blacklanternsecurity/TREVORspray
TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more! observed · 2026-08-28
Health v2 · maintenance only
70/100
- Activity 83
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2187
- days_rel: n/a
- days_push: 104
- n_releases_24m: 0
Adoption not part of the score
1379 stars · 179 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
TREVORspray is a modular password spraying tool with threading, SSH/subnet proxy rotation, and loot modules targeting identity providers like Office 365, ADFS, OWA, Okta, and Cisco AnyConnect. It also performs domain recon and user enumeration, and can attempt MFA bypass via legacy protocols like IMAP and SMTP.
Use cases
- spray passwords against office 365 accounts
- test for weak passwords across a user list
- rotate source IPs through ssh proxies while spraying
- enumerate valid users in an azure tenant
- check if accounts have mfa enabled or are locked
- bypass o365 mfa via imap or smtp
- recon a domain's mx records and federation config
When to choose
- you need a threaded password sprayer with proxy rotation for cloud identity providers
- you want automatic resume of interrupted sprays and lockout-delay handling
- you need recon and user enumeration alongside credential spraying
- you want to test legacy protocol MFA bypasses on compromised accounts
When to avoid
- you need a general-purpose brute-forcer for arbitrary web login forms
- you lack authorization to test the target systems
- you need a GUI-based credential testing tool
- the target uses an identity provider without a supported module and you cannot write one
Facets
cli-tool · maturity active
security penetration-testing cli http-client security penetration-testing python cli windows cross-platform password-spraying credential-stuffing office365 oauth proxy-rotation red-team mfa-bypass user-enumeration linux macos
2 sources
- readme: https://github.com/blacklanternsecurity/TREVORspray · fetched 2026-08-28 · 6e8cf5939de7
- registry_pypi: https://pypi.org/pypi/trevorspray/json · fetched 2026-08-29 · 7ae80db539a2
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| blacklanternsecurity/TREVORspray | main | 70 |
For agents
markdown · JSON · MCP: product_card(name="blacklanternsecurity/TREVORspray")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem