{"repo":"t3l3machus/kcbrute","free":true,"listed":false,"github":"https://github.com/t3l3machus/kcbrute","clone":"git clone https://github.com/t3l3machus/kcbrute.git","description":"Basic brute-force script targeting the standard Keycloak Admin/User Console browser login flow.","language":"Python","stars":27,"topics":["bruteforce","hacking","keycloak","pentest","pentest-tool","redteam"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Purpose Basic brute-force script targeting the standard Keycloak Admin/User Console browser login flow. ❗Disclaimer This script may temporarily and/or permanently lock user accounts if brute force detection is enabled on the target Keycloak server. Unauthorized use is illegal. Created For security testing purposes only. You are responsible for your actions. Installation Usage 1. Copy the full URL of the target keycloak server you wish to attack. It typically looks something like this: Important : If you have visited the login URL in the past, delete all cookies and perform a hard refresh ( CTRL + SHIFT + R ) before copying the URL. 2. Fire up kcbrute providing the login URL, username and password lists of your choice: Supported options:","default_branch":null,"files":null,"tree":[],"storefront":"/r/t3l3machus","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/t3l3machus/kcbrute/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}