> cat /dev/github | grep security-tools
discovered 03 Aug 2026

kcbrute

Python ★ 27 via github-topic
→ View on GitHub
kcbrute is a brute-force tool designed for testing the security of Keycloak Admin/User Console login flows by attacking the OpenID Authorization Endpoint. It allows users to specify a target URL, along with lists of usernames and passwords, and features options for threading, verbosity, and behavioral controls such as early stopping upon a successful login attempt. This tool is intended strictly for ethical security testing, with a disclaimer regarding potential account locking due to brute-force detection mechanisms.