SnaffCon/Snaffler
a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax ) observed · 2026-08-28
Health v2 · maintenance only
76/100
- Activity 69
- Release rhythm 72
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 18.5
- age_days: 2347
- days_rel: 188
- days_push: 188
- n_releases_24m: 11
Adoption not part of the score
2915 stars · 283 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Snaffler is a C# command-line tool for pentesters and red teamers that enumerates Windows/AD environments to find sensitive files (mostly credentials) on readable network file shares. It discovers domain computers and shares, then scans files using regex-based rules to flag interesting content.
Use cases
- find credentials in windows file shares during a pentest
- enumerate active directory shares for sensitive files
- red team internal recon for juicy files
- scan a network share directory for secrets
- hunt for passwords in a large AD environment
When to choose
- you are a pentester or red teamer assessing a Windows/AD environment
- you need to quickly locate credential material on readable file shares
- you want a single portable exe that runs on a domain-joined machine
When to avoid
- you need a compliance or audit tool - it is explicitly not designed for that
- you are not on a Windows/Active Directory environment
- you need ML-based file classification rather than regex rules
Facets
cli-tool · maturity active
security search-engine cli security penetration-testing windows windows cli dotnet red-team pentesting active-directory file-share-enumeration credential-hunting csharp
1 source
- readme: https://github.com/SnaffCon/Snaffler · fetched 2026-08-28 · 00174f1fdd81
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| SnaffCon/Snaffler | main | 76 |
For agents
markdown · JSON · MCP: product_card(name="SnaffCon/Snaffler")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem