Passwords & Credentials
1. John the Ripper Classic password hash cracker supporting multiple algorithms (DES, MD5, bcrypt, NTLM) with dictionary, brute-force, and incremental modes.
2. Hashcat High-performance GPU-accelerated password recovery tool. Supports 300 hash types, multiple attack modes (dictionary, mask, hybrid, rule-based), and distributed cracking.
3. Medusa Parallel network authentication brute-forcer. Supports SSH, FTP, HTTP, SMB, RDP, and more designed for speed and reliability across multiple targets.
4. Crunch Custom wordlist generator. Create dictionaries based on character sets, patterns, and length ranges. Ideal for targeted brute-force attacks.
5. CeWL Website content scraper that builds custom wordlists by crawling a target site. Perfect for generating context-aware password dictionaries.
6. RockYou.txt Legendary leaked password database (~14M entries). Still one of the most effective starting points for dictionary attacks.
7. SecLists Massive curated collection of wordlists for fuzzing, brute-forcing, and reconnaissance: usernames, passwords, URLs, payloads, and more.
8. Mimikatz Post-exploitation tool for extracting credentials from Windows: LSASS memory, SAM database, Kerberos tickets, and DPAPI secrets.
9. LaZagne Local credential recovery tool. Retrieves passwords from browsers, Wi-Fi configs, Git, databases, and dozens of other applications.
10. Responder LLMNR/NBT-NS/mDNS poisoner. Captures NTLM hashes from network broadcast requests essential for internal network assessments.
11. Credential Ninja Windows credential harvesting tool. Extracts saved passwords, API keys, and tokens from local storage and application configs.
#Password #Bruteforce #Tools
#InfoSec #CyberSecurity #EthicalHacking #Pentesting #RedTeam #CredentialHarvesting #SecurityTools #MrRobot #CyberSec #OffensiveSecurity