mqtt-pwn

Installation
SKILL.md

MQTT-PWN

One-stop interactive framework for MQTT broker penetration testing. Wraps enumeration, brute-force, fingerprinting, and publish/subscribe abuse modules in a single shell with SQLite-like persistence (PostgreSQL) so scans, topics, messages, victims, and credentials survive across the session.

When to use mqtt-pwn

Use it instead of raw mosquitto_pub/mosquitto_sub when you need to:

  • enumerate topics and messages on a broker over time and store them for later review.
  • brute-force broker credentials with wordlists or inline lists.
  • pull broker metadata/fingerprint from $SYS/# topics.
  • target Sonoff smart switches or Owntracks GPS clients exposed on a public broker.
  • run a publish/subscribe C2 for lab/IoT-implant scenarios.
  • chain MQTT findings into IoT, smart-home, or ICS workflows (pair with ics-ctf and mosquitto-clients).

Skip it for: single one-shot pub/sub checks (use mosquitto-clients), MQTT 5 enterprise features, or MQTT-SN — coverage is MQTT 3.1.1 over TCP/TLS only.

Install

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
mqtt-pwn — aeondave/malskill