How to Use Patator's --resume Feature to Recover Interrupted Brute-Force Campaigns
To recover an interrupted brute-force campaign in Patator, interrupt the current run with Ctrl-C, copy the comma-separated resume values printed to the console, and relaunch the same command with --resume followed by those values.
Patator (lanjelot/patator) is a powerful, modular brute-force testing tool designed for penetration testers and security researchers. When running long-duration attacks against large target lists, network interruptions or manual stops can halt progress. The --resume feature allows you to recover interrupted brute-force campaigns by tracking per-thread payload counts and skipping already-processed attempts on restart.
How the --resume Feature Works in Patator
Patator implements resume functionality by tracking the number of payloads processed by each worker thread during execution. When you interrupt a running job, the tool calculates the count of already-done + skipped attempts for every thread and prints this as a comma-separated list. According to the source code in src/patator/patator.py, this resume string contains one integer per thread representing the exact offset needed to continue processing.
Step-by-Step: Recovering an Interrupted Attack
Follow these steps to resume a brute-force campaign without losing progress:
-
Start your Patator job normally
http_fuzz url=http://10.0.0.1/pma/index.php \ method=POST body='pma_user=COMBO00&pma_pass=COMBO01' \ 0=combos.txt -l /tmp/log -
Interrupt the execution by pressing
Ctrl-C. Patator performs a graceful shutdown and outputs a line similar to:To resume execution, pass --resume 15,15,15,16,15,36,15,16,15,40This message is generated in
patator.pylines 1124-1134. -
Copy the comma-separated values shown in the output. Each number corresponds to a specific worker thread's progress count.
-
Resume the campaign by appending the
--resumeflag with the copied values to your original command:http_fuzz url=http://10.0.0.1/pma/index.php \ method=POST body='pma_user=COMBO00&pma_pass=COMBO01' \ 0=combos.txt -l /tmp/log --resume 15,15,15,16,15,36,15,16,15,40 -
Verify continuation by checking that the progress counters reflect the previous state rather than starting from zero.
Technical Implementation Details
The resume capability is implemented across several key sections of src/patator/patator.py.
Resume Flag Definition and Parsing
The --resume CLI argument is defined at line 817 and parsed into the self.resume attribute at line 882. The parser converts the comma-separated string into a list of integers representing skip counts for each thread.
Resume Message Generation
When Patator receives a shutdown signal, it builds the resume instruction at lines 1124-1134. This routine aggregates the processed count from each worker thread and formats it as the comma-separated string users copy for resumption.
Payload Skipping Logic
During the producer loop, Patator applies the resume offsets at lines 1282-1289 to skip already-processed payloads. Additionally, lines 1260-1262 adjust the total work size calculation to account for the reduced remaining workload, ensuring accurate progress reporting throughout the resumed session.
Practical Example: Resuming a HTTP Brute-Force Attack
Consider a scenario where you are brute-forcing a phpMyAdmin login interface and need to pause the attack:
# Initial run - interrupted after partial completion
http_fuzz url=http://10.0.0.1/pma/index.php \
method=POST body='pma_user=COMBO00&pma_pass=COMBO01' \
0=combos.txt -l /tmp/patator_log
# Press Ctrl-C when you need to stop
# Output shows: --resume 12,12,12,13,12,28,12,13,12,38
# Resume with exact thread counts
http_fuzz url=http://10.0.0.1/pma/index.php \
method=POST body='pma_user=COMBO00&pma_pass=COMBO01' \
0=combos.txt -l /tmp/patator_log \
--resume 12,12,12,13,12,28,12,13,12,38
The second invocation skips the first 12 attempts for thread 0, 12 for thread 1, through 38 for thread 9, continuing exactly where the previous execution stopped.
Summary
- Patator tracks per-thread payload counts to enable campaign recovery.
- Interrupting a run generates a
--resumestring with comma-separated thread counts displayed at lines 1124-1134 ofpatator.py. - Supplying this string via the
--resumeflag (defined at line 817 and parsed at line 882) allows skipping processed payloads via the producer loop logic at lines 1282-1289. - The feature works with all Patator modules including
http_fuzz,ssh_fuzz, andsmb_fuzz. - Always use the exact same command arguments when resuming, changing only by adding the
--resumeflag and its values.
Frequently Asked Questions
Where does Patator store the resume progress?
Patator does not store resume data in a file. The progress counts exist only in memory during execution and are printed to stdout upon interruption. You must manually capture the --resume string from the console output to preserve it.
Can I resume a campaign on a different machine?
Yes, provided you use an identical copy of the original wordlist and the same Patator version. The resume counts are based on positional offsets within the payload list, so any deviation in wordlist content or order will cause incorrect skipping behavior.
What happens if I modify the wordlist between the original run and the resume?
Modifying the wordlist between runs will invalidate the resume counts. Since Patator skips a fixed number of payloads per thread (lines 1282-1289), changes to the wordlist size or ordering will cause the tool to skip wrong entries or miss targets.
Does the resume feature work with all Patator modules?
Yes, the resume functionality is implemented in the core Patator class in patator.py and is available across all modules including http_fuzz, ftp_fuzz, ssh_fuzz, and smb_fuzz. The same --resume syntax applies regardless of the protocol being tested.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →