awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
vanhauser-thc avatar

vanhauser-thc/thc-hydra

0
View on GitHub↗
11,943 stars·2,563 forks·C·AGPL-3.0·9 views

Thc Hydra

Hydra is a network login password cracker and authentication tester designed to identify valid usernames and passwords through automated brute-force and dictionary attacks. It serves as a multi-protocol authentication tester capable of verifying credentials across a wide range of remote network services, including SSH, SMB, FTP, and various database listeners.

The project is distinguished by its ability to execute parallelized password attacks against multiple servers and protocols simultaneously. It features a modular system for implementing diverse network authentication schemes, allowing for the development of custom protocol modules and the use of a pluggable transport layer for SSL or TLS security.

Its capability surface includes credential enumeration, web form brute forcing, and the generation of password candidates via custom character sets. It also incorporates cryptographic primitives for NTLMv2 and HMAC-MD5, proxy-routed traffic tunneling for source obfuscation, and state-based session persistence to resume interrupted attacks.

The tool provides a graphical user interface for controlling and monitoring network attacks and managing parallelized requests.

Features

  • Credential Brute-Forcing - Performs automated brute-force and dictionary attacks to identify valid usernames and passwords for remote services.
  • Remote Protocol - Automates login attempts across various network protocols to test the strength of remote service passwords.
  • Parallel Execution - Executes simultaneous password guesses across multiple authentication protocols to accelerate credential discovery.
  • Pluggable Transport Layers - Ships a modular transport layer allowing the swapping of security layers like SSL or TLS based on protocol requirements.
  • Multi-Protocol Gateways - Supports authentication attacks across various services including HTTP, SMB, SMTP, SSL, and SNMP.
  • Authentication Response Heuristics - Determines authentication success by matching server responses against protocol-specific success and failure patterns.
  • Credential Validation Logic - Detects successful logins by analyzing server response codes and specific success indicators for each protocol.
  • Multi-Protocol Authentication Testing - Tests credentials across a wide variety of network services including SSH, HTTP, SMB, FTP, and database listeners.
  • Multi-Server Target Execution - Processes lists of target servers simultaneously to perform large-scale authentication testing.
  • Protocol Security Testers - Verifies credentials across a wide range of services including SSH, SMB, FTP, and databases.
  • Username Enumerations - Identifies valid usernames on remote services by analyzing server responses during the authentication process.
  • Interface-Based Module Registries - Defines a common interface to dynamically load and process interchangeable authentication logic modules.
  • Connection Multiplexers - Manages multiple simultaneous network sockets to execute high-speed authentication attempts across diverse targets.
  • Character Set Generators - Creates custom alphabets of characters to be used for automated password guessing.
  • Web Form Brute-Forcing - Automates password guessing against web login pages by analyzing server responses for success.
  • Wordlist Generators - Downloads and aggregates vendor-specific default passwords from remote sources to create targeted wordlists.
  • Firebird Database Attacks - Implements automated credential testing against Firebird database servers to identify valid logins.
  • FTP Authentication Attacks - Tests combinations of usernames and passwords against FTP servers using standard and encrypted connections.
  • GUI Attack Management - Enables configuration and execution of parallelized password attacks via a graphical interface.
  • HTTP Authentication Attacks - Performs parallelized password attacks against web servers using Basic and Digest authentication.
  • IMAP Authentication Attacks - Tests username and password combinations against IMAP servers using LOGIN, PLAIN, and CRAM-MD5 mechanisms.
  • LDAP Authentication Attacks - Verifies username and password combinations against directory servers using multiple LDAP authentication mechanisms.
  • MSSQL Authentication Attacks - Authenticates against Microsoft SQL Server instances by testing combinations of usernames and passwords.
  • Oracle Listener Attacks - Tests passwords against Oracle database listeners using plain and clear authentication modes.
  • Combination Generators - Produces sequential password strings based on defined character sets and length constraints.
  • MongoDB Authentication Attacks - Tests credentials against MongoDB servers by attempting to authenticate and query collections.
  • Oracle Database Authentication Attacks - Authenticates into Oracle databases using provided usernames and passwords via the Oracle Call Interface.
  • Oracle SID Verification - Tests remote Oracle database listeners to determine if a specific System Identifier is valid and active.
  • Authentication Handshake Analysis - Allows building custom modules to interact with network sockets for analyzing authentication handshakes.
  • Network Traffic Proxying - Directs authentication attempts through proxy servers to mask the origin or bypass network restrictions.
  • Credential Enumeration - Discovers valid user accounts on remote services by analyzing server responses during authentication.
  • Traffic Tunneling - Routes outbound authentication requests through intermediate proxy servers to obfuscate the source of the attack.
  • Custom Success Strings - Allows defining specific success or failure substrings to override default heuristics when identifying successful authentication.
  • Cracking Session Persistence - Serializes attack progress and configuration to disk to allow resuming interrupted brute-force operations.
  • NTLM Authentication Strategies - Creates and parses NTLM protocol authentication messages to facilitate remote login attempts.
  • Password Generators - Implements a character-set based generator to produce sequential password candidates for brute-force attacks.
  • HTTP Proxy Attacks - Tests usernames and passwords against HTTP proxy servers using Basic or NTLM authentication.
  • Public Key Authentication - Tests lists of usernames and private key files against remote SSH servers to identify valid pairs.
  • MySQL Authentication Attacks - Identifies valid MySQL database credentials by simulating the protocol greeting and salt exchange process.
  • SSH Authentication - Authenticates into remote SSH servers using parallelized password or keyboard-interactive methods.
  • Security Testing and Auditing - Executes parallelized authentication attacks against multiple servers to identify weak or default credentials.
  • Password Cracking Wordlists - Generates sequences of passwords based on specified lengths and character sets for brute-force attacks.
  • Custom Module Implementations - Provides interfaces and structures for developers to implement custom authentication attack modules for various network protocols.
  • Parallel Test Execution - Tests credentials against remote authentication protocols using parallelized requests to identify valid login combinations.
  • Attack Control Interfaces - Provides a graphical user interface to control and monitor authentication attacks in real-time.
  • Session Restoration - Resumes previously interrupted attacks by loading saved options and state from a restore file.
  • Brute Force Tools - Parallelized login cracker for various network protocols.
  • Fuzzing Tools - Network login brute-forcer.
  • Authentication and Brute Force - Multi-protocol login brute-forcing and password auditing.
  • Brute Force Tools - Industry-standard network login brute-forcing tool.
  • Credential Brute Forcing - Parallelized login cracker supporting multiple network protocols.
  • Credential Security - A fast network login cracker.
  • Network Security Tools - Online password cracker supporting numerous network protocols.
  • Password Attacks - Parallelized login cracker supporting numerous protocols.

Star history

Star history chart for vanhauser-thc/thc-hydraStar history chart for vanhauser-thc/thc-hydra

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Thc Hydra

Similar open-source projects, ranked by how many features they share with Thc Hydra.
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • lanjelot/patatorlanjelot avatar

    lanjelot/patator

    3,893View on GitHub↗

    Patator is a multi-purpose brute force tool and modular security framework used for testing credentials, discovering network services, and fuzzing network protocols through automated payload delivery. It functions as a credential exhaustion framework and a network protocol fuzzer. The project provides specific utilities for recovering passwords from encrypted ZIP archives, enumerating DNS zones via forward and reverse queries, and identifying valid usernames and passwords across common network protocols. Its broader capabilities include web endpoint fuzzing, network service probing, and user

    Python
    View on GitHub↗3,893
  • lcvvvv/kscanlcvvvv avatar

    lcvvvv/kscan

    4,286View on GitHub↗

    kscan is a network security scanner and service fingerprinter used to discover active hosts and open ports. It functions as a network protocol analyzer and internal network mapper to identify reachable gateways and analyze the network surface area of target environments. The tool integrates external asset discovery by retrieving target hosts through external intelligence services and verifying their availability. It also operates as a credential brute force tool, testing authentication strength across multiple protocols using automated username and password dictionaries. The project covers n

    Go
    View on GitHub↗4,286
  • hackerschoice/thc-tips-tricks-hacks-cheat-sheethackerschoice avatar

    hackerschoice/thc-tips-tricks-hacks-cheat-sheet

    3,853View on GitHub↗

    This project is a comprehensive command-line reference and toolkit designed for Linux system administration and network security assessment. It provides a collection of technical snippets and operational guides focused on managing remote environments, orchestrating shell sessions, and executing administrative tasks through native terminal utilities. The repository distinguishes itself by offering specialized techniques for stealthy operations and infrastructure manipulation. It covers methods for establishing encrypted tunnels to bypass firewalls, obfuscating process identities and command hi

    Shell
    View on GitHub↗3,853
See all 30 alternatives to Thc Hydra→

Frequently asked questions

What does vanhauser-thc/thc-hydra do?

Hydra is a network login password cracker and authentication tester designed to identify valid usernames and passwords through automated brute-force and dictionary attacks. It serves as a multi-protocol authentication tester capable of verifying credentials across a wide range of remote network services, including SSH, SMB, FTP, and various database listeners.

What are the main features of vanhauser-thc/thc-hydra?

The main features of vanhauser-thc/thc-hydra are: Credential Brute-Forcing, Remote Protocol, Parallel Execution, Pluggable Transport Layers, Multi-Protocol Gateways, Authentication Response Heuristics, Credential Validation Logic, Multi-Protocol Authentication Testing.

What are some open-source alternatives to vanhauser-thc/thc-hydra?

Open-source alternatives to vanhauser-thc/thc-hydra include: jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… lanjelot/patator — Patator is a multi-purpose brute force tool and modular security framework used for testing credentials, discovering… lcvvvv/kscan — kscan is a network security scanner and service fingerprinter used to discover active hosts and open ports. It… hackerschoice/thc-tips-tricks-hacks-cheat-sheet — This project is a comprehensive command-line reference and toolkit designed for Linux system administration and… binance/binance-spot-api-docs — This project provides technical documentation and reference guides for spot trading, including specifications for… thomhurst/tunit — TUnit is a comprehensive C# testing framework, mocking library, and fluent assertion tool. It utilizes source…