Credential Attack

Password spray methodology for bug bounty — when to do it vs web-vuln hunting, the wordlist-gen + breach-check + osint-employees + spray pipeline, mode selection (http-form / oauth / o365 / okta), rate-limit + lockout tactics, BBP legal guardrails, success detection, and the spray → authenticated hunt chain pattern. Use when assessing whether credential attack is worth running on a target, picking the right mode, or recovering from common pitfalls.

26zl 5c149d0 20.3 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/credential-attack commit 5c149d0f59

Frequently asked questions

npx skillmds@latest add 26zl/credential-attack