Directory Services Internals (DSInternals) PowerShell Module and Framework
-
Updated
Sep 11, 2026 - C#
Directory Services Internals (DSInternals) PowerShell Module and Framework
Dump ntds.dit really fast
A tool to generate a wordlist from the information present in LDAP, in order to crack passwords of domain accounts.
Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.
cracke-dit ("Cracked It") makes it easier to perform regular password audits against Active Directory environments.
Analyze secretsdump output and hashcat potfiles to find shared passwords and weak credentials in Active Directory
A tool to analyze Ntds.dit files once the NTLM and LM hashes have been cracked.
A python tool to generate an Excel file linking the list of cracked accounts and their LDAP attributes.
Patching Bloodhound CE for Owned and PtH Attacks
Having the NTLM and a cracked LM hash it is possible to get the original password by testing all the combinations of upper and lowercases. This is useful if a ntds.dit file has both NTLM and LM hashes
Cracking and bruteforce methodologies for the most common hashes, services and technologies
Active Directory password audit framework for NTDS processing, password analysis, and reporting.
The Forensic Examiner's Swiss Army Knife for analysing file-based forensic artifacts.
doNTreuse.sh is a simple Bash script for examining the extent of NT hash reuse from the result of Impacket's secretsdump.py.
Cross-platform GUI, CLI and MCP server for Microsoft ESE databases (ntds.dit, SRUDB.dat, Exchange .edb, WebCacheV01.dat, Windows.edb) - digital forensics tool with multi-format extract and reporting
Active Directory password auditing — compare ntds.dit NT hashes against HaveIBeenPwned (NTLM). Portable Windows GUI, online k-anonymity or offline, HTML/JSON/CSV reports, secure wipe. By Ayi NEDJIMI.
To associate your repository with the ntds topic, visit your repo's landing page and select "manage topics."