Skip to main content

CredWolf

Credential validation tool for Active Directory Domain Services.

CI PyPI Python 3.11+ License: Apache 2.0 Docs

Installation • Quick start • Usage • CLI reference • Documentation • Contributing

CredWolf tests username and secret combinations (passwords, NT hashes, Kerberos keys, or ticket files) against a domain controller and reports which credentials are valid. It also supports username enumeration via Kerberos to discover valid AD accounts without causing login attempts. It is designed for authorized penetration testing, red team engagements, and security audits where you need to verify whether recovered or suspected credentials are active.

Full documentation

Features

  • NTLM + Kerberos - validate credentials over SMB, LDAP, LDAPS, and Kerberos pre-authentication (UDP/TCP)
  • Every secret type - passwords, NT hashes (bare + LM:NT), RC4 keys, AES128 keys, AES256 keys, and ticket files (ccache/kirbi with auto-detection)
  • Username enumeration - discover valid AD accounts via Kerberos without triggering login failures or lockouts; ASREProastable accounts flagged automatically
  • Username case correction - when using Kerberos AES authentication, the KDC returns the correct username casing in the salt. CredWolf detects this and uses the corrected name in all output
  • 88+ credential permutations - every meaningful combination of user sources, secret sources, encryption types, and transports
  • Paired files - user:password, user:hash, and user:key files for pre-matched credential testing
  • Machine-parseable output - domain/user:secret@type format, easy to grep or pipe
  • Safety-first errors - clock skew stops execution immediately, per-user skip on unknown/revoked principals, detailed account status detection
  • Rate limiting - --delay, --jitter, and --max-lockouts to avoid triggering lockout policies
  • Validation only - no post-authentication activity by design

Supported protocols

Protocol Transport Secret types
NTLM SMB (default), LDAP, LDAPS Password, NT hash
Kerberos UDP (default), TCP Password, RC4 key, AES128 key, AES256 key, ticket (ccache/kirbi)
Username enumeration UDP (default), TCP None required

Example

Validate a recovered password against a domain controller over SMB:

$ credwolf -d evil.corp ntlm --dc-ip 10.0.0.1 -u Administrator -p 'Password1!'
[+] evil.corp/Administrator:Password1!@password

Installation

Install from PyPI:

uv tool install credwolf        # recommended
pip install credwolf             # or with pip

Or install from source:

uv tool install git+https://github.com/StrongWind1/CredWolf

The cw command is also installed as a shorthand for credwolf.

See the installation guide for source and Docker options.

Quick start

# Validate a password over SMB
$ credwolf -d evil.corp ntlm --dc-ip 10.0.0.1 -u Administrator -p 'Password1!'
[+] evil.corp/Administrator:Password1!@password

# Validate an NT hash (pass-the-hash)
$ credwolf -d evil.corp ntlm --dc-ip 10.0.0.1 -u Administrator --hash 7facdc498ed1680c4fd1448319a8c04f
[+] evil.corp/Administrator:7facdc498ed1680c4fd1448319a8c04f@nt_hash

# Validate an AES256 key over Kerberos (pass-the-key)
$ credwolf -d evil.corp kerberos --kdc-ip 10.0.0.1 -u Administrator --aes256-key 9b12da6a4bdc263c1ac8f6302dc071e6e84321a263fa48784534b1ae43db2925 --transport tcp
[+] evil.corp/Administrator:9b12da6a4bdc263c1ac8f6302dc071e6e84321a263fa48784534b1ae43db2925@aes256_key

# Enumerate valid usernames (no login attempts, no lockout risk)
$ credwolf -d evil.corp userenum --kdc-ip 10.0.0.1 -U users.txt
[+] evil.corp/Administrator
[+] evil.corp/svc_backup - no_preauth (ASREProastable)
[*] Enumeration complete: 2/5 users found

See the full usage guide and CLI reference for all options.

Development

git clone https://github.com/StrongWind1/CredWolf.git
cd CredWolf
uv sync                        # install dev dependencies
make check                     # run lint + typecheck + tests

Conventional commit messages (feat:, fix:, docs:); run make check before every commit.

Credits

Built on Impacket. Inspired by CrackMapExec, Kerbrute, smartbrute, and SprayHound.

Related tools

Other projects in this collection:

  • AD-SecretGen - derive AD password hashes and Kerberos keys from a password
  • NTDSWolf - offline NTDS.dit parser and credential extractor
  • KerbWolf - Kerberos roasting and hash extraction toolkit
  • Kerberos - Kerberos in Active Directory: protocol, security, and attacks

Disclaimer

CredWolf is intended for authorized penetration testing, red team engagements, and security audits only. You must have explicit written permission from the system owner before testing credentials against any Active Directory environment. Unauthorized access to computer systems is illegal. The authors are not responsible for any misuse or damage caused by this tool.

License

Apache License 2.0

Metadata

Release files for credwolf 1.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for credwolf 1.2.1
File Size Uploaded
credwolf-1.2.1.tar.gz 1.8 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for credwolf 1.2.1
File Interpreter ABI Platform
credwolf-1.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 1.9 MB

Release files / credwolf-1.2.1.tar.gz

Download URL credwolf-1.2.1.tar.gz
Size 1.8 MB
Tags Source
SHA-256 checksum
How to use checksums
4849fb18ee4dbb839c10b7e1de1005493e7b52ed417994c422cebba33cf9aff6
BLAKE2b-256 checksum
How to use checksums
1c6b28b74f78013cacc1e85e102cac0709e665c668b25e39c1d114a4e99f5f03
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.

Transparency log

Release files / credwolf-1.2.1-py3-none-any.whl

Download URL credwolf-1.2.1-py3-none-any.whl
Size 35.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3792ba65fa53ec98e63b52c916560c74c5e77b273602d2c00a50a37e79faa26f
BLAKE2b-256 checksum
How to use checksums
817d6d8ab0113ab22252cbd75f3d6ff8b5647d506a27a2ea4110e6ea05e9d446
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.2.1 This release

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page