finds.dev← search

// the find

hmaverickadams/breach-parse

★ 2,150 · Shell · updated Mar 2024

A tool for parsing breached passwords

breach-parse is a short Shell script that searches a local copy of the BreachCompilation password dump for lines matching a pattern, such as a domain, and writes the hits to a file. It is aimed at security staff checking whether a company's accounts appear in known breach data, and at anyone who already holds the dump and wants a faster way to filter it.

- The visible tree is two scripts, breach-parse.sh and install.sh, so the whole tool can be read in one sitting. That matters for something that goes near credential data.

- Usage is one line: a pattern, an output file, and an optional path to the data. The @gmail.com example shows filtering by domain, which is the obvious first use.

- The data location is an argument rather than a fixed path, so the dump can live on whatever disk has room for it. /opt/breach-parse is only the fallback default.

- The last push was 21 March 2024, more than two years before today. Nothing in the README says the tool has been checked against a recent dump or a current shell.

- The README is a few commands. It doesn't say what the output looks like, whether duplicates are removed, how malformed lines are handled, or how long a search takes on a dump this size. You find that out by running it.

- The only data source given is a torrent magnet link to a breached-credential compilation. The README says nothing about the legal position of holding that data, or how to store and dispose of it once it is on disk.

- The README states no license, so reuse and redistribution rules are unclear. No test files appear in the visible tree.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →