27 repositorios
Automated testing of authentication credentials to evaluate system security.
Distinct from Security Testing: Distinct from general security testing: focuses specifically on credential-based brute-force assessment.
Explore 27 awesome GitHub repositories matching security & cryptography · Credential Brute-Forcing. Refine with filters or upvote what's useful.
SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log
Provides large collections of common credentials for testing system resilience against brute-force attacks.
Hashcat is a high-performance hash cracking software and OpenCL compute application used to recover plain-text passwords from hashed data. It functions as a GPU-accelerated recovery tool and distributed password cracker, leveraging CPUs and GPUs to perform intensive cryptographic computations. The system differentiates itself through a distributed cracking workflow that coordinates tasks across multiple machines via an overlay network to share computational load. It further optimizes recovery speed using Markov chain keyspace optimization to prioritize the most likely password candidates. Th
Iterates through all possible combinations of characters based on a specified mask to find a matching hash.
Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor
Evaluates system access security by performing automated credential brute-force attempts.
RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers
Provides automated testing of authentication credentials through dictionary-based brute-force attacks against network services.
fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram
Executes automated dictionary and brute-force attacks to evaluate authentication strength.
Hydra is a network login password cracker and authentication tester designed to identify valid usernames and passwords through automated brute-force and dictionary attacks. It serves as a multi-protocol authentication tester capable of verifying credentials across a wide range of remote network services, including SSH, SMB, FTP, and various database listeners. The project is distinguished by its ability to execute parallelized password attacks against multiple servers and protocols simultaneously. It features a modular system for implementing diverse network authentication schemes, allowing f
Performs automated brute-force and dictionary attacks to identify valid usernames and passwords for remote services.
Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan
Provides automated testing of authentication credentials through systematic brute-force attacks.
This repository contains the source code for a C-based network botnet designed to compromise Internet of Things devices. It serves as a functional implementation of malware used for security research, behavioral analysis, and the development of threat detection signatures. The project includes a command and control server architecture that manages infected devices via a custom binary protocol and TCP-based command distribution. It employs a cross-compilation toolchain to build and deliver architecture-specific binary payloads across multiple hardware platforms. The codebase covers capabiliti
Spreads across network ports by attempting to authenticate using a predefined list of common default credentials.
fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i
Provides libraries of common passwords and default vendor credentials for testing authentication strength.
Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism
Cycles through username and password payloads to automate credential guessing against login forms and HTTP authentication.
Bjorn is a penetration testing framework that automates network scanning, credential brute-forcing, vulnerability assessment, and data exfiltration, all coordinated through an event-driven task pipeline and controlled via a web-based dashboard. Its modular plugin architecture allows independent security modules to be loaded and chained together, with an asynchronous network scanner discovering live hosts and open ports without blocking the main execution flow. The framework distinguishes itself by integrating a credential brute-force engine that systematically attempts login combinations agai
Integrates a credential brute-force engine that systematically attempts login combinations against network services.
Ladon es un escáner de penetración de red interna y herramienta de evaluación de vulnerabilidades diseñada para identificar fallas de seguridad y activos de alto riesgo a través de segmentos de red. Opera como un escáner de seguridad sin archivos (fileless), ejecutando su motor y módulos directamente en la memoria para evitar dejar una huella en el disco en los sistemas objetivo. El proyecto se distingue por su integración como plugin para balizas de comando (command beacons), específicamente dentro del framework Cobalt Strike. Esto permite el descubrimiento de red y la detección de vulnerabilidades residentes en memoria. Además, admite operaciones sigilosas mediante la ofuscación de cargas útiles y scripts, así como técnicas para eludir la detección por parte de sistemas de detección y respuesta de endpoints (EDR). La herramienta proporciona un conjunto completo de capacidades para la post-explotación, incluyendo auditoría de credenciales, extracción y la ejecución de ataques Kerberos para la penetración de dominios. Maneja el descubrimiento de activos mediante escaneo multiprotocolo y huellas dactilares de servicios para identificar sistemas operativos y tecnologías web. Además, admite la automatización del movimiento lateral, la escalada de privilegios y el despliegue de cargas útiles de ejecución remota de código. El framework es extensible a través de una arquitectura de plugins que permite la carga dinámica de ensamblajes o scripts externos para añadir módulos de escaneo personalizados y pruebas de concepto.
Provides an automated engine for testing usernames and passwords against network protocols to evaluate security.
Nettacker es un framework de pruebas de penetración automatizado diseñado para orquestar el reconocimiento, escaneo de puertos y detección de vulnerabilidades. Funciona como una herramienta de reconocimiento de red y escáner de vulnerabilidades que identifica puertos abiertos, realiza fingerprinting de servicios y verifica sistemas contra bases de datos de fallos de seguridad conocidos. El framework se distingue por combinar un crawler de aplicaciones web para descubrir rutas ocultas mediante fuzzing con un sistema de gestión de vulnerabilidades que persiste los resultados del escaneo en una base de datos para rastrear evaluaciones históricas. También incluye capacidades especializadas para la enumeración de subdominios, fuerza bruta de credenciales y la capacidad de enrutar tráfico a través de proxies para anonimización. El sistema cubre una amplia superficie de capacidades de seguridad, incluyendo descubrimiento de activos de red, auditoría de servicios multi-protocolo y auditoría de configuración. Soporta escaneo multi-objetivo a través de rangos IP y bloques CIDR, y proporciona herramientas para generar informes de seguridad en múltiples formatos. El control programático está disponible a través de una interfaz basada en REST, permitiendo que el framework se integre en pipelines de seguridad y flujos de automatización.
Provides a systematic tool for testing common login combinations to identify unauthorized access vulnerabilities.
Blasting Dictionary proporciona conjuntos de datos curados de nombres de usuario y contraseñas comunes, diseñados para auditar la seguridad de la autenticación e identificar cuentas vulnerables. Sirve como una colección de diccionarios de ataques de fuerza bruta y relleno de credenciales (credential stuffing) para probar contraseñas débiles o predeterminadas en servicios objetivo. El proyecto facilita las pruebas de penetración y evaluaciones de vulnerabilidad al proporcionar los conjuntos de datos necesarios para simular ataques de fuerza bruta y credential stuffing. Estos recursos se utilizan para evaluar la seguridad de los sistemas de autenticación e identificar servicios susceptibles a accesos no autorizados. El conjunto de herramientas cubre la auditoría de credenciales mediante pruebas automatizadas y el suministro de diccionarios de ataque para identificar credenciales de inicio de sesión inseguras en servicios objetivo.
Supplies curated collections of common usernames and passwords used for automated authentication testing.
AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng
Generates customized text files of potential credentials to feed into automated password guessing tools.
Cameradar is a network scanning tool designed to discover publicly accessible IP cameras. It identifies active Real Time Streaming Protocol services by scanning IP ranges and using device fingerprints to determine specific hardware models. The tool performs security auditing through dictionary-based probing and brute force attacks to uncover valid streaming paths and authentication credentials. It validates discovered streams by verifying the receipt of real-time transport protocol data packets to eliminate false positives. The system supports a multi-stage discovery pipeline and can export
Tests common routes and authentication credentials via brute force to find accessible camera streams.
Este proyecto es una utilidad de auditoría de seguridad y pruebas de penetración diseñada para automatizar la adivinación de contraseñas, el relleno de credenciales y el ataque de fuerza bruta a cuentas de Instagram. Funciona como un auditor de recuperación de cuentas que simula ataques de inicio de sesión automatizados para probar la fortaleza de las contraseñas de las cuentas. La herramienta incorpora un gestor de proxies para manejar la importación y el monitoreo de listas de proxies. Este sistema enruta las solicitudes a través de direcciones IP rotativas y monitorea la salud de los proxies para eliminar direcciones que no responden y evitar la limitación de velocidad (rate limiting). El software proporciona capacidades para la ejecución concurrente de solicitudes y el manejo automatizado de sesiones para simular solicitudes de navegador auténticas. Admite la prueba iterativa de contraseñas candidatas y el uso de ataques de diccionario para evaluar las vulnerabilidades de las cuentas.
Automates the guessing of user passwords through repeated login attempts to evaluate account security.
Rubeus is a comprehensive Kerberos attack toolkit for Active Directory environments, written in C#. It provides a full suite of operations for manipulating Kerberos tickets, exploiting delegation configurations, and performing credential attacks against Windows domains. The toolkit enables ticket extraction from logon sessions and memory, with real-time monitoring via Event Tracing for Windows. It supports forging golden and silver tickets with arbitrary privileges, as well as the creation of forged delegation contexts. Delegation attacks include abuse of constrained and unconstrained delegat
Creates processes with alternate credentials and performs brute-force attacks against Kerberos authentication.
CDK es un conjunto de herramientas especializado para la auditoría de seguridad de contenedores, explotación de escapes de contenedores y pruebas de penetración de infraestructura en la nube. Proporciona una colección de scripts y herramientas diseñadas para identificar y explotar vulnerabilidades en los runtimes de contenedores para salir de entornos aislados y ejecutar comandos en el sistema operativo host subyacente. El proyecto cuenta con una suite de explotación de runtime Docker dedicada para abusar de la API de Docker, procfs y cgroups para obtener acceso no autorizado a nivel de host. Incluye técnicas específicas para eludir el aislamiento mediante LXCFS, explotación de espacios de nombres de usuario y montaje de discos del host, así como capacidades para extraer metadatos de la nube y auditar permisos de cuentas de servicio para escalar privilegios en entornos de clúster. El kit de herramientas cubre una amplia gama de capacidades de auditoría de seguridad, incluyendo la auditoría de clústeres Kubernetes para la exfiltración de secretos y análisis de políticas, escaneo de archivos y servicios sensibles, y la detección de intercambio de red del host. También proporciona utilidades para establecer reverse shells, desplegar payloads en entornos restringidos e instalar herramientas de administración del sistema dentro de contenedores mínimos.
Includes a tool to brute-force registry usernames and passwords to hijack container images.
Pikachu es una plataforma de entrenamiento en seguridad web y sandbox de aplicaciones web vulnerables. Proporciona un entorno de laboratorio en contenedores diseñado para practicar pruebas de penetración e identificar fallas de seguridad comunes. El proyecto sirve como laboratorio de práctica para el OWASP Top 10, ofreciendo una suite de simulación para riesgos críticos. Incluye escenarios específicos para practicar la explotación de inyección SQL, cross-site scripting (XSS), ejecución remota de código y control de acceso roto. El entorno cubre una amplia gama de simulaciones de pruebas de seguridad, incluyendo directory traversal, server-side request forgery (SSRF), carga de archivos insegura y ataques de entidades externas XML (XXE). También cuenta con un backend administrativo para gestionar simulaciones de phishing y monitorear payloads de sesión capturados. La plataforma completa se despliega mediante una imagen en contenedores que inicializa automáticamente el esquema de la base de datos y puebla el entorno con datos de prueba.
Simulates repeated attempts to guess credentials to verify the strength of authentication mechanisms.