# vanhauser-thc/thc-hydra

hydra

Repository: https://github.com/vanhauser-thc/thc-hydra
Canonical: https://ross.abutalabs.com/products/thc-hydra
Language: C
License: AGPL-3.0
License Family: copyleft
Topics: penetration-testing, password-cracker, network-security, hydra, thc, pentesting, pentest, pentest-tool, brute-force, brute-force-passwords, bruteforce-attacks, brute-force-attacks, bruteforcing, bruteforcer, bruteforce, password-cracking
Last push: 2026-07-30T10:11:35+00:00

## Health v2 (maintenance only)
Score: 80/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 95, release rhythm 50, longevity 100
- inputs: {"age_days": 4514, "days_push": 34, "days_rel": 122, "gap_med": 242, "n_releases_24m": 2}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 12200, forks 2643 (observed 2026-08-28T04:10:52.006123+00:00)

## What it is
THC-Hydra is a parallelized network login cracker supporting dozens of protocols (SSH, FTP, HTTP forms, SMB, RDP, databases, and more). It is a command-line proof-of-concept tool for security researchers and penetration testers to demonstrate weak password security.

## Use cases
- brute force ssh passwords
- crack login credentials over http forms
- test password strength on ftp servers
- audit network services for weak passwords
- pentest rdp and smb authentication
- dictionary attack against mysql or postgres logins

## When to choose
- you need to test many different network protocols from one tool
- you want fast parallelized brute-force login attempts
- you are a penetration tester or security researcher doing authorized audits

## When to avoid
- you need a GUI-driven password auditing tool
- you want offline password hash cracking rather than online login attacks
- your use is not authorized by the system owner

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, security, networking
- domain: security, penetration-testing, networking
- platform: windows, bsd, cli
- tags: password-cracking, brute-force, login-hacker, thc, hydra, parallelized-attacks, linux, macos, docker

## Member repositories
- vanhauser-thc/thc-hydra (main) score 80

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:52.006123+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:14:16.764919+00:00, confidence not recorded.
  - readme: https://github.com/vanhauser-thc/thc-hydra (fetched 2026-08-28T04:10:52.006123+00:00, sha af3d6f30c245)
- Data as of 2026-08-30T08:39:29.467469+00:00.
