
brutus
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

A tool for automating cracking methodologies through Hashcat from the TrustedSec team.

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+…

Python utility that scrapes PDFs to generate targeted wordlists for brute force, forced browsing, and dictionary attacks, with word frequency,…

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Browser-based password cracking toolkit with hash lookup, wordlist generation, rule-based attack simulation, and client-side hash cracking for…

8-14 character Hashcat masks based on analysis of 3.2 million NTLM hashes cracked while pentesting

Modern tactical exploitation toolkit.

Windows绕过EDR实现DumpHash

A web front-end for password cracking and analytics

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Generate wordlists using pattern logic and expressions.

A C# tool to output crackable DPAPI hashes from user MasterKeys

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…