hash-sentinel
Version, currently latest1 version
- latestlatestApr 8, 2025
github.com/evait-security/hash-sentinel
No description declared in shard.yml.
Installation
# Add this to your shard.yml
dependencies:
hash-sentinel:
github: evait-security/hash-sentinel
version: ~> latestThen run:
shards installshard.yml
- Crystal
>= 1.0.0- License
- MIT
- Author
- FLX
- Target
hash-sentinelfrom src/hash_sentinel.cr
Dependencies
This version declares no dependencies.
README
π Hash Sentinel
Hash Sentinel is a handy and efficient Crystal tool designed to quickly identify users in an Active Directory environment who share identical NT hashes (passwords). Itβs a powerful addition to a penetration testerβs toolkit, especially useful during post-exploitation phases, domain takeovers, and password policy assessments.
π Introduction
When conducting penetration tests, especially after compromising a Windows domain environment, itβs crucial to analyze password usage across domain accounts. Identifying users with identical passwords helps assess password hygiene, detect shared administrative passwords, and pinpoint critical security issues.
After you've successfully taken control of an Active Directory domain (for example, by obtaining Domain Admin credentials), you typically extract the NTDS database dump. Here's a typical scenario to generate such a dump with Impacket's secretsdump.py:
secretsdump.py DOMAIN/Administrator:'Password123'@192.168.0.10 -outputfile full_domain_dump.txt -user-status
After obtaining the dump, you can filter out enabled users and exclude machine accounts with:
cat full_domain_dump.txt.ntds | grep 'status=Enabled' | cut -d " " -f 1 | grep -v '\$' > enabled_users_dump.ntds
Now, to detect users sharing the same password efficiently, Hash Sentinel helps you analyze this filtered data quickly and effortlessly.
π Installation
Ensure Crystal is installed (https://crystal-lang.org/install/).
Clone this repository:
git clone https://github.com/your_username/hash-sentinel.git
cd hash-sentinel
shards install
π§ Building from Source
Build the executable binary with the following command:
crystal build --release src/hash_sentinel.cr -o hash-sentinel
Now, the binary hash-sentinel will be created in your project directory.
βΆοΈ Running the Binary
After building the binary, you can easily analyze your NT hash dumps. Run it using the following command structure:
./hash-sentinel -f enabled_users_dump.ntds
Command Line Parameters
| Parameter | Description | Example |
|---|---|---|
-f | Path to input file containing user hashes | -f enabled_users_dump.ntds |
-h | Display help information | -h |
π Usage Example
πΉ Input File Example (enabled_users_dump.ntds):
john.doe:1000:aad3b435b51404eeaad3b435b51404ee:88e4d9fabaecf3dec18dd80905521b29:::
jane.smith:1001:aad3b435b51404eeaad3b435b51404ee:e52cac67419a9a224a3b108f3fa6cb6d:::
mark.brown:1002:aad3b435b51404eeaad3b435b51404ee:88e4d9fabaecf3dec18dd80905521b29:::
πΉ Command:
./hash-sentinel -f enabled_users_dump.ntds
πΉ Output Example:
π Analyzing NT hashes...
β οΈ Duplicate password found: john.doe, mark.brown
π‘οΈ Why Use Hash Sentinel?
- Quickly identifies weak password policies.
- Detects password reuse across user accounts.
- Facilitates security reporting and actionable recommendations.
- Simplifies large-scale password audits.
π Practical Workflow Example
A full practical example of a penetration testing workflow with hash-sentinel:
Step 1: Extract NTDS dump using Impacket (requires Domain Admin privileges):
secretsdump.py DOMAIN/Admin:'Passw0rd!'@10.10.10.100 -outputfile domain_dump.txt -user-status
Step 2: Extract only enabled user accounts (excluding machine accounts):
cat domain_dump.txt.ntds | grep 'status=Enabled' | cut -d " " -f 1 | grep -v '\$' > enabled_users_dump.ntds
Step 3: Run hash-sentinel:
./hash-sentinel -f enabled_users_dump.ntds
π License
MIT License
Happy Hacking! π
Documentation
Built from the current release. The first visit to a release nobody has asked for starts its build.
Links
This release
- Version
latest- Tagged
- Apr 8, 2025
- Commit
abcdca2d2a8a- Crystal
>= 1.0.0- Indexed
- yes
Dependents
No indexed shard depends on this one yet.
Repository
github.com/evait-security/hash-sentinel
Metadata
- Created
- Aug 12, 2026
- Updated
- Aug 13, 2026
- Synced
- Aug 13, 2026
- Versions
- 1