apiscan
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Password brute force and hash cracking against target services
> /plugin marketplace add ogrodev/fsociety > /plugin install fsociety@ogrodev-fsociety
How it fires
How this command gets triggered: by you, by Claude, or both.
/bruteforceContext preview
What this command does when you run it.
Password brute force and hash cracking against target services
description: Password brute force and hash cracking against target services allowed-tools: ToolSearch, Bash, Read, Write argument-hint: <service> <target>
Service: `$1` Target: `$2`
Execute password attacks using Hexstrike MCP tools.
Use ToolSearch to load:
Map the service to the appropriate approach:
**Online brute force** (live service login):
**Offline hash cracking** (captured hashes):
**Network credential testing**:
Run `hydra_attack` with:
For captured hashes, choose the right tool:
Run with:
Report found credentials clearly: | Username | Password | Service | Status | |----------|----------|---------|--------|
**IMPORTANT**: Handle credentials responsibly. Only test credentials within authorized scope.
Multi-plugin marketplace for Claude Code offensive security plugins
Repo: ogrodev/fsociety
API security audit — REST, GraphQL, JWT analysis, parameter discovery
Archive or list previous engagement snapshots
Resume or execute an attack campaign with progress tracking
Show running scans, system health, and engagement status
Post-engagement lessons learned analysis and debrief report