# blacklanternsecurity/TREVORspray

TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!

Repository: https://github.com/blacklanternsecurity/TREVORspray
Canonical: https://ross.abutalabs.com/products/trevorspray
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: password, spraying, security, hacking, microsoft, passwords, office, 365, exchange, oauth, autodiscover, email, socks, proxy, python, spray, trevor
Last push: 2026-05-21T23:45:37+00:00

## Health v2 (maintenance only)
Score: 70/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 83, release rhythm 35, longevity 100
- inputs: {"age_days": 2187, "days_push": 104, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1379, forks 179 (observed 2026-08-28T04:04:33.768840+00:00)

## What it is
TREVORspray is a modular password spraying tool with threading, SSH/subnet proxy rotation, and loot modules targeting identity providers like Office 365, ADFS, OWA, Okta, and Cisco AnyConnect. It also performs domain recon and user enumeration, and can attempt MFA bypass via legacy protocols like IMAP and SMTP.

## Use cases
- spray passwords against office 365 accounts
- test for weak passwords across a user list
- rotate source IPs through ssh proxies while spraying
- enumerate valid users in an azure tenant
- check if accounts have mfa enabled or are locked
- bypass o365 mfa via imap or smtp
- recon a domain's mx records and federation config

## When to choose
- you need a threaded password sprayer with proxy rotation for cloud identity providers
- you want automatic resume of interrupted sprays and lockout-delay handling
- you need recon and user enumeration alongside credential spraying
- you want to test legacy protocol MFA bypasses on compromised accounts

## When to avoid
- you need a general-purpose brute-forcer for arbitrary web login forms
- you lack authorization to test the target systems
- you need a GUI-based credential testing tool
- the target uses an identity provider without a supported module and you cannot write one

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, cli, http-client
- domain: security, penetration-testing
- platform: python, cli, windows, cross-platform
- tags: password-spraying, credential-stuffing, office365, oauth, proxy-rotation, red-team, mfa-bypass, user-enumeration, linux, macos

## Member repositories
- blacklanternsecurity/TREVORspray (main) score 70

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:33.768840+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:40:18.395624+00:00, confidence not recorded.
  - readme: https://github.com/blacklanternsecurity/TREVORspray (fetched 2026-08-28T04:04:33.768840+00:00, sha 6e8cf5939de7)
  - registry_pypi: https://pypi.org/pypi/trevorspray/json (fetched 2026-08-29T11:56:19.449921+00:00, sha 7ae80db539a2)
- Data as of 2026-08-30T08:39:29.467469+00:00.
