Ross ROSS = Recommend OSS · open-source software intelligence for agents

galkan/crowbar

Crowbar is brute forcing tool that can be used during penetration tests. It is developed to support protocols that are not currently supported by thc-hydra and other popular brute forcing tools. observed · 2026-08-28

github.com/galkan/crowbar · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4355
  • days_rel: n/a
  • days_push: 988
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1531 stars · 320 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Crowbar is a Python-based brute forcing tool for penetration testing that supports protocols often missing from other brute force tools, such as SSH private key authentication, OpenVPN, RDP with NLA, and VNC key authentication. It is a command-line utility that can scan target ranges with nmap before attempting credential attacks.

Use cases

  • brute force SSH servers using obtained private keys
  • crack RDP passwords with NLA support
  • brute force OpenVPN credentials
  • attack VNC servers with key authentication
  • discover open ports on an IP range before brute forcing
  • find valid logins during a penetration test

When to choose

  • you need to brute force protocols like sshkey, openvpn, rdp, or vnckey that thc-hydra does not support
  • you have private keys from a pentest and want to test them against other SSH servers
  • you work in Kali Linux and want an apt-installable brute forcing tool

When to avoid

  • you need brute forcing for common protocols like HTTP forms or FTP better served by thc-hydra
  • you need a GUI-based password auditing tool
  • you require ongoing feature development or frequent updates

Facets

cli-tool · maturity maintenance

penetration-testing security cli security penetration-testing python cli brute-force ssh-key rdp openvpn vnc password-cracking kali-linux command-line linux

1 source

Member repositories

RepositoryRoleHealth v2
galkan/crowbarmain23

For agents

markdown · JSON · MCP: product_card(name="galkan/crowbar")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem