We extract and analyse Active Directory password hashes offline, identifying weak, reused, and compromised credentials that could give an attacker easy access to your network.
Password hashes are extracted and analysed offline using industry-standard cracking techniques. No passwords are tested against live systems, eliminating any risk of account lockouts.
We audit every account in your Active Directory environment, including service accounts, admin accounts, and dormant accounts that are often overlooked.
You receive a clear breakdown of password strength across your organisation, with specific recommendations to improve your password policy and reduce credential risk.
We agree the scope of the audit, access requirements, and any specific account types or domains to prioritise.
Secure extraction of NTLM password hashes from your domain controllers for offline analysis.
GPU-accelerated cracking using dictionary, rule-based, and brute force techniques, plus comparison against breached credential databases.
Broken passwords are categorised by pattern, length, duplication, and account privilege to surface the most impactful weaknesses.
Clear, categorised results showing password strength distribution, reuse patterns, and specific policy improvement recommendations.
Cracking success rates, pattern analysis with character mapping tables, duplicate password identification, password length distribution, and per-account scoring.
Practical guidance on improving password hygiene, including passphrase adoption strategies, policy recommendations, and user education advice.
A walkthrough of the results with your technical team, covering key findings, pattern trends, and priority actions, with time for questions.
Post-engagement support from the Illume team to answer questions about findings and remediation guidance.
Speak to a consultant about auditing your Active Directory credentials. We'll provide a fixed-price proposal, with no obligation.