In today's digital age, the risk of exposure to password breaches is higher than ever before, and this assessment will help you avoid falling into this typical security gap.
Cracking passwords is a common entry point for attackers. Our audit will identify the passwords used within your organization that need to be strengthened.
Highlight how frequently the same password is reused through the environment.
Evidence to push change towards a stronger password policy.
You’ll have one week of 24/7 dedicated cracking time on our multi-GPU cracking rig.
Along with our dedicated multi-GPU powered hardware with multiple high-end graphics cards, we will use brute force to crack your Active Directory users’ password hashes before providing you with the discovered metrics and insight into how many users are choosing passwords that have been previously disclosed in past breaches or can be cracked due to using predictable formats (e.g., Winter2023!).
Afterward, we’ll walk you through how to securely supply the password hashes for all domain users and then see how many can be guessed using an offline attack.
Schellman does perform password strength assessments—our Penetration Testing Team continues to grow and is currently comprised of individuals from different backgrounds including former developers, system administrators, and lifelong security professionals. Our team is incredibly experienced, and collectively holds the following professional certifications, among others:
Typically, we find that these assessments take 1 week of dedicated cracking time, plus a few days for report writing.
You can expect to pay no less than $10,000 for this type of assessment.
We provide custom tooling/scripts that query the domain for encrypted hashes which are then uploaded to our secure file storage for analysis.
Next, the hashes are transferred to our secure high-performance password-cracking machine. For a week, offline password cracking commences using Schellman-tailored password lists and password mutation rules. After this week, identified weak accounts will be reported upon with supporting evidence.