{"repo":"pwnfoo/NTLMRecon","free":true,"listed":false,"github":"https://github.com/pwnfoo/NTLMRecon","clone":"git clone https://github.com/pwnfoo/NTLMRecon.git","description":"Enumerate information from NTLM authentication enabled web endpoints 🔎","language":"Python","stars":509,"topics":["redteam","ntlm","security","cybersecurity","reconnaissance","recon","tools","osint","enumeration","hacking"],"license":"MIT","category":"security-tools","readme_excerpt":"NTLMRecon An NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains. NTLMRecon is built with flexibilty in mind. Need to run recon on a single URL, an IP address, an entire CIDR range or combination of all of it all put in a single input file? No problem! NTLMRecon got you covered. Read on. Overview NTLMRecon looks for NTLM enabled web endpoints, sends a fake authentication request and enumerates the following information from the NTLMSSP response: 1. AD Domain Name 2. Server name 3. DNS Domain Name 4. FQDN 5. Parent DNS Domain Since NTLMRecon leverages a python implementation of NTLMSSP, it eliminates the overhead of running Nmap NSE http-ntlm-info for every successful discovery. On every successful discovery of a NTLM enabled web endpoint, the tool enumerates and saves information about the domain as follows to a CSV file : URL Domain Name Server Name DNS Domain Name FQDN DNS Domain -------------------------- ------------- ------------- ------------------- ------------------------------ ------------- https://contoso.com/EWS/ XCORP EXCHANGE01 xcorp.contoso.net EXCHANGE01.xcorp.contoso.net contoso.net Installation BlackArch NTLMRecon is already packaged for BlackArch and can be installed by running pacman -S ntlmrecon Build from source 1. Clone the repository : git clone https://github.com/pwnfoo/ntlmrecon/ 2. RECOMMENDED - Install virtualenv : pip install ","default_branch":null,"files":null,"tree":[],"storefront":"/r/pwnfoo","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/pwnfoo/NTLMRecon/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}