# evilsocket/legba

The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator.  🥷

Repository: https://github.com/evilsocket/legba
Canonical: https://ross.abutalabs.com/products/legba
Homepage: https://legba.evilsocket.net/
Language: Rust
License: NOASSERTION
License Family: other
Last push: 2026-08-14T22:04:22+00:00

## Health v2 (maintenance only)
Score: 84/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 72, longevity 74
- inputs: {"age_days": 1045, "days_push": 19, "days_rel": 106, "gap_med": 50, "n_releases_24m": 6}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1934, forks 114 (observed 2026-08-28T04:05:56.401992+00:00)

## What it is
Legba is a fast, multiprotocol credentials bruteforcer, password sprayer, and enumerator written in Rust on top of the Tokio async runtime. It supports many protocols (HTTP, SSH, FTP, SMTP, RDP, VNC, SQL/NoSQL databases, LDAP, Kerberos, and more) and offers a REST API, MCP server, and YAML recipe system.

## Use cases
- brute-force SSH passwords against a server
- password spray an HTTP login form
- enumerate valid credentials on FTP or SMTP
- crack RDP or VNC logins during a pentest
- test database credentials on MySQL or MSSQL
- resume an interrupted credential scanning session
- integrate credential brute-forcing into an AI agent via MCP

## When to choose
- you need a fast modern replacement for THC-Hydra, Medusa, Ncrack, or Patator
- you want a single static binary with no native dependencies
- you need broad multiprotocol coverage with async concurrency
- you want rate limiting, jitter, and session resume for stealthy scans
- you want REST API or MCP integration for automation

## When to avoid
- you need a niche protocol legba does not yet implement
- you only need a GUI-based password cracking tool
- you are looking for offline hash cracking rather than online credential attacks
- you require a tool with a long-established audit history for compliance reasons

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, cli, http-client, auth
- domain: security, penetration-testing, developer-tools
- platform: windows, cli, rust
- tags: bruteforce, password-spraying, credential-enumeration, wordlist, multiprotocol, tokio, mcp-server, rest-api, command-line, linux, macos, docker

## Member repositories
- evilsocket/legba (main) score 84

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:56.401992+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:08:29.494618+00:00, confidence not recorded.
  - readme: https://github.com/evilsocket/legba (fetched 2026-08-28T04:05:56.401992+00:00, sha e19434484548)
  - homepage: https://legba.evilsocket.net/ (fetched 2026-08-29T10:47:54.161392+00:00, sha 133b29d2ff9f)
  - site_page: https://legba.evilsocket.net/install (fetched 2026-08-29T10:47:54.164706+00:00, sha 3dddff7d216e)
  - registry_crates: https://crates.io/api/v1/crates/legba (fetched 2026-08-29T10:47:54.168566+00:00, sha 54931a6a3870)
  - site_page: https://legba.evilsocket.net/faq (fetched 2026-08-29T10:47:54.166530+00:00, sha 1930e27c203a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
