Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
spraycharles — Low and slow password spraying tool, designed to spray on an interval over a long period of time | Kitploit
Tools/GitHubGitHub/tw1sm/spraycharles
Password CrackingPassword AttacksWeb SecurityPenetration TestingAuthentication
GitHubtw1sm/spraycharles

spraycharles

Low and slow password spraying tool, designed to spray on an interval over a long period of time

View Repository
22337138 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Spraycharles

hey, yo I'm feeling like spraycharles - Chiddy Bang

Python PyPi

Low and slow password spraying tool, designed to spray on an interval over a long period of time.

Includes spraying plugins for Office365, OWA, EWS, Okta, ADFS, Cisco SSL VPN, Citrix Netscaler, Sonciwall, NTLM over HTTP, and SMB.

Associated blog post by @sprocket_ed covering NTLM over HTTP, Exchange Web Services and Spraycharles.

What is this tool?

Spraycharles is a relatively simple password sprayer, designed at a time when there weren't many publicly available tools enabling password spraying to be a non-manual process over the course of a penetration test. Maybe the best feature of Spraycharles is the ability to setup a long running spray using -a/--attempts and -i/--interval, and let it run over the couse of several days, while periodically checking on it. If you have a one-off service or something unique to spray, it's also very easy to template a new module and start spraying.

What is this tool not?

Spraycharles was not initially designed with modern authentication/cloud providers in mind. If you're looking for more advanced features, you may want to check out tools such as CredMaster or TeamFiltration Spraycharles was not designed to be fast - it is single threaded and geared towards more of a volume/time approach.

Install

Spraycharles can be installed with pip3 install spraycharles or by cloning this repository and running pip3 install .

[!TIP] This will register the spraycharles, and sc for short, aliases in your path. Log and output files are stored in ~/.spraycharles. An alternative output location can be specified with a CLI flag.

Using Docker

Execute the following commands to build the Spraycharles Docker container:

git clone https://github.com/Tw1sm/spraycharles
cd spraycharles/extras
docker build . -t spraycharles

Execute the following command to use the Spraycharles Docker container:

docker run -it -v ~/.spraycharles:/root/.spraycharles spraycharles -h

You may need to specify additional volumes based on where username a password lists are being stored.

NixOS

For Nix or NixOS users is a package available. Keep in mind that the latest releases might only be present in the unstable channel.

nix-env -iA nixos.spraycharles

Usage

The spray subcommand:

 Usage: spraycharles spray [OPTIONS] COMMAND [ARGS]...

 Low and slow password spraying
Download Tool