Skip to main content

Post-exploitation NTDS dump analyzer — correlates secretsdump output with hashcat potfiles to identify shared passwords and weak credentials in Active Directory

Project description

TattleTale

PyPI version PyPI downloads License: MIT Python 3.10+

Help

Analyze secretsdump output and hashcat potfiles to find shared passwords, weak credentials, and other issues in Active Directory. No dependencies.

Built from years of hands-on experience in enterprise penetration testing. Used in real-world assessments of Fortune 500 companies and critical infrastructure.

Install

pip

pip install ntds-tattletale

Then run it:

tattletale -d dump.ntds -p cracked.pot

Standalone

It's a single Python file with no dependencies. Grab it and go:

curl -O https://raw.githubusercontent.com/coryavra/tattletale/master/tattletale.py
python3 tattletale.py -d dump.ntds -p cracked.pot

Container

The included Containerfile works with Apple Containers (macOS 26+) and Docker (OCI-compliant).

# Apple Containers (native to macOS)
container build -t tattletale .
container run --rm -v "$(pwd)/data:/mnt/shared" tattletale \
    -d /mnt/shared/ntds.dit \
    -p /mnt/shared/cracked.pot \
    -o /mnt/shared/report

# Docker works too
docker build -t tattletale .
docker run --rm -v "$(pwd)/data:/mnt/shared" tattletale \
    -d /mnt/shared/ntds.dit \
    -p /mnt/shared/cracked.pot \
    -o /mnt/shared/report

Usage

tattletale -d <file> [-p <file>] [-t <files>] [options]

REQUIRED
    -d, --dit <file>            secretsdump output file

OPTIONS
    -p, --pot <file>            hashcat potfile with cracked hashes
    -t, --targets <files>       target lists (admins.txt, svc.txt, etc)
    -o, --output <dir>          export reports to directory
    -r, --redact-partial        show first 2 chars only (Pa**********)
    -R, --redact-full           hide passwords completely (************)
    -h, --help                  show help message
    -V, --version               show version

POLICY
    --policy-length <n>         minimum password length
    --policy-complexity <n>     require n-of-4 character classes (upper, lower, digit, symbol)
    --policy-no-username        password cannot contain username

Examples

# Basic analysis - just the dump file
tattletale -d ntds.dit

# With cracked hashes from hashcat
tattletale -d ntds.dit -p hashcat.pot

# Track high-value targets with multiple lists
tattletale -d ntds.dit -p hashcat.pot -t domain_admins.txt svc_accounts.txt

# Redacted output for client reports
tattletale -d ntds.dit -p hashcat.pot -r -o ./report

# Check cracked passwords against policy (8 chars, 3-of-4 complexity)
tattletale -d ntds.dit -p hashcat.pot --policy-length 8 --policy-complexity 3

Output

Statistics

Overview of the dump: total accounts, cracking progress, hash types, and security warnings like empty passwords or legacy LM hashes.

Statistics

High Value Targets

Shows the status of accounts from your target lists. Grouped by file so you can track domain admins separately from service accounts.

High Value Targets

Shared Credentials

Accounts that share the same password hash. Grouped by password with target accounts highlighted.

Shared Credentials

Password Analysis

Pattern analysis across all cracked passwords: length distribution, character composition, common patterns (seasons, years, keyboard walks), and most reused passwords.

Password Analysis

Input formats

File Format Example
DIT dump secretsdump output DOMAIN\user:1001:LM_HASH:NT_HASH:::
Potfile hashcat potfile NT_HASH:cleartext
Targets one username per line administrator

See also

Standing on the shoulders of giants:

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ntds_tattletale-3.1.0.tar.gz (16.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ntds_tattletale-3.1.0-py3-none-any.whl (16.6 kB view details)

Uploaded Python 3

File details

Details for the file ntds_tattletale-3.1.0.tar.gz.

File metadata

  • Download URL: ntds_tattletale-3.1.0.tar.gz
  • Upload date:
  • Size: 16.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for ntds_tattletale-3.1.0.tar.gz
Algorithm Hash digest
SHA256 fa8e90cc82f5a2a6e7327ad6ebba52da10f0479843d8eeba29e07ce958a76e32
MD5 edbf134cc1a9b198d28c86fcf4427cc1
BLAKE2b-256 453619ea190d73c954e66ea52bbe6429d369c3b518362ed997d453753df68696

See more details on using hashes here.

Provenance

The following attestation bundles were made for ntds_tattletale-3.1.0.tar.gz:

Publisher: publish.yml on coryavra/tattletale

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ntds_tattletale-3.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for ntds_tattletale-3.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 94c1aaa07ad4e6493ee54f02ac894c7fe488e1e5acd99f7f830826766133f518
MD5 673f632c7d67572b88fb48982082a3ed
BLAKE2b-256 277759504a03a554db4eb5383457ff39d1a24b7e6ab4d0b2f76ac0bfe24a5c1a

See more details on using hashes here.

Provenance

The following attestation bundles were made for ntds_tattletale-3.1.0-py3-none-any.whl:

Publisher: publish.yml on coryavra/tattletale

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page