{"adoption": {"forks": 176, "observed_at": "2026-08-28T04:04:49.206047+00:00", "stars": 1470}, "canonical_url": "https://ross.abutalabs.com/products/ntlm_theft", "card": {"archived": false, "artifact_type": "cli-tool", "description": "A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)", "domain": ["security", "penetration-testing", "developer-tools"], "enriched": true, "function": ["security", "penetration-testing", "cli"], "health_score": 46, "homepage": null, "language": "Python", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["Greenwolf/ntlm_theft"], "name": "Greenwolf/ntlm_theft", "platform": ["python", "cli", "cross-platform"], "pushed_at": "2025-09-22T14:28:27+00:00", "repo": "Greenwolf/ntlm_theft", "stars": 1470, "tags": ["ntlmv2", "hash-theft", "red-team", "phishing", "smb", "responder", "offensive-security"], "topics": [], "urls": [], "use_cases": ["generate NTLMv2 hash theft files for internal phishing during a penetration test", "capture NTLMv2 hashes from employees who open malicious documents", "mass test antivirus and email gateway detection of hash theft file types", "create phishing payloads for targets with outbound SMB access", "quickly enumerate which file types can trigger NTLM authentication on Windows", "generate .url, .lnk, .docx, .xlsx, and .pdf files that leak NTLMv2 hashes to an SMB capture server"], "what_it_is": "ntlm_theft is a Python3 CLI tool that generates 21 different types of NTLMv2 hash theft files (e.g., .url, .scf, .docx, .pdf, .jnlp) that trigger SMB authentication when opened by a target. It is designed for penetration testers and red teamers to capture NTLMv2 hashes via a hash capture server such as Responder or impacket-smbserver.", "when_to_avoid": ["you need a stealthy, fully undetectable red team tool - many generated file types are known signatures", "you are looking for a defensive detection tool rather than an offensive generator", "your target environment blocks all outbound SMB traffic and you are not on the internal network", "you need macro-based or exploit-based document attacks rather than 'intended functionality' techniques"], "when_to_choose": ["you are a penetration tester or red teamer performing internal phishing engagements", "you need to capture NTLMv2 hashes from Windows hosts via SMB", "you want to test email gateways or antivirus against hash theft file types", "you need a quick way to generate many hash theft file variants at once"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/ntlm_theft", "repo": "Greenwolf/ntlm_theft", "role": "main", "score": 52}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.206047+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:34:47.650855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3ccf36eaf2bd5c1601e6ad26491124c633fec12cd70e2bd6a85ae212e861a708", "fetched_at": "2026-08-28T04:04:49.206047+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Greenwolf/ntlm_theft"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 43, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2276, "days_push": 345, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 52, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}