services.
Ladon هو ماسح اختراق شبكة داخلي وأداة تقييم ثغرات مصممة لتحديد العيوب الأمنية والأصول عالية المخاطر عبر قطاعات الشبكة. يعمل كماسح أمني بدون ملفات (fileless)، حيث ينفذ محركه ووحداته مباشرة في الذاكرة لتجنب ترك أثر على القرص في الأنظمة المستهدفة. يتميز المشروع بتكامله كمكون إضافي لمنارات الأوامر (command beacons)، وتحديداً داخل إطار عمل Cobalt Strike. يسمح هذا باكتشاف الشبكة المقيم في الذاكرة واكتشاف الثغرات الأمنية. يدعم علاوة على ذلك العمليات الخفية من خلال تشويش الحمولة والنصوص البرمجية، بالإضافة إلى تقنيات لتجاوز الاكتشاف بواسطة أنظمة اكتشاف واستجابة نقاط النهاية. توفر الأداة مجموعة شاملة من القدرات لما بعد الاستغلال، بما في ذلك تدقيق بيانات الاعتماد، والاستخراج، وتنفيذ هجمات Kerberos لاختراق النطاق. يتعامل مع اكتشاف الأصول عبر المسح متعدد البروتوكولات وبصمات الخدمة لتحديد أنظمة التشغيل وتقنيات الويب. بالإضافة إلى ذلك، يدعم أتمتة الحركة الجانبية، وتصعيد الامتيازات، ونشر حمولات تنفيذ الكود عن بُعد. إطار العمل قابل للتوسيع من خلال معمارية المكونات الإضافية التي تسمح بالتحميل الديناميكي للتجميعات أو النصوص البرمجية الخارجية لإضافة وحدات مسح مخصصة وإثباتات المفهوم.
Provides an automated engine for testing usernames and passwords against network protocols to evaluate security.
Nettacker هو إطار عمل لاختبار الاختراق المؤتمت مصمم لتنسيق الاستطلاع، وفحص المنافذ، واكتشاف الثغرات الأمنية. يعمل كأداة لاستطلاع الشبكة وماسح للثغرات الأمنية يقوم بتحديد المنافذ المفتوحة، وبصمات الخدمات، وفحص الأنظمة مقابل قواعد بيانات الثغرات الأمنية المعروفة. يتميز إطار العمل بدمج زاحف لتطبيقات الويب لاكتشاف المسارات المخفية عبر الـ fuzzing مع نظام لإدارة الثغرات الأمنية يحتفظ بنتائج الفحص في قاعدة بيانات لتتبع التقييمات التاريخية. كما يتضمن قدرات متخصصة لتعداد النطاقات الفرعية، وهجمات القوة الغاشمة (brute forcing) على بيانات الاعتماد، والقدرة على توجيه حركة المرور عبر وكلاء (proxies) لإخفاء الهوية. يغطي النظام نطاقاً واسعاً من القدرات الأمنية، بما في ذلك اكتشاف أصول الشبكة، وتدقيق الخدمات متعددة البروتوكولات، وتدقيق التكوين. ويدعم الفحص متعدد الأهداف عبر نطاقات IP وكتل CIDR، ويوفر أدوات لتوليد تقارير أمنية بتنسيقات متعددة. التحكم البرمجي متاح عبر واجهة REST، مما يسمح بدمج إطار العمل في خطوط أنابيب الأمان وسير عمل الأتمتة.
Provides a systematic tool for testing common login combinations to identify unauthorized access vulnerabilities.
يوفر Blasting Dictionary مجموعات بيانات منسقة لأسماء المستخدمين وكلمات المرور الشائعة، مصممة لتدقيق قوة المصادقة وتحديد الحسابات المعرضة للخطر. يعمل كمجموعة من قوائم كلمات المرور لهجمات حشو الاعتمادات (Credential Stuffing) واختبارات كلمات المرور لاكتشاف الاعتمادات الضعيفة أو الافتراضية في الخدمات المستهدفة. يسهل المشروع اختبارات الاختراق الأمني وتقييمات الثغرات من خلال توفير مجموعات البيانات اللازمة لمحاكاة هجمات القوة الغاشمة (Brute Force) وحشو الاعتمادات. تُستخدم هذه الموارد لتقييم أمان أنظمة المصادقة وتحديد الخدمات المعرضة للوصول غير المصرح به. تغطي مجموعة الأدوات تدقيق الاعتمادات من خلال الاختبار الآلي وتوفير قوائم كلمات المرور للهجمات لتحديد بيانات تسجيل الدخول غير الآمنة في الخدمات المستهدفة.
