
brutus v1.11.0
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
Brutus
"Et tu, Brute?" — The last words before credentials fall.
Modern credential testing tool in pure Go
Installation • Quick Start • Pipeline • Protocols • Enumeration • Proxy • Library
Overview
Brutus is a multi-protocol authentication testing tool designed to address a critical gap in offensive security tooling: efficient credential validation across diverse network services. While HTTP-focused tools are abundant, penetration testers and red team operators frequently encounter databases, SSH, SMB, and other network services that require purpose-built authentication testing capabilities.
Built in Go as a single binary with zero external dependencies, Brutus integrates seamlessly with Nerva for automated service discovery, enabling operators to rapidly identify and test authentication vectors across entire network ranges.
Key features:
- Zero dependencies: Single binary, cross-platform (Linux, Windows, macOS)
- 27 protocols: SSH, RDP, MySQL, PostgreSQL, MSSQL, Oracle, Redis, SMB, LDAP, WinRM, SNMP, HTTP Basic Auth, and more
- SOCKS5 proxy support: Route all traffic through a SOCKS5 proxy with
--proxy - Aggressiveness modes:
--mode cautious|default|aggressivefor tuning coverage vs. safety - Pipeline integration: Native support for Nerva, naabu, nmap, and masscan workflows
- Embedded bad keys: Built-in collection of known SSH keys (Vagrant, F5, ExaGrid, etc.)
- Account enumeration: account-existence oracle enumeration, Kerberos user enumeration, email generation, Microsoft Teams/Entra ID device code auth
- Go library: Import directly into your security automation tools
- Production ready: Rate limiting, connection pooling, and comprehensive error handling
Why Brutus?
Traditional tools like THC Hydra have served the security community well, but they come with significant friction: complex dependency chains, platform-specific compilation issues, and no native integration with modern reconnaissance workflows.
Brutus is purpose-built for modern offensive security:
-
True zero-dependency deployment: Download a single binary and run. No
libssh-dev, nolibmysqlclient-dev, no compilation errors. Works identically on Linux, macOS, and Windows. -
Native pipeline integration: Brutus speaks JSON and integrates directly with Nerva, naabu, nmap, and masscan. Pipe discovered services straight into credential testing without format conversion or scripting.
-
Embedded intelligence: Known SSH bad keys (Vagrant, F5 BIG-IP, ExaGrid, etc.) are compiled into the binary. Use
brutus badkeysto test them against SSH targets. -
Library-first design: Import Brutus directly into your Go security tools. Build custom automation without shelling out to external processes.
# Full network credential audit in one pipeline (JSON mode)
naabu -host 10.0.0.0/24 -p 22,3306,5432,6379 -silent | nerva --json | brutus creds --json
# Or use Nerva's default URI output — no --json flags needed
naabu -host 10.0.0.0/24 -p 22,3306,5432,6379 -silent | nerva | brutus creds
Use Cases
Penetration Testing
- Validate discovered credentials across multiple services during internal assessments
- Test password reuse patterns across database and file share services
- Identify default credentials on newly deployed infrastructure
Red Team Operations
- Rapid credential validation after password dumps or phishing campaigns
- Test lateral movement opportunities across network services
- Validate compromised credentials across heterogeneous environments
Private Key Spraying
Found a private key on a compromised system? Spray it across the network to find where else it grants access:
# Discover SSH services and spray a found private key
naabu -host 10.0.0.0/24 -p 22 -silent | \
nerva --json | \
brutus creds -u root,admin,ubuntu,deploy -k /path/to/found_key --json
This pipeline discovers all SSH services, identifies them with Nerva, and tests the compromised key against common usernames—revealing lateral movement opportunities in seconds.
Web Admin Panel Testing
Discover HTTP services and test credentials using AI-powered detection or manual credential lists:
# AI-powered: auto-detect devices and suggest default credentials
naabu -host 10.0.0.0/24 -p 80,443,3000,8080,9090 -silent | \
nerva --json | \
brutus web --experimental-ai --json
# Manual: test specific credentials against web panels
naabu -host 10.0.0.0/24 -p 80,443,8080 -silent | \
nerva --json | \
brutus web -c "admin:admin,root:password" --json
# Default wordlist: test common credentials without AI or -c
naabu -host 10.0.0.0/24 -p 80,443,8080 -silent | \
nerva --json | \
brutus web --json
Security Validation
- Test default credentials on newly deployed services
- Validate password policy enforcement across platforms
- Generate audit trails for compliance and security assessments
Installation
Pre-built Binaries (Recommended)
Download from GitHub Releases:
# Linux (amd64)
curl -L https://github.com/praetorian-inc/brutus/releases/latest/download/brutus-linux-amd64.tar.gz | tar xz
sudo mv brutus /usr/local/bin/
# macOS (Apple Silicon)
curl -L https://github.com/praetorian-inc/brutus/releases/latest/download/brutus-darwin-arm64.tar.gz | tar xz
sudo mv brutus /usr/local/bin/
# macOS (Intel)
curl -L https://github.com/praetorian-inc/brutus/releases/latest/download/brutus-darwin-amd64.tar.gz | tar xz
sudo mv brutus /usr/local/bin/
# Windows (PowerShell)
Invoke-WebRequest -Uri https://github.com/praetorian-inc/brutus/releases/latest/download/brutus-windows-amd64.zip -OutFile brutus.zip
Expand-Archive -Path brutus.zip -DestinationPath .
Remove-Item brutus.zip
Go Install
go install github.com/praetorian-inc/brutus/cmd/brutus@latest
Quick Start
Subcommands
Brutus organizes its functionality into six focused subcommands:
brutus creds # Non-HTTP credential auditing (SSH, databases, SMB, etc.)
brutus web # HTTP/web panel auditing (Basic Auth, form login, AI-powered)
brutus snmp # SNMP community string testing
brutus badkeys # Known weak/compromised SSH key testing
brutus logon # Windows logon-screen backdoor detection (sticky keys, utilman)
brutus enum # Account enumeration (account-existence oracles, Kerberos, Teams auth, email generation)
Each subcommand has aliases for discoverability:
| Subcommand | Aliases |
|---|---|
creds | services, defaults, credentials |
web | http, panels |
snmp | community |
badkeys | keys, ssh-keys, badkey |
logon | stickykeys, sticky-keys, utilman, sethc, winlogon, accessibility |
enum | (none) |
# Test SSH credentials
brutus creds --target 192.168.1.100:22 --protocol ssh -u root -p toor
# Test HTTP web panel with AI credential detection
brutus web --target 192.168.1.1:80 --experimental-ai
# Test HTTP web panel with manual credentials
brutus web --target 192.168.1.1:80 -c "admin:admin,root:toor"