Ross ROSS = Recommend OSS · open-source software intelligence for agents

knavesec/CredMaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling observed · 2026-08-28

github.com/knavesec/CredMaster · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

38/100

  • Activity 12
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2168
  • days_rel: n/a
  • days_push: 532
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1290 stars · 173 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

CredMaster is a Python CLI tool for password spraying and brute-force attacks that rotates the source IP address on every authentication attempt using dynamically generated FireProx AWS passthrough proxies. It includes plugins for services like OWA, EWS, ADFS, MSOL, and Azure endpoints, plus lockout evasion and notification features.

Use cases

  • spray passwords against O365 or Azure AD without getting IP-blocked
  • brute force OWA or EWS logins during a pentest
  • evade account lockout policies with timed spraying
  • rotate IPs per authentication attempt via AWS proxies
  • enumerate valid Office365 users without authenticating
  • get notified on Slack or Discord when valid credentials are found

When to choose

  • you need evasive password spraying with per-request IP rotation
  • you're doing authorized red-team or pentest work against Microsoft auth endpoints
  • you want lockout policy evasion and timed spray scheduling built in

When to avoid

  • you have no AWS account or don't want to incur Lambda/API Gateway costs
  • you need a general-purpose web brute forcer rather than auth-spray plugins
  • your use is unauthorized - this is for authorized security testing only

Facets

cli-tool · maturity active

security http-client cli penetration-testing security python cli cloud password-spraying brute-force fireprox aws-proxy red-team credential-stuffing evasion

1 source

Member repositories

RepositoryRoleHealth v2
knavesec/CredMastermain38

For agents

markdown · JSON · MCP: product_card(name="knavesec/CredMaster")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem