mqtt-pwn
Installation
SKILL.md
MQTT-PWN
One-stop interactive framework for MQTT broker penetration testing. Wraps enumeration, brute-force, fingerprinting, and publish/subscribe abuse modules in a single shell with SQLite-like persistence (PostgreSQL) so scans, topics, messages, victims, and credentials survive across the session.
When to use mqtt-pwn
Use it instead of raw mosquitto_pub/mosquitto_sub when you need to:
- enumerate topics and messages on a broker over time and store them for later review.
- brute-force broker credentials with wordlists or inline lists.
- pull broker metadata/fingerprint from
$SYS/#topics. - target Sonoff smart switches or Owntracks GPS clients exposed on a public broker.
- run a publish/subscribe C2 for lab/IoT-implant scenarios.
- chain MQTT findings into IoT, smart-home, or ICS workflows (pair with
ics-ctfandmosquitto-clients).
Skip it for: single one-shot pub/sub checks (use mosquitto-clients), MQTT 5 enterprise features, or MQTT-SN — coverage is MQTT 3.1.1 over TCP/TLS only.