S01E01 - Password Cracking

Elliot wants to know everything about his therapist. So he brute-forces her accounts. He pulls up Krista’s social media (Gmail, Facebook, iTunes, eHarmony), scrapes personal details, and feeds them into a tool called elpscrk. The name is almost short for “Elliot’s Password Crack”, his own take on profiled password cracking, in the same vein as John the Ripper, the classic password cracker that’s been around since 1996.
elpscrk generates password candidates from what Elliot already knows about Krista: her favourite singer (Bob Dylan), her birth year (1972), common patterns, common separators. It cracks her password in seconds: Dylan_2791.
Favourite artist. Birth year reversed. Underscore in the middle. Exactly the kind of password most people think is clever.
TL;DR
| 🎬 Reel or Real? | ✅ real technique, fictional tool. elpscrk doesn’t exist, but CUPP and similar profilers do exactly this |
The Tool: elpscrk
elpscrk isn’t real. It’s a prop created for the show. A custom script that takes personal details about a target and generates likely passwords from them.
After the show aired, someone built a working version: elpscrk on GitHub. It does exactly what the show depicts: takes names, dates, pet names, favourite bands, and spits out password combinations.
But elpscrk wasn’t the first. Tools that do this have been around for years:
- CUPP (Common User Passwords Profiler). The most well-known. Feed it personal details, it generates a targeted wordlist. Preinstalled on Kali Linux.
- WhoAmI: OSINT-based password profiler
- Mentalist: GUI-based wordlist generator with rule chaining
This approach is called profiled dictionary attack: instead of trying every possible combination, you generate candidates based on what you know about the person.
Why It Works
People are predictable. Same patterns, over and over:
- Name + numbers:
krista1972,dylan123 - Favourite thing + year:
Dylan_2791,Beatles2001 - Pet name + birthday:
flipper0315 - Simple substitutions:
P@ssw0rd,Kr1st@
A profiled wordlist of a few thousand candidates built from someone’s social media can crack a personal account faster than a brute-force attack running millions of random combinations. It’s not about computing power. It’s about knowing your target.
Elliot didn’t need a supercomputer. He needed Krista’s Instagram.
What the Show Gets Right
Pretty much everything. The sequence is textbook:
- Reconnaissance: scrape the target’s public profiles for personal details
- Wordlist generation: feed those details into a profiler to generate candidates
- Credential testing: run the wordlist against the target’s login
This is how a significant percentage of personal account compromises happen. The Verizon DBIR consistently lists stolen/weak credentials as a top attack vector year after year.
Speed is the one thing the show simplifies. In reality, most online services have rate limiting, so you can’t just hammer a login form with thousands of guesses. But if you’ve got a hashed password file (from a breach), offline cracking with a profiled wordlist is fast.
Closing
Krista’s password was Dylan_2791. She probably thought it was secure. It has a mix of letters, numbers, an underscore, and it’s not a dictionary word. But it’s built from two pieces of information she shared publicly. That’s all Elliot needed.
elpscrk is fiction. The method isn’t. If your password is built from things people can find out about you, it’s not a password. It’s a puzzle, and the pieces are already on your social media.
Next: S01E01 - Steganography.