Corporate password list generator for internal security assessments
Project description
CorpCrack
CorpCrack is a targeted password list generator built for internal network assessments that produces organization-based, likelihood-sorted output.
Why not just use a wordlist?
Generic wordlists (rockyou, SecLists, etc.) have no awareness of the organization you are targeting. They will never contain the patterns that employees actually set.
CorpCrack generates a single likelihood-sorted list that serves two purposes. Towards the top of the list are the most commonly identified passwords, ideal for spraying within a lockout window. Further down, it transitions into company-specific and leetspeak patterns better suited for cracking, the kind of candidates that generic wordlists will never have.
Features
| Flag | Description |
|---|---|
-s NAME |
Short / abbreviated company name |
-l NAME |
Full company name |
--year-start YEAR |
Start year for time-based passwords (inclusive) |
--year-end YEAR |
End year for time-based passwords (inclusive) |
-o FILE |
Write passwords to file instead of stdout |
--top N |
Output only the top N most likely passwords |
--min-length N |
Exclude passwords shorter than N characters |
--max-length N |
Exclude passwords longer than N characters |
--exclude FILE |
Exclude passwords found in FILE (one per line) |
--patterns LIST |
Only include passwords from these patterns (comma-separated) |
--shift-modifiers MODE |
Trailing characters to append (default: !, common, all, none, or custom) |
--show-weights |
Print the current weight table and exit |
--config FILE |
Load tier weights from a TOML config file |
--init-config [PATH] |
Generate a starter config file (corpcrack.toml) |
Installation
pipx install corpcrack
uv tool install corpcrack
Or install from latest commit:
pipx install git+https://github.com/c0inslot/corpcrack
uv tool install git+https://github.com/c0inslot/corpcrack
Usage Examples
# Full engagement run, company context, year range, write to file
corpcrack -s ACME -l "Acme Corporation" --year-start 2022 --year-end 2026 -o passwords.txt
# Quick spray list, just the top 20 most likely passwords, no company context
corpcrack --top 20
# Target enforces a 10-character minimum password policy
corpcrack -s ACME --year-start 2024 --year-end 2026 --min-length 10
# Exclude passwords you already tried in a previous spray window
corpcrack -s ACME --year-start 2024 --year-end 2026 --exclude already_tried.txt
# Only output static and company patterns
corpcrack -s ACME --year-start 2024 --year-end 2026 --patterns static,company
# Generate with all common shift modifiers (!@#$%) instead of just !
corpcrack -s ACME --year-start 2024 --year-end 2026 --shift-modifiers common
# See how your weights are currently ordered
corpcrack --show-weights
corpcrack --show-weights --config corpcrack.toml
# Generate a default config, tweak weights, then use it
corpcrack --init-config
corpcrack -s ACME --year-start 2024 --year-end 2026 --config corpcrack.toml
How the output is sorted
Each pattern has a weight that controls where it appears in the list. Lower numbers appear first.
| Pattern | Default | Examples |
|---|---|---|
static |
100 | Welcome1, Password123!, keyboard walks |
season_current |
200 | Spring2026! |
month_current |
250 | April2026! |
welcome_current |
275 | Welcome2026! |
special |
300 | Winteriscoming2025! |
company |
400 | ACME1!, ACME123! |
company_current |
450 | ACMESpring2026! |
welcome |
500 | Welcome2024!, Password2025! |
welcome_company |
550 | Welcome2ACME2025! |
company_year |
600 | ACME2024!, ACME@2025 |
season |
700 | Summer2024!, Winter2023! |
company_season |
800 | ACMESummer2024! |
month |
900 | January2024!, Oct25! |
company_month |
1000 | ACMEJan2024! |
leet_common |
10000 | W3lcom31 |
leet_multi |
20000 | W3l<0m31 |
leet_uncommon |
30000 | Wel{ome1 |
Patterns named *_current match the current season or month based on your system clock. Leet variants always appear below all non-leet passwords, following the same pattern ordering as their base passwords.
Custom weights
Generate a starter config:
corpcrack --init-config
This writes corpcrack.toml to the current directory. Edit the weights, then pass it in:
corpcrack -s ACME --year-start 2024 --year-end 2026 --config corpcrack.toml
Only the keys you include are overridden, everything else keeps its default.
Move a specific pattern higher in the list:
[weights]
company_season = 450
Disable the current-time boost. By default, passwords matching the current season/month rank higher. To treat them the same as any other season/month:
[weights]
season_current = 700
month_current = 900
welcome_current = 500
company_current = 800
Keep leetspeak variants out of spray range. Push them to the bottom of the list:
[weights]
leet_common = 999999
leet_multi = 999999
leet_uncommon = 999999
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file corpcrack-1.0.1.tar.gz.
File metadata
- Download URL: corpcrack-1.0.1.tar.gz
- Upload date:
- Size: 13.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6bb04b8e1b6cc8a19b9519856d10f8189c7dff52a8489e2254b42a597971ebb4
|
|
| MD5 |
e410375bba6ef2470039ab441bd18b1f
|
|
| BLAKE2b-256 |
e0e10ced028ac01144a1810539f5ca58090e200cc97b427a1b31ec89960af754
|
File details
Details for the file corpcrack-1.0.1-py3-none-any.whl.
File metadata
- Download URL: corpcrack-1.0.1-py3-none-any.whl
- Upload date:
- Size: 13.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9c17b4d658e357f310959a3e7bb64a43cd72a533a48203f82f64580e0ec39404
|
|
| MD5 |
bfc37878c5a431206f803e721b8a7ce2
|
|
| BLAKE2b-256 |
07cb392d8105f25f70ef335a0a58cc49f27049baeb8113907c64012f96cca421
|