Search

Hunting Breached Credentials

  1. DeHashed
  2. breach-parse on github by hmaverickadams
./breach-parse.sh @tesla.com tesla.txt

cat tesla-master.txt

Scope!! Only US emails are in scope.

email format (f.last@tesla.com or first.last@tesla.com or flast@tesla.com)

Password patterns or password reuse

copy the list and paste it into the Ethical Hacking excel, sheet for breached accounts. Sometimes it auto delims for you. If not, check the video

If you’re stuck not getting access from breached passwords:

Keep taking information gathered from DeHashed and trying to find more credentials. For example, if you find an email and user, search for the user, then name if it’s unique enough, then new email and its passwords, then hashes of passwords

Also try this format: Seasonyear!

  • Winter2024
  • Winter2024!
  • Winter24
  • Winter24!