Ross ROSS = Recommend OSS · open-source software intelligence for agents

x90skysn3k/brutespray

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols. observed · 2026-08-28

github.com/x90skysn3k/brutespray · homepage · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 38.0
  • age_days: 3437
  • days_rel: 8
  • days_push: 8
  • n_releases_24m: 11

Full methodology

Adoption not part of the score

2525 stars · 437 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Brutespray is a fast, multi-protocol credential brute-forcing tool written in Go. It parses scan output from Nmap, Nessus, Nexpose, JSON, and lists to automatically test default and custom credentials across 40+ protocols in parallel.

Use cases

  • brute-force credentials on services found in nmap scan output
  • test default passwords across ssh, ftp, rdp, smb, mysql and other protocols
  • password spray a cidr range with lockout-aware delays
  • parse nessus or nexpose reports and automatically attempt logins
  • resume an interrupted credential attack from a checkpoint
  • run brute-force attempts through a socks5 proxy
  • generate metasploit rc or netexec scripts from successful findings

When to choose

  • you need to turn network scan output into automated credential testing across many protocols
  • you want a single fast Go binary with embedded wordlists and no external dependencies
  • you need lockout-aware password spraying, proxy support, or resume capability
  • you want an interactive terminal UI to monitor and pause brute-force sessions

When to avoid

  • you need a general-purpose password cracking tool for offline hashes like hashcat
  • you only need a simple single-protocol brute-forcer like hydra or medusa
  • you require a GUI-based penetration testing workflow
  • you are looking for a defensive auditing tool rather than offensive testing

Facets

cli-tool · maturity active

security penetration-testing cli terminal-ui security penetration-testing networking windows go cli brute-force credential-testing password-spraying nmap nessus offensive-security red-team socks5-proxy command-line linux macos docker

4 sources

Member repositories

RepositoryRoleHealth v2
x90skysn3k/brutespraymain95

For agents

markdown · JSON · MCP: product_card(name="x90skysn3k/brutespray")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem