27 dépôts
Automated testing of authentication credentials to evaluate system security.
Distinct from Security Testing: Distinct from general security testing: focuses specifically on credential-based brute-force assessment.
Explore 27 awesome GitHub repositories matching security & cryptography · Credential Brute-Forcing. Refine with filters or upvote what's useful.
SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log
Provides large collections of common credentials for testing system resilience against brute-force attacks.
Hashcat is a high-performance hash cracking software and OpenCL compute application used to recover plain-text passwords from hashed data. It functions as a GPU-accelerated recovery tool and distributed password cracker, leveraging CPUs and GPUs to perform intensive cryptographic computations. The system differentiates itself through a distributed cracking workflow that coordinates tasks across multiple machines via an overlay network to share computational load. It further optimizes recovery speed using Markov chain keyspace optimization to prioritize the most likely password candidates. Th
Iterates through all possible combinations of characters based on a specified mask to find a matching hash.
Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor
Evaluates system access security by performing automated credential brute-force attempts.
RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers
Provides automated testing of authentication credentials through dictionary-based brute-force attacks against network services.
fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram
Executes automated dictionary and brute-force attacks to evaluate authentication strength.
Hydra is a network login password cracker and authentication tester designed to identify valid usernames and passwords through automated brute-force and dictionary attacks. It serves as a multi-protocol authentication tester capable of verifying credentials across a wide range of remote network services, including SSH, SMB, FTP, and various database listeners. The project is distinguished by its ability to execute parallelized password attacks against multiple servers and protocols simultaneously. It features a modular system for implementing diverse network authentication schemes, allowing f
Performs automated brute-force and dictionary attacks to identify valid usernames and passwords for remote services.
Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan
Provides automated testing of authentication credentials through systematic brute-force attacks.
This repository contains the source code for a C-based network botnet designed to compromise Internet of Things devices. It serves as a functional implementation of malware used for security research, behavioral analysis, and the development of threat detection signatures. The project includes a command and control server architecture that manages infected devices via a custom binary protocol and TCP-based command distribution. It employs a cross-compilation toolchain to build and deliver architecture-specific binary payloads across multiple hardware platforms. The codebase covers capabiliti
Spreads across network ports by attempting to authenticate using a predefined list of common default credentials.
fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i
Provides libraries of common passwords and default vendor credentials for testing authentication strength.
Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism
Cycles through username and password payloads to automate credential guessing against login forms and HTTP authentication.
Bjorn is a penetration testing framework that automates network scanning, credential brute-forcing, vulnerability assessment, and data exfiltration, all coordinated through an event-driven task pipeline and controlled via a web-based dashboard. Its modular plugin architecture allows independent security modules to be loaded and chained together, with an asynchronous network scanner discovering live hosts and open ports without blocking the main execution flow. The framework distinguishes itself by integrating a credential brute-force engine that systematically attempts login combinations agai
Integrates a credential brute-force engine that systematically attempts login combinations against network services.
Ladon est un scanner de pénétration réseau interne et un outil d'évaluation de vulnérabilité conçu pour identifier les failles de sécurité et les actifs à haut risque à travers les segments réseau. Il fonctionne comme un scanner de sécurité sans fichier (fileless), exécutant son moteur et ses modules directement en mémoire pour éviter de laisser une empreinte disque sur les systèmes cibles. Le projet se distingue par son intégration en tant que plugin pour les balises de commande (beacons), spécifiquement au sein du framework Cobalt Strike. Cela permet une découverte réseau et une détection de vulnérabilité résidant en mémoire. Il prend en outre en charge les opérations furtives via l'obfuscation de charge utile et de script, ainsi que des techniques pour contourner la détection par les systèmes de détection et de réponse aux points de terminaison (EDR). L'outil fournit une suite complète de capacités pour la post-exploitation, incluant l'audit d'identifiants, l'extraction et l'exécution d'attaques Kerberos pour la pénétration de domaine. Il gère la découverte d'actifs via le scan multi-protocole et l'empreinte de service pour identifier les systèmes d'exploitation et les technologies web. De plus, il prend en charge l'automatisation des mouvements latéraux, l'élévation de privilèges et le déploiement de charges utiles d'exécution de code à distance. Le framework est extensible via une architecture de plugin qui permet le chargement dynamique d'assemblages ou de scripts externes pour ajouter des modules de scan personnalisés et des preuves de concept.
Provides an automated engine for testing usernames and passwords against network protocols to evaluate security.
Nettacker est un framework de test d'intrusion automatisé conçu pour orchestrer la reconnaissance, le scan de ports et la détection de vulnérabilités. Il fonctionne comme un outil de reconnaissance réseau et un scanner de vulnérabilités qui identifie les ports ouverts, empreinte les services et vérifie les systèmes par rapport à des bases de données de failles de sécurité connues. Le framework se distingue en combinant un crawler d'applications web pour découvrir des chemins cachés via le fuzzing, avec un système de gestion des vulnérabilités qui persiste les résultats des scans dans une base de données pour suivre les évaluations historiques. Il inclut également des capacités spécialisées pour l'énumération de sous-domaines, le brute forcing d'identifiants et la possibilité d'acheminer le trafic via des proxys pour l'anonymisation. Le système couvre une large surface de capacités de sécurité, incluant la découverte d'actifs réseau, l'audit de services multi-protocoles et l'audit de configuration. Il prend en charge le scan multi-cibles sur des plages IP et des blocs CIDR, et fournit des outils pour générer des rapports de sécurité dans plusieurs formats. Un contrôle programmatique est disponible via une interface REST, permettant au framework d'être intégré dans des pipelines de sécurité et des flux d'automatisation.
