Description
This module uses John the Ripper or Hashcat to identify weak passwords that have been acquired from Windows systems. LANMAN is format 3000 in hashcat. NTLM is format 1000 in hashcat. MSCASH is format 1100 in hashcat. MSCASH2 is format 2100 in hashcat. NetNTLM is format 5500 in hashcat. NetNTLMv2 is format 5600 in hashcat. krb5tgs is format 13100 in hashcat. krb5tgs-aes128 is format 19600 in hashcat. krb5tgs-aes256 is format 19700 in hashcat. krb5asrep is format 18200 in hashcat. timeroast is format 31300 in hashcat.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/analyze/crack/windowsmsf undefined(windows) > show actions ...actions...msf undefined(windows) > set ACTION < action-name >msf undefined(windows) > show options ...show and set options...msf undefined(windows) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub