brutespray v2.7.2
New releaseAug 25, 2026Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpos 2026-8-25 20:45:13 Author: kitploit.com(查看原文) 阅读量:8 收藏

New releaseAug 25, 2026

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.

VersiongoreleaserGo Report Card

Created by: Shane Young/@x90sky && Jacob Robles/@shellfail

Inspired by: Leon Johnson/@sho-luv

Description

Brutespray automatically attempts default credentials on discovered services. It takes scan output from Nmap (GNMAP/XML), Nessus, Nexpose, JSON, and lists, then brute-forces credentials across 40+ protocols in parallel. Built in Go with an interactive terminal UI, embedded wordlists, and resume capability.

Quick Install

go install github.com/x90skysn3k/brutespray/v2@latest

Release Binaries | Build from Source | Docker

Quick Start

# From Nmap scan output
brutespray -f nmap.gnmap -u admin -p password

# Target a specific host
brutespray -H ssh://192.168.1.1:22 -u admin -p passlist.txt

# CIDR range
brutespray -H ssh://10.1.1.0/24:22 -u root -p passlist.txt

# Combo credentials
brutespray -H ssh://10.0.0.1:22 -C root:root

See all examples for more usage patterns.

Demo

Features

  • 40+ protocols — SSH, FTP, RDP, SMB, MySQL, PostgreSQL, Redis, LDAP, WinRM, and more
  • Module parameters — Per-module settings via -m KEY:VALUE (auth type, target path, NTLM domain, etc.)
  • Multi-auth support — HTTP Digest/NTLM auto-detection, SMTP PLAIN/LOGIN, IMAP/POP3 SASL, SMB pass-the-hash
  • Interactive TUI — Tabbed views, live settings, pause/resume hosts (details)
  • Multiple input formats — Nmap GNMAP/XML, Nessus, Nexpose, JSON, lists (details)
  • Password spray mode — Lockout-aware spraying with configurable delays (details)
  • SOCKS5 proxy — Full proxy support with authentication (details)
  • Resume & checkpoint — Interrupt with Ctrl+C, resume later (details)
  • Embedded wordlists — Layered manifest system compiled into the binary (details)
  • Summary reports — JSON, CSV, Metasploit RC, NetExec scripts (details)
  • Performance tuning — Dynamic threading, circuit breaker, rate limiting (details)
  • YAML config files — Per-engagement settings (details)

How Brutespray Compares

Featurebrutesprayhydramedusancrackbrutus
Single static binary
Interactive TUI
Checkpoint / resume
Spray mode (lockout-aware)
Per-attempt JSONL output⚠️❌ (success-only)
SOCKS5 + proxy rotation⚠️
Embedded SSH bad-keys (CVE-tagged)
Pipeline stdin (naabu / fingerprintx / masscan)
Pre-auth RDP recon (NLA / sticky-keys)
Nmap gnmap + XML / Nessus / Nexpose import⚠️⚠️ (nmap only)
Per-module params (-m KEY:VAL)partial
Service count4150+341423

Symbols reflect documented behavior at PR time. Competing tools change quickly.

Supported Services

ssh ftp ftps telnet smtp smtp-vrfy imap pop3 mysql postgres mssql mongodb redis vnc snmp smbnt rdp http https vmauthd teamspeak asterisk nntp oracle xmpp ldap ldaps winrm rexec rlogin rsh wrapper

Full details and service-specific notes: docs/services.md

Print discovered services from a scan file with -P -q:

Documentation

GuideDescription
InstallationGo install, release binaries, build from source, Docker
UsageCLI flags, config files, input formats
ServicesAll 40+ protocols with ports, status, and notes
ExamplesCommon usage patterns and recipes
Interactive TUIKeybindings, tabs, live settings
AdvancedSpray mode, proxy, resume, performance tuning
WordlistsManifest system, layers, overrides, customization
Output & ReportingSummary reports, Metasploit/NetExec integration

Star History

Star History Chart

Read more

Categories


文章来源: https://kitploit.com/en/posts/github-x90skysn3k-brutespray-v272
如有侵权请联系:admin#unsafe.sh