Provides a systematic tool for testing common login combinations to identify unauthorized access vulnerabilities.
Blasting Dictionary propose des jeux de données organisés de noms d'utilisateur et de mots de passe courants, conçus pour auditer la robustesse de l'authentification et identifier les comptes vulnérables. Il sert de collection de listes de mots pour le credential stuffing et de dictionnaires d'attaques par mot de passe, utilisés pour tester la présence d'identifiants faibles ou par défaut sur des services cibles. Le projet facilite les tests d'intrusion et les évaluations de vulnérabilité en fournissant les jeux de données nécessaires à la simulation d'attaques par force brute et par credential stuffing. Ces ressources sont utilisées pour évaluer la sécurité des systèmes d'authentification et identifier les services susceptibles d'accès non autorisés. L'ensemble d'outils couvre l'audit des identifiants via des tests automatisés et la mise à disposition de listes de mots d'attaque pour identifier les identifiants de connexion non sécurisés sur les services cibles.
Supplies curated collections of common usernames and passwords used for automated authentication testing.
AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng
Generates customized text files of potential credentials to feed into automated password guessing tools.
Cameradar is a network scanning tool designed to discover publicly accessible IP cameras. It identifies active Real Time Streaming Protocol services by scanning IP ranges and using device fingerprints to determine specific hardware models. The tool performs security auditing through dictionary-based probing and brute force attacks to uncover valid streaming paths and authentication credentials. It validates discovered streams by verifying the receipt of real-time transport protocol data packets to eliminate false positives. The system supports a multi-stage discovery pipeline and can export
Tests common routes and authentication credentials via brute force to find accessible camera streams.
Ce projet est un utilitaire d'audit de sécurité et de test d'intrusion conçu pour automatiser la devinette de mots de passe, le credential stuffing et le brute-forcing de comptes sur Instagram. Il fonctionne comme un auditeur de récupération de compte qui simule des attaques de connexion automatisées pour tester la force des mots de passe des comptes. L'outil intègre un gestionnaire de proxy pour gérer l'importation et le monitoring de listes de proxys. Ce système route les requêtes via des adresses IP rotatives et surveille la santé des proxys pour élaguer les adresses non réactives et éviter la limitation de débit (rate limiting). Le logiciel fournit des capacités pour l'exécution de requêtes concurrentes et la gestion automatisée de sessions pour simuler des requêtes de navigateur authentiques. Il prend en charge le test itératif de mots de passe candidats et l'utilisation d'attaques par dictionnaire pour évaluer les vulnérabilités des comptes.
Automates the guessing of user passwords through repeated login attempts to evaluate account security.
Rubeus is a comprehensive Kerberos attack toolkit for Active Directory environments, written in C#. It provides a full suite of operations for manipulating Kerberos tickets, exploiting delegation configurations, and performing credential attacks against Windows domains. The toolkit enables ticket extraction from logon sessions and memory, with real-time monitoring via Event Tracing for Windows. It supports forging golden and silver tickets with arbitrary privileges, as well as the creation of forged delegation contexts. Delegation attacks include abuse of constrained and unconstrained delegat
Creates processes with alternate credentials and performs brute-force attacks against Kerberos authentication.
CDK est une boîte à outils spécialisée pour l'audit de sécurité des conteneurs, l'exploitation d'évasions de conteneurs et le pentesting d'infrastructures cloud. Elle fournit une collection de scripts et d'outils conçus pour identifier et exploiter les vulnérabilités dans les runtimes de conteneurs afin de sortir des environnements isolés et d'exécuter des commandes sur le système d'exploitation hôte sous-jacent. Le projet propose une suite d'exploitation dédiée au runtime Docker pour abuser de l'API Docker, de procfs et des cgroups afin d'obtenir un accès non autorisé au niveau de l'hôte. Il inclut des techniques spécifiques pour contourner l'isolation via LXCFS, l'exploitation des espaces de noms utilisateur et le montage de disques hôtes, ainsi que des capacités pour extraire les métadonnées cloud et auditer les permissions des comptes de service afin d'élever les privilèges dans les environnements de cluster. La boîte à outils couvre un large éventail de capacités d'audit de sécurité, y compris l'audit de clusters Kubernetes pour l'exfiltration de secrets et l'analyse de politiques, l'analyse de fichiers et services sensibles, et la détection du partage de réseau hôte. Elle fournit également des utilitaires pour établir des reverse shells, déployer des charges utiles dans des environnements restreints et installer des outils d'administration système au sein de conteneurs minimaux.
Includes a tool to brute-force registry usernames and passwords to hijack container images.
Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab environment designed for practicing penetration testing and identifying common security flaws. The project serves as an OWASP Top 10 practice lab, offering a simulation suite for critical risks. It includes specific scenarios for practicing the exploitation of SQL injection, cross-site scripting, remote code execution, and broken access control. The environment covers a broad range of security testing simulations, including directory traversal, server-side request forgery, unsa
Simulates repeated attempts to guess credentials to verify the strength of authentication mechanisms.