KnowsMore officially supports Python 3.8+.
Main features
- Import NTLM Hashes from .ntds output txt file (generated by CrackMapExec or secretsdump.py)
- Import NTLM Hashes from NTDS.dit and SYSTEM
- Import Cracked NTLM hashes from hashcat output file
- Import BloodHound ZIP or JSON file
- BloodHound importer (import JSON to Neo4J without BloodHound UI)
- Analyse the quality of password (length , lower case, upper case, digit, special and latin)
- Analyse similarity of password with company and user name
- Search for users, passwords and hashes
- Export all cracked credentials direct to BloodHound Neo4j Database as ‘owned object’
- Other amazing features…
Getting stats
knowsmore --statsThis command will produce several statistics about the passwords like the output bellow
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="KnowsMore v0.1.4 by Helvio Junior Active Directory, BloodHound, NTDS hashes and Password Cracks correlation tool https://github.com/helviojunior/knowsmore [+] Startup parameters command line: knowsmore –stats module: stats database file: knowsmore.db [+] start time 2023-01-11 03:59:20 [?] General Statistics +——-+—————-+——-+ | top | description | qty | |——-+—————-+——-| | 1 | Total Users | 95369 | | 2 | Unique Hashes | 74299 | | 3 | Cracked Hashes | 23177 | | 4 | Cracked Users | 35078 | +——-+—————-+——-+ [?] General Top 10 passwords +——-+————-+——-+ | top | password | qty | |——-+————-+——-| | 1 | password | 1111 | | 2 | 123456 | 824 | | 3 | 123456789 | 815 | | 4 | guest | 553 | | 5 | qwerty | 329 | | 6 | 12345678 | 277 | | 7 | 111111 | 268 | | 8 | 12345 | 202 | | 9 | secret | 170 | | 10 | sec4us | 165 | +——-+————-+——-+ [?] Top 10 weak passwords by company name similarity +——-+————–+———+———————-+——-+ | top | password | score | company_similarity | qty | |——-+————–+———+———————-+——-| | 1 | company123 | 7024 | 80 | 1111 | | 2 | Company123 | 5209 | 80 | 824 | | 3 | company | 3674 | 100 | 553 | | 4 | Company@10 | 2080 | 80 | 329 | | 5 | company10 | 1722 | 86 | 268 | | 6 | Company@2022 | 1242 | 71 | 202 | | 7 | Company@2024 | 1015 | 71 | 165 | | 8 | Company2022 | 978 | 75 | 157 | | 9 | Company10 | 745 | 86 | 116 | | 10 | Company21 | 707 | 86 | 110 | +——-+————–+———+———————-+——-+ ” dir=”auto”>
KnowsMore v0.1.4 by Helvio Junior
Active Directory, BloodHound, NTDS hashes and Password Cracks correlation tool
https://github.com/helviojunior/knowsmore[+] Startup parameters
command line: knowsmore --stats
module: stats
database file: knowsmore.db
[+] start time 2023-01-11 03:59:20
[?] General Statistics
+-------+----------------+-------+
| top | description | qty |
|-------+----------------+-------|
| 1 | Total Users | 95369 |
| 2 | Unique Hashes | 74299 |
| 3 | Cracked Hashes | 23177 |
| 4 | Cracked Users | 35078 |
+-------+----------------+-------+
[?] General Top 10 passwords
+-------+-------------+-------+
| top | password | qty |
|-------+-------------+-------|
| 1 | password | 1111 |
| 2 | 123456 | 824 |
| 3 | 123456789 | 815 |
| 4 | guest | 553 |
| 5 | qwerty | 329 |
| 6 | 12345678 | 277 |
| 7 | 111111 | 268 |
| 8 | 12345 | 202 |
| 9 | secret | 170 |
| 10 | sec4us | 165 |
+-------+-------------+-------+
[?] Top 10 weak passwords by company name similarity
+-------+--------------+---------+----------------------+-------+
| top | password | score | company_similarity | qty |
|-------+--------------+---------+----------------------+-------|
| 1 | company123 | 7024 | 80 | 1111 |
| 2 | Company123 | 5209 | 80 | 824 |
| 3 | company | 3674 | 100 | 553 |
| 4 | Company@10 | 2080 | 80 | 329 |
| 5 | company10 | 1722 | 86 | 268 |
| 6 | Company@2022 | 1242 | 71 | 202 |
| 7 | Company@2024 | 1015 | 71 | 165 |
| 8 | Company2022 | 978 | 75 | 157 |
| 9 | Company10 | 745 | 86 | 116 |
| 10 | Company21 | 707 | 86 | 110 |
+-------+--------------+---------+----------------------+-------+

