
Hydra
THC Hydra is a free, multi-protocol online login brute-forcing tool for authorised password audits across many network services.
1 upvote · 0 downvotes
No ratings yet
- Category
- Offensive Security & Pentesting
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 1 October 2026
- Links
- GitHub
What it is
Hydra (THC-Hydra) is an open-source network logon cracker from van Hauser / The Hacker’s Choice (THC). It performs parallelised online password guessing against many remote services and is a staple of password-attack training, including Hack The Box Academy modules that cover Hydra alongside related tools.
What it helps with
- Brute-forcing or spraying credentials against protocols such as SSH, FTP, HTTP forms, RDP, SMB, databases, LDAP, VNC and many others.
- Running multiple parallel connects to speed authorised password audits.
- Combining username and password lists for controlled login testing.
- Using modules for HTTP GET/POST forms, proxies and protocol-specific options.
- Supporting Linux, Windows/Cygwin, macOS and other Unix-like builds, plus a Docker image.
- Demonstrating weak remote authentication during penetration tests and labs.
Who it's for
Penetration testers, red teams and security consultants who need to validate remote authentication strength on networks and applications within a written scope.
Worth knowing
Use Hydra only for legal, authorised purposes. Online brute forcing can lock accounts, trigger alerts and violate terms of service or law if used without permission. The author asks that it not be used for illegal purposes. Hydra is free under the GNU Affero General Public Licence v3. Prefer the vanhauser-thc/thc-hydra repository and releases for current builds. Attribution: framing from the THC-Hydra README; licence from the repository licence file.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.