Skip to content

Network Credential Capture (PCredz)

PCredz extracts plaintext credentials and crackable authentication material from PCAPs or visible live traffic.

Quick start

Action Command
Parse a PCAP ./Pcredz -f capture.pcap -o pcredz-output
Parse captures recursively ./Pcredz -d captures/ -o pcredz-output
Capture live traffic sudo ./Pcredz -i <iface> -o pcredz-output
Include duplicate findings ./Pcredz -f capture.pcap -v -o pcredz-output

Output: pcredz-output/CredentialDump-Session.log and pcredz-output/logs/.

Extracted material

Traffic Material Output file
NTLM over SMB / HTTP / LDAP NetNTLMv1/v2 responses NTLMv1.txt / NTLMv2.txt
Kerberos AS-REQ (RC4 / etype 23) Crackable preauthentication data MSKerb.txt
Unencrypted HTTP Basic / forms Credentials and matching form fields HTTP-Basic.txt / HTTP-PasswordFields.txt
Unencrypted LDAP simple bind / FTP / SMTP Plaintext credentials LDAP-Simple.txt / FTP-Plaintext.txt / SMTP-Plaintext.txt
SNMPv1/v2c Community strings SNMPv1.txt / SNMPv2c.txt

Crack With Hashcat

Material Hashcat command
NetNTLMv1 hashcat -m 5500 pcredz-output/logs/NTLMv1.txt <wordlist>
NetNTLMv2 hashcat -m 5600 pcredz-output/logs/NTLMv2.txt <wordlist>
Kerberos AS-REQ, etype 23 hashcat -m 7500 pcredz-output/logs/MSKerb.txt <wordlist>
  • NetNTLM responses cannot be used for pass-the-hash. Relay requires live authentication.
  • Kerberos output is AS-REQ preauthentication, not AS-REP roast material.

Notes / OPSEC

  • Traffic must reach your interface through local connections, SPAN/TAP, or interception. Same-VLAN access and promiscuous mode alone do not expose switched unicast traffic.
  • PCredz does not poison, coerce authentication, relay, or decrypt TLS.
  • Live mode saves findings, not raw packets. Capture separately with tcpdump/Wireshark.
  • Capture both NTLM directions. A missing server challenge causes the parser to substitute zeros, producing unusable cracking material if the actual challenge differed.
  • HTTP form matches can be false positives; verify them against the PCAP.