{"adoption": {"forks": 62, "observed_at": "2026-08-28T04:03:49.937034+00:00", "stars": 1164}, "canonical_url": "https://ross.abutalabs.com/products/pamspy", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Credentials Dumper for Linux using eBPF", "domain": ["security", "penetration-testing", "operating-systems"], "enriched": true, "function": ["security", "monitoring", "tracing"], "health_score": 28, "homepage": null, "language": "C", "license": "Apache-2.0", "license_family": "permissive", "maturity": "active", "member_repos": ["citronneur/pamspy"], "name": "citronneur/pamspy", "platform": ["cli"], "pushed_at": "2024-09-09T13:19:12+00:00", "repo": "citronneur/pamspy", "stars": 1164, "tags": ["ebpf", "credentials-dumper", "pam", "red-team", "offensive-security", "linux"], "topics": [], "urls": [], "use_cases": ["dump linux passwords with ebpf", "capture sudo and ssh credentials on a compromised host", "red team credential harvesting on linux", "hook pam authentication to intercept passwords", "alternative to 3snake for credential dumping", "monitor pam authentication events in real time"], "what_it_is": "pamspy is a Linux credentials dumper that uses eBPF to hook the pam_get_authtok function in libpam.so, capturing passwords from processes like sudo, sshd, and passwd. It is distributed as a static binary with no dependencies and can run in daemon mode writing captured credentials to a file.", "when_to_avoid": ["you are on a system without eBPF support or without root privileges", "you need a defensive auditing tool rather than credential capture", "your target uses authentication not routed through PAM"], "when_to_choose": ["you need to capture PAM-based credentials on a Linux host where you have root access", "you want a dependency-free static binary for red team operations", "you prefer eBPF-based hooking over LD_PRELOAD or ptrace techniques"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/pamspy", "repo": "citronneur/pamspy", "role": "main", "score": 23}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:49.937034+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:29:39.904518+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c2bd6f53b60b30cd00098afb9ae7cc46a84feb8c811c84fcd2c0cfdaf89c5edb", "fetched_at": "2026-08-28T04:03:49.937034+00:00", "kind": "readme", "missing": false, "url": "https://github.com/citronneur/pamspy"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1524, "days_push": 723, "days_rel": 723, "gap_med": null, "n_releases_24m": 1}, "score": 23, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}