awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

28 个仓库

Awesome GitHub RepositoriesPassword Attacks

Utilities for cracking credentials and generating wordlists.

Explore 28 awesome GitHub repositories matching part of an awesome list · Password Attacks. Refine with filters or upvote what's useful.

Awesome Password Attacks GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • hashcat/hashcathashcat 的头像

    hashcat/hashcat

    26,200在 GitHub 上查看↗

    Hashcat is a high-performance hash cracking software and OpenCL compute application used to recover plain-text passwords from hashed data. It functions as a GPU-accelerated recovery tool and distributed password cracker, leveraging CPUs and GPUs to perform intensive cryptographic computations. The system differentiates itself through a distributed cracking workflow that coordinates tasks across multiple machines via an overlay network to share computational load. It further optimizes recovery speed using Markov chain keyspace optimization to prioritize the most likely password candidates. Th

    Advanced, high-performance tool for password recovery.

    C
    在 GitHub 上查看↗26,200
  • gentilkiwi/mimikatzgentilkiwi 的头像

    gentilkiwi/mimikatz

    21,630在 GitHub 上查看↗

    Mimikatz is a security research suite designed for auditing Windows authentication and managing system security configurations. It provides a comprehensive framework for extracting sensitive credentials, manipulating process privileges, and managing digital identity assets directly from system memory or offline memory dumps. The project distinguishes itself through advanced system-level exploitation techniques, including runtime process injection, API hooking, and the ability to bypass cryptographic export restrictions. It features a specialized toolkit for Kerberos protocol operations, allow

    Advanced tool for credential dumping and Windows security manipulation.

    C
    在 GitHub 上查看↗21,630
  • magnumripper/johntherippermagnumripper 的头像

    magnumripper/JohnTheRipper

    13,274在 GitHub 上查看↗

    JohnTheRipper is a multi-platform offline password recovery tool designed to detect and crack hundreds of different hash and cipher formats across various operating systems. It functions as a security utility for retrieving lost credentials and performing security audit testing to identify weak passwords within a database of hashes. The project features a custom rule password cracker and a mangling engine that uses a domain-specific language to transform wordlist entries into common password mutation patterns. It provides hardware-accelerated recovery by distributing parallel processing tasks

    High-speed utility for cracking various password hashes.

    C
    在 GitHub 上查看↗13,274
  • openwall/johnopenwall 的头像

    openwall/john

    13,268在 GitHub 上查看↗

    John is a command-line security utility designed for password strength auditing and cryptographic hash recovery. It functions as a professional tool for identifying weak user credentials and recovering access to protected files, archives, and private keys across various operating systems, databases, and applications. The software distinguishes itself through a high-performance architecture that utilizes processor-level vector instructions to perform parallel cryptographic operations. It incorporates a rule-based mutation engine that transforms dictionary words into complex candidates based on

    Fast password cracker for various hash types.

    Cassemblerccracker
    在 GitHub 上查看↗13,268
  • manisso/fsocietyManisso 的头像

    Manisso/fsociety

    12,136在 GitHub 上查看↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Provides utilities for cracking credentials and generating wordlists to recover user passwords.

    Pythonbrute-force-attacksdesktopexploitation
    在 GitHub 上查看↗12,136
  • vanhauser-thc/thc-hydravanhauser-thc 的头像

    vanhauser-thc/thc-hydra

    11,943在 GitHub 上查看↗

    Hydra is a network login password cracker and authentication tester designed to identify valid usernames and passwords through automated brute-force and dictionary attacks. It serves as a multi-protocol authentication tester capable of verifying credentials across a wide range of remote network services, including SSH, SMB, FTP, and various database listeners. The project is distinguished by its ability to execute parallelized password attacks against multiple servers and protocols simultaneously. It features a modular system for implementing diverse network authentication schemes, allowing f

    Tests combinations of usernames and passwords against FTP servers using standard and encrypted connections.

    C
    在 GitHub 上查看↗11,943
  • alessandroz/lazagneAlessandroZ 的头像

    AlessandroZ/LaZagne

    10,867在 GitHub 上查看↗

    LaZagne is a cross-platform credential recovery tool designed to extract passwords and secrets from operating systems, browsers, and applications. It functions as a security utility for retrieving stored credentials from compromised systems during penetration testing. The tool provides capabilities for decrypting domain credentials and extracting sensitive data from system storage, including memory dumps, credential managers, keychains, and password hashes. It recovers stored passwords from common software by accessing plaintext files, APIs, and local databases. The project supports digital

    Credential recovery tool for extracting passwords from local applications.

    Python
    在 GitHub 上查看↗10,867
  • byt3bl33d3r/crackmapexecbyt3bl33d3r 的头像

    byt3bl33d3r/CrackMapExec

    9,144在 GitHub 上查看↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Post-exploitation tool for network credential and configuration auditing.

    Python
    在 GitHub 上查看↗9,144
  • skeeto/endlesshskeeto 的头像

    skeeto/endlessh

    8,477在 GitHub 上查看↗

    Endlessh is an SSH tarpit and network honeypot designed to mitigate automated SSH brute force attacks. It acts as a defensive layer that protects servers by diverting malicious connection attempts into a slow-motion trap. The project implements a tarpit by sending endless, throttled banners to clients, which keeps connections open indefinitely to occupy attacker resources and slow down network scans. The service includes connection rate limiting to prevent system resource exhaustion and provides monitoring through connection activity and diagnostic data logging to system logs. Process manage

    Sends endless slow banners to clients to occupy connections and distract attackers from real servers.

    C
    在 GitHub 上查看↗8,477
  • v1s1t0r1sh3r3/airgeddonv1s1t0r1sh3r3 的头像

    v1s1t0r1sh3r3/airgeddon

    7,797在 GitHub 上查看↗

    airgeddon is a bash-based wireless network audit suite and security toolkit for Linux. It serves as a framework for testing wireless vulnerabilities and verifying network configurations across various encryption standards, including WPA, WEP, and WPS. The project functions as an orchestration layer that integrates a collection of third-party wireless security tools. It features a modular approach to attack vectorization, coordinating tasks such as evil twin simulations with captive portals, WPA handshake interception, and the execution of WPS vulnerability tests. Its capabilities cover a bro

    Recovers network passwords by executing Pixie Dust, brute-force, or known-PIN attacks against WPS implementations.

    Shell
    在 GitHub 上查看↗7,797
  • ihebski/defaultcreds-cheat-sheetihebski 的头像

    ihebski/DefaultCreds-cheat-sheet

    6,409在 GitHub 上查看↗

    DefaultCreds-cheat-sheet is a searchable reference database of default usernames and passwords for thousands of hardware and software products, designed for use during security assessments. It functions as a curated directory that maps vendor products to their known factory-set login credentials, enabling rapid lookup during penetration testing and security preparation workflows. The tool is delivered as a single-file client application with no backend dependencies, serving static content from any web server or local file system for offline use. It stores credential mappings in a flat JSON da

    Reference for common default credentials across various systems.

    Pythonblueteamblueteam-toolsblueteaming
    在 GitHub 上查看↗6,409
  • lgandx/responderlgandx 的头像

    lgandx/Responder

    6,335在 GitHub 上查看↗

    Responder is a network penetration testing tool that intercepts and spoofs link-local name resolution queries, including LLMNR, NBT-NS, and mDNS, to redirect traffic to an attacker-controlled host. It hosts rogue protocol servers for over 15 protocols, capturing authentication credentials during challenge-response handshakes, and stores captured hashes and cleartext credentials in a SQLite database for structured offline analysis. The tool distinguishes itself through its ability to relay captured NTLM authentication challenges to target services for lateral movement without cracking the hash

    Intercepts LDAP and LDAPS authentication attempts, logging both plaintext passwords and NetNTLMv2 hashes.

    Python
    在 GitHub 上查看↗6,335
  • sammwyy/mikumikubeamsammwyy 的头像

    sammwyy/MikuMikuBeam

    5,794在 GitHub 上查看↗

    MikuMikuBeam is a hybrid command-line and web-based tool for launching configurable network stress tests with real-time monitoring and plugin extensibility. It provides a modular pipeline for constructing and executing network attacks, supporting configurable parameters such as target, packet size, duration, and delay. The tool distinguishes itself through a dual-mode configuration interface that allows attack parameters to be set via both a web UI and command-line arguments, with CLI providing colored real-time output. It features isolated client session management where each browser tab spa

    Manages several isolated attack instances running simultaneously from separate browser tabs.

    Goddosddos-attack-toolsddos-attacks
    在 GitHub 上查看↗5,794
  • fluxionnetwork/fluxionFluxionNetwork 的头像

    FluxionNetwork/fluxion

    5,776在 GitHub 上查看↗

    Fluxion is a wireless security auditing framework that tests WPA/WPA2 networks by capturing handshakes and deploying rogue access points with captive portals. It operates by deauthenticating clients from legitimate access points, forcing them to reconnect to a cloned network where a fake authentication page collects the network passphrase. The tool distinguishes itself through a plugin-based attack lifecycle with mandatory hook functions for consistent execution, multilingual metadata scripts that load attack descriptions based on locale, and a handshake verification pipeline that validates c

    Logs the verified password and halts the attack, letting clients reconnect to the legitimate access point.

    HTML
    在 GitHub 上查看↗5,776
  • rootphantomer/blasting_dictionaryrootphantomer 的头像

    rootphantomer/Blasting_dictionary

    5,273在 GitHub 上查看↗

    Blasting Dictionary 提供了一套精选的常用用户名和密码数据集,旨在用于审计身份验证强度和识别易受攻击的账户。它是一个凭据填充(Credential Stuffing)字典和密码攻击词库的集合,用于测试目标服务中是否存在弱密码或默认凭据。 该项目通过提供模拟暴力破解和凭据填充攻击所需的数据集,促进了安全渗透测试和漏洞评估。这些资源可用于评估身份验证系统的安全性,并识别易受未经授权访问的服务。 该工具集涵盖了通过自动化测试进行的凭据审计,并提供攻击词库以识别目标服务上的不安全登录凭据。

    Provides curated dictionaries of strings designed for automated brute force and dictionary attacks.

    Python
    在 GitHub 上查看↗5,273
  • pennyw0rth/netexecPennyw0rth 的头像

    Pennyw0rth/NetExec

    5,274在 GitHub 上查看↗

    NetExec is a framework for concurrent credential spraying and remote command execution across network protocols. It provides input sanitization and command parsing to reduce injection risks, a plugin-based protocol abstraction that dispatches credentials and commands uniformly regardless of transport, and session and token lifecycle management for long-running multi-command operations. Results from concurrent executions are collected and normalized through a result aggregation pipeline. The framework includes a concurrent job scheduler that manages worker threads for parallel execution across

    Network service exploitation tool for credential testing and movement.

    Pythonactive-directoryhackinginfosec
    在 GitHub 上查看↗5,274
  • ullaakut/cameradarUllaakut 的头像

    Ullaakut/cameradar

    5,084在 GitHub 上查看↗

    Cameradar is a network scanning tool designed to discover publicly accessible IP cameras. It identifies active Real Time Streaming Protocol services by scanning IP ranges and using device fingerprints to determine specific hardware models. The tool performs security auditing through dictionary-based probing and brute force attacks to uncover valid streaming paths and authentication credentials. It validates discovered streams by verifying the receipt of real-time transport protocol data packets to eliminate false positives. The system supports a multi-stage discovery pipeline and can export

    Scans targets for open hosts to identify the specific device models providing streaming feeds.

    Gocamerascctvhacking
    在 GitHub 上查看↗5,084
  • rogandawes/p4wnp1RoganDawes 的头像

    RoganDawes/P4wnP1

    4,350在 GitHub 上查看↗

    P4wnP1 is a hardware-based USB HID attack platform and peripheral emulator. It functions as a tool for emulating USB keyboards and mice to execute automated keystroke payloads, as well as a WiFi-enabled remote access tool that provides a wireless bridge for network relay and SSH access. The project is distinguished by its ability to establish covert bidirectional communication channels and remote shells using raw HID reports, specifically to bridge air-gapped systems. It further enables wireless network interception and the routing of network traffic over WiFi to facilitate man-in-the-middle

    Automates credential theft from a locked Windows machine by capturing hashes through network redirection, cracking them, and typing the password to unlock the target.

    Python
    在 GitHub 上查看↗4,350
  • samsesh/socialbox-termuxsamsesh 的头像

    samsesh/SocialBox-Termux

    4,145在 GitHub 上查看↗

    SocialBox-Termux is a credential bruteforce suite and security tool collection designed to run within the Termux Android environment. It functions as an automated account cracker used to test password lists against usernames to discover valid login credentials for social media and email platforms. The toolkit incorporates network traffic masking by routing requests through the Tor network to conceal the origin IP address. It utilizes signature-based rate bypass to mimic legitimate client traffic and avoid automated login blocks. The suite provides capabilities for account validation to verif

    Manages the state of password attacks to allow resuming from the last attempted password.

    Shellandroidbrute-forcebruteforce
    在 GitHub 上查看↗4,145
  • ropnop/kerbruteropnop 的头像

    ropnop/kerbrute

    3,358在 GitHub 上查看↗

    A tool to perform Kerberos pre-auth bruteforcing

    Tool for performing Kerberos pre-authentication brute-forcing.

    Go
    在 GitHub 上查看↗3,358
上一个12下一个
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Password Attacks

探索子标签

  • Credential Capture LoggersTools that record verified passwords and halt attacks, allowing clients to reconnect to the legitimate network. **Distinct from Password Attacks:** Distinct from Password Attacks: focuses on logging successful credential captures and stopping the attack, not cracking or generating passwords.
  • Device-SpecificAutomated password attacks targeting specific hardware or software device authentication. **Distinct from Password Attacks:** Targets a specific device (Adam6500) rather than general password cracking techniques
  • FTP Authentication AttacksCredential cracking targeting File Transfer Protocol servers. **Distinct from Password Attacks:** Focuses on FTP and FTPS authentication, unlike general password attacks.
  • Firebird Database AttacksCredential cracking specifically targeting Firebird database servers. **Distinct from Password Attacks:** Focuses on Firebird database authentication, unlike general password attacks.
  • GUI Attack Management2 个子标签Graphical interfaces for configuring and executing parallelized password attacks. **Distinct from Password Attacks:** Specializes general password attack utilities by adding a graphical management interface.
  • HTTP Authentication AttacksCredential cracking targeting web servers and their authentication mechanisms. **Distinct from Password Attacks:** Focuses on HTTP Basic and Digest auth, unlike general password attacks.
  • ICQ Authentication AttacksCredential cracking targeting the ICQ messaging service. **Distinct from Password Attacks:** Specifically targets ICQ authentication, unlike general password attacks.
  • IMAP Authentication AttacksCredential cracking targeting IMAP mail servers. **Distinct from Password Attacks:** Focuses on IMAP-specific mechanisms like CRAM-MD5, unlike general password attacks.
  • IRC Authentication AttacksCredential cracking targeting Internet Relay Chat servers. **Distinct from Password Attacks:** Specifically targets IRC server authentication, unlike general password attacks.
  • LDAP Authentication AttacksCredential cracking targeting directory servers via LDAP. **Distinct from Password Attacks:** Targets directory-specific LDAP authentication, unlike general password attacks.
  • Lock Screen Credential TheftAutomated credential theft from locked Windows machines by capturing hashes through network redirection, cracking them, and typing the password to unlock the target. **Distinct from Password Attacks:** Distinct from Password Attacks: specifically targets locked Windows machines via network redirection and HID typing, not general password cracking.
  • MSSQL Authentication AttacksCredential cracking targeting Microsoft SQL Server instances. **Distinct from Password Attacks:** Focuses on MSSQL login attempts, unlike general password attacks.
  • Memcached Authentication AttacksCredential cracking targeting Memcached servers. **Distinct from Password Attacks:** Focuses on Memcached SASL authentication, unlike general password attacks.
  • NCP Authentication AttacksCredential cracking targeting Novell Network Core Protocol. **Distinct from Password Attacks:** Focuses on NCP protocol authentication, unlike general password attacks.
  • NNTP Authentication AttacksCredential cracking targeting Network News Transfer Protocol servers. **Distinct from Password Attacks:** Specifically targets NNTP authentication, unlike general password attacks.
  • Network HardwareCredential verification targeting network infrastructure hardware like routers and switches. **Distinct from Password Attacks:** Targets Cisco networking hardware specifically
  • Oracle Listener AttacksCredential cracking targeting Oracle database listeners. **Distinct from Password Attacks:** Focuses on the listener service authentication, unlike general password attacks.
  • Privileged AccessAttempts to crack passwords used for administrative or privileged access modes. **Distinct from Password Attacks:** Targets the 'enable' privileged mode specifically rather than standard user login
  • RTSP Attack Modules1 个子标签Modules for testing credentials against the Real Time Streaming Protocol. **Distinct from Password Attacks:** Specializes password attack utilities to the RTSP protocol specifically.
  • Security Tool Authentication AttacksPassword guessing targeting the authentication interfaces of other security software. **Distinct from Password Attacks:** Targets Cobalt Strike software specifically
  • TeamSpeak Authentication AttacksAutomated credential testing specifically for TeamSpeak servers. **Distinct from Password Attacks:** Specializes general password attacks to the TeamSpeak protocol
  • Telnet Authentication AttacksAutomated credential testing for Telnet services. **Distinct from Password Attacks:** Specific protocol implementation of a password attack
  • VMware Authentication AttacksAutomated credential testing for VMware Authentication Daemons. **Distinct from Password Attacks:** Specializes general password attacks to the VMware protocol
  • VNC Authentication AttacksAutomated credential testing for VNC servers using RFB protocol handshakes. **Distinct from Password Attacks:** Specific protocol implementation of a password attack
  • Version Control SystemCredential testing targeting authentication in version control systems. **Distinct from Password Attacks:** Targets CVS version control specifically
  • VoIP ServiceAutomated password attacks targeting Voice over IP and communication manager services. **Distinct from Password Attacks:** Targets VoIP services like Asterisk specifically
  • WPS AttacksAttacks targeting Wi-Fi Protected Setup (WPS), including Pixie Dust and PIN brute-forcing. **Distinct from Password Attacks:** Focuses specifically on WPS protocol vulnerabilities rather than general password attacks.