{"id":28249118,"url":"https://github.com/aenoshrajora/phantommist","last_synced_at":"2026-01-25T21:36:56.807Z","repository":{"id":295237530,"uuid":"958134040","full_name":"aenoshrajora/PhantomMist","owner":"aenoshrajora","description":"PhantomMist is a powerful password spraying tool designed for ethical penetration testing and security assessments. It automates large-scale authentication attempts while minimizing detection, supporting multiple protocols and customizable attack configurations.","archived":false,"fork":false,"pushed_at":"2025-04-02T08:47:27.000Z","size":11873,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-06-13T11:46:10.125Z","etag":null,"topics":["automation","crystal","cybersecurity-tools","exploitation-tool","password","password-spray","penetration-testing-tools","security-tools"],"latest_commit_sha":null,"homepage":"","language":"Crystal","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/aenoshrajora.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-03-31T17:43:16.000Z","updated_at":"2025-04-02T08:47:30.000Z","dependencies_parsed_at":"2025-05-24T11:53:58.774Z","dependency_job_id":null,"html_url":"https://github.com/aenoshrajora/PhantomMist","commit_stats":null,"previous_names":["aenoshrajora/phantommist"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/aenoshrajora/PhantomMist","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aenoshrajora%2FPhantomMist","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aenoshrajora%2FPhantomMist/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aenoshrajora%2FPhantomMist/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aenoshrajora%2FPhantomMist/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/aenoshrajora","download_url":"https://codeload.github.com/aenoshrajora/PhantomMist/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aenoshrajora%2FPhantomMist/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28759416,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-25T20:56:06.009Z","status":"ssl_error","status_checked_at":"2026-01-25T20:54:48.203Z","response_time":113,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["automation","crystal","cybersecurity-tools","exploitation-tool","password","password-spray","penetration-testing-tools","security-tools"],"created_at":"2025-05-19T13:14:12.501Z","updated_at":"2026-01-25T21:36:56.792Z","avatar_url":"https://github.com/aenoshrajora.png","language":"Crystal","funding_links":[],"categories":[],"sub_categories":[],"readme":"![Static Linux](https://github.com/aenoshrajora/phantommist/actions/workflows/StaticLinuxBuild.yml/badge.svg) \n![Arch Linux](https://github.com/aenoshrajora/phantommist/actions/workflows/ArchLinuxBuild.yml/badge.svg) \n![Debain(based) Linux](https://github.com/aenoshrajora/phantommist/actions/workflows/DebianLinuxBuild.yml/badge.svg)\n![Kali](https://github.com/aenoshrajora/phantommist/actions/workflows/KaliBuild.yml/badge.svg)\n![Mac OS](https://github.com/aenoshrajora/phantommist/actions/workflows/MacOSBuild.yml/badge.svg)\n\n\n# **Why**\nI got sick and tired of having to remember and manually spray a password every 30-60 min for a userlist and managing a large list with what passwords had been sprayed for what user was the worst. Also adding to a userlist added additional problems with either starting over or leaving out missed passwords for new accounts. Additionally many spraying tools only existed for certain endpoints ie just an o365 spray tool or just an exchange spray tool. I wanted a standard framework that could do any spraying i needed with all the features i wanted. So i created....\n\n\n\u003cbr\u003e\n\u003cimg src=\"./mdassets/phantommist_art.png\"\u003e \n\n\n### [Wiki](https://github.com/aenoshrajora/phantommist/wiki). (Not Released Yet)\n\n# **PhantomMist**\nA fast multithreaded password spray tool designed to simplify and automate many password spraying problems i faced.\n## **Features**\n* Database to keep track of what has been sprayed/valid finds (Sqlite3)\n  * This prevents previous combos from being sprayed!! So if you add a username to your list you can just rerun the same command and it will ignore previously sprayed combos\n* Supports username,password (as single inputs and files )\n* Jitter between individual authenticaion requests\n* Delay between passwords\n* MFA detection ( on a per module basis )\n* Lockout detection (on a per module basis )\n* Webhook support (autodetects Teams, Discord, Slack, and Google Chat URLS via domain name)\n* Multithreaded\n* For full list of changes and features added. see the [ReleaseNotes](https://github.com/aenoshrajora/phantommist/blob/main/ReleaseNotes.md) (Releases have not been released yet due to testing and analyzing)\n\n# **PMDB** \nAn nice interface for the backend database.\n## **Features** \n* console application \n* tab completion \n* suggestions \n* exporting info to csv file \n* search capabilities\n\n\u003cbr\u003e\n\u003cimg src=\"./mdassets/fulldemo.gif\"\u003e \n\n**Note:** The the demo above uses the testing spraytype for demonstration purposes. This doesnt make any network connections.\n\n## **Current supported spray types**\nfully implemented means that the module works as designed. some protocols may not support mfa detection. others i have not had a chance to compare the \"valid\" check for one with MFA enabled ( ex. sonicall virtualoffice )\n|Type|MFA support| Lockout Detection | Fully implemented |\n|----|-----------|-------------------|-------------------|\nExchangeEAS|no  |  no               | yes                \nExchangeOWA|no  |  no               | yes (could be a little more refined but fully working)\nadfs_forms |YES(msft azure mfa ) |  no               | yes\no365_adfs_forms | not yet |  no               | not validated \nSonicwallVirtualOffice|no  |  no    | yes (no mfa though) (validation not confirmed)\nSonicwall(the digest one) | no | no | yes(validation not confirmed)\nO365|YES|YES|yes\nSSLVPN Cisco|no|no|yes ~~( i converted some code from a previous spraying ruby script i wrote that worked. but havent had a chance to test this one)~~ confirmed with group= --domain flag.\nVPN Fortinet|no|no|kinda(use at own risk)(validataion not confirmed)\nSpiceworks|no|no|no(no mfa/lockout though)(validataion not confirmed)\nInfinateCampus|no|no|yes\nGlobal Protect | no|no|not fully tested \nESXI (root web) | no | no (default is 10 be carefull) | yes - tested with esxi 6.5,7.0\nVmWare Horizon (Domain Joined Web prompt) | no | no | yes \nOkta | not yet  | no  | Yes (may try to add mfa detection later)\nEgnyte | no  | no  | not validated\nCitrix | no  | no  | not validated\n\n\n```\nExamples:\n./phantommist -s msol -u myemail@domain.com -p password123\n./phantommist -s adfs_forms -u usernames.txt -p passwords.txt\n./phantommist -s msol --user-pass-format upffile.txt\n./phantommist -s ExchageOWA -u myemail@domain.com --user-as-password --target \"https://adfs.mydomain.com\"\n\nExamples:\n./phantommist -s msol -u myemail@domain.com -p password123\n./phantommist -s adfs_forms -u usernames.txt -p passwords.txt\n./phantommist -s msol --user-as-password --user-pass-format upffile.txt\n./phantommist -s msol -u myemail@domain.com --user-as-password\n\nGlobal options:\n    -s, --spray-type=[spraytype]     Set spray type. use --list-spraytypes to get current list\n    -t, --target=[ip/hostname]       Target to spray ( could also be a fireprox address )\n    -u, --username=[name]            Comma seperated usernames or filename of usernames to spray (one per line)\n    -p, --password=[password]        Password or file of passwords to spray. Whitespace will be trimmed off the ends\n    -d, --delay=[time]               Time in seconds to delay between password attempts\n    -j, --jitter=[time]              Time in milliseconds to delay between individual account attempts. default is 1000.\n    --domain=[domain]                Sets the domain for options that require domain specification.\n    -h, --help                       Print Help menu\n    --version                        Print current version\n    -v, --verbose                    Print verbose information\n\nAdditional Options:\n    --threads=[count]                Use worker threads to drasticly speed things up!(default is 1)\n    --nodb                           does not use the database\n    --force                          Forces the spray to occur despite if it has been sprayed before or if it was previously marked invalid. This still logs to the database.\n    --user-as-password               Sets the user and password to the same string\n    --user-pass-format=[filename]    Supplied file in 'user:password' format. If a password has a : in it, it wont break. everything after the first : is used as the password\n    --webhook=[url]                  Will send a webhook if valid credential is found!! (autodetects Teams, Discord, Slack, and Google Chat URLS)\n    --webhookcard=[string]           The 'card' template used to send to the specified webhook. For use only with custom webhooks(for now)\n    --strip-user-string=[stiped_string]\n                                     Will strip the entered string from the end of the username. Ideally used with --user-as-password.  ex: --strip-user-string '@domain.com' = user@domain.com =\u003e user\n    --strip-pass-string=[stiped_string]\n                                     Will strip the entered string from the end of the username. Ideally used with --user-as-password.  ex: --strip-pass-string '@domain.com' = user@domain.com =\u003e user\n    --useragent=[agentstring]        Use a custom useragent string, or a file containing useragents(will chose randomly from them).\n    --list-spraytypes                List the available spraytypes.\n    --disable-color                  Disables color outputs entirely\n```\n\n\n## **Use**\n\n### Download from [releases](https://github.com/aenoshrajora/PhantomMist/releases). (Not Released Yet)\nor \n\n## Compile yourself \neither use the make file \n```bash\nmake all        # compiles phantommist and pmdb \nmake install    # installs the tools\n```\n### Compile the manual way \n```bash\nshards install \ncrystal build -p src/phantommist.cr \ncrystal build -p src/pmdb.cr \n```\nYou can also use:\n```bash\nshards install \ncrystal build -p --no-debug --release src/phantommist.cr \ncrystal build -p --no-debug --release src/pmdb.cr \n```\nWhich will take longer but will be more optimized (not that you need it) it also may not give you help if something breaks.... your choice\n\n### **Examples:**\n```\n./phantommist -s ExchangeEAS -u users.txt -p passwords.txt\n./phantommist -s msol -u \"user1@example.com\" -p passwords.txt\n./phantommist -s vpncisco -u users.txt -p \"Password123\" --webhook \"https://teamswebhook.com/asdfasdfasdf\"\n./phantommist -s msol -u emails.txt -p \"Password123\" --jitter 500 --dealy 3600  --target \"https://aws.fireprox.instance/fireprox\"\n```\n\n\n## TODO\n* ~~multithread things ( templates started )~~\n* add a spraygroup feature - so that you can spray multiple back to back but then delay. this may be usefull for some lockout policies. \n* ~~go public~~\n* ~~dd wiki~~ its there. will be constantly adding to it \n* ~~maybe update the way some of the modules are called (thinking ./phantommist \\\u003ctype\\\u003e [arguments] ex. phantommist vpncisco -u users.txt -p \"Password123\" )~~ just going to stick to the -s flag. dont fix whats not broken.\n* docker file?\n* ~~make install feature~~\n* ~~pipeline something so that i can build/release on multiple platforms at a time~~\n* Add various webhooks support. ~~teams~~,~~slack~~, ~~google chat~~( need feature requests here for what people use )\n* Email support? like webhooks but email? could be usefull for sending emails to phone numbers for sms notifications.... probably a dumb idea\n* Implement a yml file for configuration defaults. That might be easiest for things like webhooks, target substitutions... etc that way no cluttered cli \n* Add better support for fireprox or other web proxies like that - currently fireprox can be used as the target and does work. Proxychains works well so that may be what i stick with. \n* Update pmdb to include tab completion and better dialog menus\n* Make a wiki.... this file it getting a bit big and harder to navigate\n\n\n\n## **Contributing**\n* Fork the project and submit a request with your feature/fix \n* Submit a feature request through github(look at the wiki/todo list first your idea might already be there or answered)\n* If you have a new spray type you want submit a feature request or give me the web request sequence (burp files are super nice). NOTE if its not public/you cant prove you own something i wont test password spraying unless i can spin it up in my lab. If you send me a burp sample.... please consider OPSEC.  \n* For new spraytypes there is a template.cr file in src/spray_tyes that should be easy/convienient to use to implement new auth types\n\n\n\n\n\n\n# **pmdb**\npmdb is a simple applicaion to interact with the backend db for phantommist. there is now a timestamp for each password spray item. so it is possible to go back and see exactly what time a specific user attempt was sprayed.\n\ninteractive commands: \n* usernames - show usernames in the database\n* passwords - show what passwords have been sprayed \n* sprayed - shows all username/password combination that have been sprayed\n* vaid - shows all username/password combinations that are valid\n* export \\\u003ctablename\\\u003e - exports the specified tablename to a csv file in the local directory \n* search \\\u003csearch string\\\u003e \n* valid \\\u003csearch string\\\u003e\n* help \n\n~~pmdb is the new updated version of pmdb. it now features a tab completsion and help menu scrolling option while naviating.~~\n~~features are expiramental at this point. but should work as advertized.~~ this is out of date now and merged to the main pmdb \n\npmdb now supports tabcompletion and syntax suggestion! \n\n\n\n# Thank you all for your inspiration and contributions to the community!!!  \n\n## Other Thanks \n* To the individual who helped troubleshoot okta. (you know who you are)\n\n\n\n# **Crystal Install help** \nphantommist is written in [crystal-lang](\"https://crystal-lang.org\"). A language similar to ruby in syntax but produces a  compiled binary, is extremely fast, and is easy to work with. Installing can be done as below. if you dont trust these commands... go here: https://crystal-lang.org/install/\n\n---\n**Arch** based linux distros  \n```\nsudo pacman -S crystal shards \n```\n\n**Debian/RedHat** based linux distros(**Kali** too)\n```\ncurl -fsSL https://crystal-lang.org/install.sh | sudo bash\n```\n\n**Windows** (Crystal is supported on windows) there are several options:\n* There is prerelease crystal compiler for windows available. \n* Use wsl (this is what i use 80% of the time and it works really well)\n* use a linux vm\n\n\n**MacOS**(homebrew):\n```\nbrew update\nbrew install crystal\n```\n\n\n* [ExchangeEAS] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_ExchangeEAS)\n* [ExchangeOWA] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_ExchangeOWA)\n* [cisco_vpn] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_cisco_vpn)\n* [ADFS_forms] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_ADFS_forms)\n* [vpn_sonicwall_virtualoffice] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_vpn_sonicwall_virtualoffice)\n* [vpn_sonicwall_virtualoffice_5x] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_vpn_sonicwall_virtualoffice_5x)\n* [vpn_sonicwall_digest] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_vpn_sonicwall_digest)\n* [vpn_fortinet] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_vpn_fortinet)\n* [spiceworks] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_spiceworks)\n* [InfinateCampus] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_InfinateCampus)\n* [global_protect] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_global_protect)\n* [ESXI_web] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_ESXI_web)\n* [VMWare_Horizon] (https://github.com/aenoshrajora/phantommist/wiki/SprayType_VMWare_Horizon)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faenoshrajora%2Fphantommist","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Faenoshrajora%2Fphantommist","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faenoshrajora%2Fphantommist/lists"}