# kaonashi-passwords/Kaonashi

Wordlist, rules and masks from Kaonashi project (RootedCON 2019)

Repository: https://github.com/kaonashi-passwords/Kaonashi
Canonical: https://ross.abutalabs.com/products/kaonashi
License: GPL-3.0
License Family: copyleft
Topics: wordlist, password, password-strength, password-safety, dictionary-attack, dictionary, password-cracking, hashcat, masks, rules, password-leak, wpa, rootedcon, kaonashi14m, kaonashiwpa, kaonashi
Last push: 2022-04-22T09:03:48+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2679, "days_push": 1594, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1099, forks 117 (observed 2026-08-28T04:03:34.985461+00:00)

## What it is
Kaonashi is a collection of password wordlists, hashcat rules, and masks derived from large-scale analysis of billions of real leaked passwords, presented at RootedCON 2019. It provides sorted wordlists (Kaonashi, Kaonashi14M, KaonashiWPA100M) for use in password auditing and cracking tools like hashcat.

## Use cases
- download a large sorted password wordlist for hashcat
- crack WPA handshakes with a common-password list
- audit password strength against real leaked passwords
- find hashcat rules and masks derived from real password patterns
- build a custom top-n wordlist from real password leaks

## When to choose
- you need empirically sorted wordlists from real password leaks for hashcat
- you are doing authorized password auditing or WPA cracking
- you want rules and masks based on statistical analysis of billions of passwords

## When to avoid
- you need an actively updated wordlist - the last release was 2022
- you want a cracking tool itself rather than data files
- you cannot use external Mega/torrent downloads for the large wordlists

## Facets
- artifact type: dataset
- maturity: maintenance
- function: security, penetration-testing, data-generation
- domain: security, penetration-testing, privacy
- platform: cross-platform, cli
- tags: wordlist, password-cracking, hashcat, dictionary-attack, masks, rules, wpa

## Member repositories
- kaonashi-passwords/Kaonashi (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:34.985461+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:46:03.608888+00:00, confidence not recorded.
  - readme: https://github.com/kaonashi-passwords/Kaonashi (fetched 2026-08-28T04:03:34.985461+00:00, sha 299b612be542)
- Data as of 2026-08-30T08:39:29.467469+00:00.
