Homebrew
RecommendedHomebrewbrew install hydra
Parallelised login attempt tester for authorized audits
Needs review. May lag the current upstream release. Verify before relying on it. Cross-check against the upstream documentation before relying on a command.
Hydra automates credential testing against many service types (SSH, FTP, HTTP form, RDP, SMB, SMTP auth) so an organisation can measure whether weak or default passwords are actually in use on its own systems.
This is the category of tool that most easily crosses a legal line. Run it only with written authorization, inside an agreed window, against test or clearly identified accounts, with lockout policy understood in advance.
Supported platforms
8
Documented install or usage guidance
Learning curve
intermediate
Difficulty of becoming productive, not of the underlying theory
Tags
authentication, audit, policy, lockout
Dataset entry
hydra.ts
Reviewed 2025-12-19
Grouped by platform. Elevation requirements are marked per method.
brew install hydra
Needs elevated privileges (sudo / Administrator).
sudo apt install hydra libssl-dev
sudo dnf install hydra
Package availability follows your distribution and enabled repositories. Entry revised 19 Dec 2025 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Uses a POST template with the username and password placeholders that Hydra substitutes.
hydra -l testuser -P lab-wordlist.txt 192.0.2.20 http-post-form '/login:user=^USER^&pass=^PASS^:F=invalid'
Notes
Measures whether an SSH account accepts a password from a short list of known-weak candidates.
hydra -l svc_backup -P weak-own-lab.txt ssh://192.0.2.30 -t 4 -f
Notes
Writes a restore file so a long audit can continue after a restart.
hydra -R /tmp/lab.restore
Notes
Service syntax differs per module; the usage dump is the reference for your build.
hydra -h | less
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Check the module list in `hydra -h`, and re-configure the build with the needed libraries if you must have them.
Possible causes
Usual fix
Send one bad login manually, copy the exact error text, and use it as `F=` — or invert with `S=` on a success string.
Possible causes
Usual fix
Stop immediately, notify the system owner, and record the impact. Future runs need an agreed rate and a service account that is exempt from lockout.
Not documented yet: medusa. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.
Hashcat cover adjacent parts of the same job.