{"repo":"x90skysn3k/brutespray","free":true,"listed":false,"github":"https://github.com/x90skysn3k/brutespray","clone":"git clone https://github.com/x90skysn3k/brutespray.git","description":"Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.","language":"Go","stars":2520,"topics":["brute-force-attacks","bruteforce","credential-testing","cybersecurity","ftp","golang","infosec","nessus","network-security","nmap"],"license":"MIT","category":"security-tools","readme_excerpt":"Brutespray Created by: Shane Young/@x90sky && Jacob Robles/@shellfail Inspired by: Leon Johnson/@sho-luv Description Brutespray automatically attempts default credentials on discovered services. It takes scan output from Nmap (GNMAP/XML), Nessus, Nexpose, JSON, and lists, then brute-forces credentials across 40+ protocols in parallel. Built in Go with an interactive terminal UI, embedded wordlists, and resume capability. Quick Install Release Binaries Build from Source Docker Quick Start See all examples for more usage patterns. Demo Features - 40+ protocols — SSH, FTP, RDP, SMB, MySQL, PostgreSQL, Redis, LDAP, WinRM, and more - Module parameters — Per-module settings via -m KEY:VALUE (auth type, target path, NTLM domain, etc.) - Multi-auth support — HTTP Digest/NTLM auto-detection, SMTP PLAIN/LOGIN, IMAP/POP3 SASL, SMB pass-the-hash - Interactive TUI — Tabbed views, live settings, pause/resume hosts (details) - Multiple input formats — Nmap GNMAP/XML, Nessus, Nexpose, JSON, lists (details) - Password spray mode — Lockout-aware spraying with configurable delays (details) - SOCKS5 proxy — Full proxy support with authentication (details) - Resume & checkpoint — Interrupt with Ctrl+C, resume later (details) - Embedded wordlists — Layered manifest system compiled into the binary (details) - Summary reports — JSON, CSV, Metasploit RC, NetExec scripts (details) - Performance tuning — Dynamic threading, circuit breaker, rate limiting (details) - YAML config files — Per-engagement se","default_branch":null,"files":null,"tree":[],"storefront":"/r/x90skysn3k","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/x90skysn3k/brutespray/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}