The Credential Mapper
Switch branches/tags
Nothing to show
Clone or download
lightos Merge pull request #23 from khast3x/master
Alpine Dockerfile + instructions
Latest commit d862247 Dec 1, 2017

credmap: The Credential Mapper

Credmap is an open source tool that was created to bring awareness to the dangers of credential reuse. It is capable of testing supplied user credentials on several known websites to test if the password has been reused on any of these. An official introductionary post can be found here.

Help Menu

Usage: --email EMAIL | --user USER | --load LIST [options]

  -h/--help             show this help message and exit
  -v/--verbose          display extra output information
  -u/--username=USER..  set the username to test with
  -p/--password=PASS..  set the password to test with
  -e/--email=EMAIL      set an email to test with
  -l/--load=LOAD_FILE   load list of credentials in format USER:PASSWORD
  -f/--format=CRED_F..  format to use when reading from file (e.g. u|e:p)
  -x/--exclude=EXCLUDE  exclude sites from testing
  -o/--only=ONLY        test only listed sites
  -s/--safe-urls        only test sites that use HTTPS.
  -i/--ignore-proxy     ignore system default HTTP proxy
  --proxy=PROXY         set proxy (e.g. "socks5://")
  --list                list available sites to test with


./ --username janedoe --email
./ -u johndoe -e --exclude ","
./ -u johndoe -p abc123 -vvv --only ","
./ -e --verbose --proxy ""
./ --load creds.txt --format "e.u.p"
./ -l creds.txt -f "u|e:p"
./ -l creds.txt
./ --list

Add new websites

Adding new websites to be tested using credmap can be done by creating a new XML file in the websites/ folder. To view a list of all possible tags that can be used in the XML file, please refer to the Wiki.


Build and deploy with the following:

git clone
cd credmap
docker build -t credmap .
docker run -it credmap