Supplies curated collections of common usernames and passwords used for automated authentication testing.
AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng
Generates customized text files of potential credentials to feed into automated password guessing tools.
Cameradar is a network scanning tool designed to discover publicly accessible IP cameras. It identifies active Real Time Streaming Protocol services by scanning IP ranges and using device fingerprints to determine specific hardware models. The tool performs security auditing through dictionary-based probing and brute force attacks to uncover valid streaming paths and authentication credentials. It validates discovered streams by verifying the receipt of real-time transport protocol data packets to eliminate false positives. The system supports a multi-stage discovery pipeline and can export
Tests common routes and authentication credentials via brute force to find accessible camera streams.
This project is a security auditing and penetration testing utility designed for automating password guessing, credential stuffing, and account brute-forcing on Instagram. It functions as an account recovery auditor that simulates automated login attacks to test the strength of account passwords. The tool incorporates a proxy manager to handle the import and monitoring of proxy lists. This system routes requests through rotating IP addresses and monitors proxy health to prune unresponsive addresses and avoid rate limiting. The software provides capabilities for concurrent request execution a
Automates the guessing of user passwords through repeated login attempts to evaluate account security.
Rubeus is a comprehensive Kerberos attack toolkit for Active Directory environments, written in C#. It provides a full suite of operations for manipulating Kerberos tickets, exploiting delegation configurations, and performing credential attacks against Windows domains. The toolkit enables ticket extraction from logon sessions and memory, with real-time monitoring via Event Tracing for Windows. It supports forging golden and silver tickets with arbitrary privileges, as well as the creation of forged delegation contexts. Delegation attacks include abuse of constrained and unconstrained delegat
Creates processes with alternate credentials and performs brute-force attacks against Kerberos authentication.
CDK هي مجموعة أدوات متخصصة لتدقيق أمان الحاويات، واستغلال الهروب من الحاويات، واختبار اختراق البنية التحتية السحابية. توفر المجموعة مجموعة من النصوص البرمجية والأدوات المصممة لتحديد واستغلال الثغرات الأمنية في بيئات تشغيل الحاويات للهروب من البيئات المعزولة وتنفيذ الأوامر على نظام التشغيل المضيف الأساسي. يتميز المشروع بمجموعة استغلال وقت تشغيل Docker مخصصة لإساءة استخدام Docker API و procfs و cgroups للحصول على وصول غير مصرح به على مستوى المضيف. يتضمن المشروع تقنيات محددة لتجاوز العزل عبر LXCFS، واستغلال مساحة اسم المستخدم، وتركيب أقراص المضيف، بالإضافة إلى إمكانيات لاستخراج البيانات الوصفية السحابية وتدقيق أذونات حساب الخدمة لتصعيد الامتيازات في بيئات المجموعات (clusters). تغطي مجموعة الأدوات مجموعة واسعة من إمكانيات التدقيق الأمني، بما في ذلك تدقيق مجموعات Kubernetes لاستخراج الأسرار وتحليل السياسات، ومسح الملفات والخدمات الحساسة، واكتشاف مشاركة شبكة المضيف. كما توفر أدوات لإنشاء قذائف عكسية (reverse shells)، ونشر الحمولات في البيئات المقيدة، وتثبيت أدوات إدارة النظام داخل حاويات مصغرة.
Includes a tool to brute-force registry usernames and passwords to hijack container images.
Pikachu هي منصة تدريب على أمن الويب وصندوق رمل لتطبيقات الويب الضعيفة. توفر بيئة مختبر داخل حاويات مصممة لممارسة اختبار الاختراق وتحديد عيوب الأمان الشائعة. يعمل المشروع كمختبر ممارسة لـ OWASP Top 10، ويقدم مجموعة محاكاة للمخاطر الحرجة. يتضمن سيناريوهات محددة لممارسة استغلال حقن SQL، والبرمجة عبر المواقع (XSS)، وتنفيذ الكود عن بُعد، وكسر التحكم في الوصول. تغطي البيئة مجموعة واسعة من محاكيات اختبار الأمان، بما في ذلك اجتياز الأدلة، وتزوير الطلبات من جانب الخادم (SSRF)، وتحميل الملفات غير الآمن، وهجمات الكيانات الخارجية XML (XXE). كما تتميز بواجهة خلفية إدارية لإدارة محاكيات التصيد الاحتيالي ومراقبة حمولات الجلسات الملتقطة. يتم نشر المنصة بأكملها عبر صورة داخل حاوية تقوم تلقائياً بتهيئة مخطط قاعدة البيانات وملء البيئة ببيانات أولية.
Simulates repeated attempts to guess credentials to verify the strength of authentication mechanisms.