Meet Constantine – Find Mythos-level vulnerabilities in your code. It proves them, patches them, PRs them back. Autonomously.

Credentials Are Still the Shortest Path In

How Brutus grew into an engine that finds your identities, tests them everywhere they’re accepted, and remembers what it confirms.

An attacker rarely needs a novel exploit when a valid username and password pair is sitting in a breach dump, reused across a dozen internal services, or left at a vendor default nobody changed.

Brutus started as a focused credential testing tool. It has since grown into something broader: an engine that finds the identities attached to an organization, tests them everywhere they might be accepted, and carries what it confirms forward into future runs. All of it runs automatically as part of the pipeline. There’s no manual setup and no analyst kicking off individual checks.

Here’s what changed.

Knowing who works there

Testing a credential assumes you already know the account exists. Brutus now builds that picture from more places.

A new people enumeration subsystem maps organizational exposure using professional identity data, drawing on an Apollo.io connector built with a split discover and enrich flow so the full org roster isn’t revealed automatically. A LinkedIn Sales Navigator connector adds another path for personnel discovery.

Microsoft 365 enumeration is now a first class command in its own right rather than something reachable only from inside another mode, and it supports rotating proxies. GitHub email enumeration through rotating proxies is also fixed: the CSRF session handshake no longer stalls or fails quietly, and progress is visible while the session is being established.

Two smaller changes make the output easier to work with. Generated usernames now carry the first and last name that produced each candidate, so nothing downstream has to reverse engineer a person’s name from the local part of an address. And rotating proxy support is available across active enumeration modes rather than in a handful of them.

Fourteen more protocols under test

Brutus now tests credentials and detects unauthenticated access across fourteen additional protocols:

  • Messaging and queuing: AMQP, MQTT, Kafka, NATS, ActiveMQ, XMPP, SIP
  • Data and caching: Memcached, Firebird, DB2, ZooKeeper
  • Industrial and infrastructure: OPC UA, IPMI, SOCKS5

IPMI is worth calling out on its own. Out of band management interfaces sit below the operating system, often on a flat management network, and frequently still carry the BMC credentials they shipped with. Brutus tests for those defaults. OPC UA brings the same treatment to industrial environments.

Any service fingerprinted on any port is testable without manual configuration, so nonstandard ports don’t create blind spots.

Two fixes round this out. The PostgreSQL plugin now honors TLS mode configuration, which means TLS only servers are reachable and the plugin behaves like the MySQL, MSSQL, Neo4j, and LDAP plugins already did. The PostgreSQL connector also handles credentials with special characters or spaces, plus IPv6 hosts, correcting connection failures that used to turn into silently skipped checks.

Credentials that compound

A confirmed credential is worth more than the single service it was confirmed against, and Brutus now treats it that way.

Credentials confirmed during a hunt are persisted and handed to the re-verification pass instead of disappearing when the task container exits. Each confirmed pair is also stored per tenant and automatically tested against other services in later runs.

That second change is the one with teeth. Password reuse is one of the most reliable findings in offensive work, and it usually takes an operator noticing a pattern and deciding to chase it. Here it happens on its own, across the environment, every time.

Backdoors that survive a password reset

Brutus can now detect accessibility tool backdoors at the RDP logon screen, where sethc.exe or Utilman.exe has been replaced with a SYSTEM shell. These are old techniques that remain effective for a simple reason: rotating every password in the environment does nothing to remove them.

Detection happens before authentication and needs no credentials. Brutus captures a baseline screenshot over a non NLA RDP connection, sends the known trigger, captures the response, and compares the two. System state is never modified, and the check runs only on in scope assets under an active testing posture.

Why this matters

Most real intrusions are a sequence of small, unglamorous steps: find a person, guess their account name, try a password that worked somewhere else, land on a service nobody was watching. Each step is easy to dismiss in isolation. Together they’re how environments fall over.

Brutus now runs that sequence continuously, across more of the identity surface and more of the services that accept credentials, and it remembers what it learns.

The fastest way to see what that turns up is to point it at your own environment. Sign up for Praetorian’s free Guard tier and get a look at the identity exposure and credential issues already sitting in your attack surface.

About the Authors

Unit-O1

Unit-O1

Unit-01 is Praetorian's centurion. He does not stand watch. He runs continuous offense across the full attack surface, finds the way in, and maps where it leads before a real adversary gets there. See what he would find in your environment at https://www.praetorian.com/praetorian-guard-demo

Catch the Latest

Catch our latest exploits, news, articles, and events.

Ready to Discuss Your Next Continuous Threat Exposure Management Initiative?

Praetorian’s Offense Security Experts are Ready to Answer Your Questions