Steal Net-NTLM Hash using Bad-PDF
-
Updated
Oct 20, 2025 - Python
Steal Net-NTLM Hash using Bad-PDF
Fast offline auditing of Active Directory passwords using Python.
Windows LSA credential extractor for lsass.dmp minidumps. Targets Windows 11 24H2/25H2 and Windows Server 2025. Pure Win32, no DbgHelp, no dependencies. Extracts MSV, WDigest, Kerberos, CredMan, DPAPI. AES-CFB128 and 3DES-CBC decryption via BCrypt
Dump password hashes and other useful info via .NET
Add a description, image, and links to the ntlm-hashes topic page so that developers can more easily learn about it.
To associate your repository with the ntlm-hashes topic, visit your repo's landing page and select "manage topics."