There are 1 repository under ntlm topic.
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
Password Crack Framework
Finding all things on-prem Microsoft for password spraying and enumeration.
Bruteforce HTTP Authentication
A set of prioritized Hashcat .hcmask files intelligently developed from terabytes of password breach datasets and organized by run time.
Expose Microsoft Windows SSPI to Node for SSO authentication.
Identify the accounts most vulnerable to dictionary attacks
Winfoom is an HTTP(s) proxy server facade that allows applications to authenticate through the proxy without having to deal with the actual handshake.
A nginx module to allow proxying requests with NTLM Authentication.
A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.
SMBExec implementation in Nim - SMBv2 using NTLM Authentication with Pass-The-Hash technique
Script to perform some hashcracking logic automagically
ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based on Data Encryption Standard (DES).
Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already saved SAM and SYSTEM hives.
A Rust implementation of the Security Support Provider Interface (SSPI) API
Password cracking research using the Have I Been Pwned (HIBP) dataset to evaluate the effectiveness of the PassGPT Large Language Model (LLM).
Search (offline) if your password (NTLM or SHA1 format) has been leaked (HIBP passwords list v8)
WordPress plug-in "Next Active Directory Integration"
Cross-platform proxy selection with optional native authentication negotiation
POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch
Parallel password cracker. Supports NTLM, LM, MD5, MD4, SHA1, SHA224, SHA256, SHA384, and SHA512.
Authentication classes to be used with requests
hashgen - the blazingly fast hash generator
Burp extension to decode NTLM SSP headers and extract domain/host information