Overview
Hydra parallelises login attempts against HTTP forms, SSH, FTP, RDP, SMB and many other services.\nIt is the tool behind most credential attacks against exposed services, and its speed is exactly why rate limiting and lockouts matter.\nOn an authorised test it quickly proves whether a password policy is theoretical or real.
Indicators of Compromise
Signals that suggest this is present on a system.
- Parallel failed logins from one source
- Dictionary-ordered password attempts
- High authentication failure rates against a single service