CredsHunter is a read-only credential discovery toolkit for authorized internal penetration testing and post-exploitation.
It searches Linux and Windows hosts for credential material that is realistically useful during an engagement: plaintext passwords, database connection strings, private keys, credential containers, reusable hashes, shell-history credentials, GPP cpassword values, unattended-install credentials, and other high-value local artifacts.
The project deliberately does not target cloud / SaaS access tokens such as JWTs, AWS access keys, GitHub tokens, Slack tokens, or generic API keys. Those artifacts frequently create noise during internal assessments and are usually less useful for host-to-host lateral movement.
- Reuse-focused — prioritize credentials that can support privilege escalation or lateral movement.
- Read-only — never modify the target system.
- Network-silent — never transmit discovered data.
- Low-noise — tuned filters suppress common false positives.
- Cross-platform — matching Linux and Windows workflows.
- Operator-friendly — live findings, grouped severity tiers, plain-text logging, stage controls, and clean interruption handling.
CredsHunter uses a five-stage funnel that narrows from known credential locations to recursive content inspection.
| Stage | Focus | Examples |
|---|---|---|
| 1 | OS & application credential stores | Registry, GPP, histories, vaults, keys, saved sessions, known credential locations |
| 2 | Confirmed credential containers | .kdbx, .ppk, .pfx, .p12, .keytab, keystores and similar containers |
| 3 | High-value file types | Private keys, .env, backups, databases, captures, archives, configuration files |
| 4 | Suspicious filenames | *password*, *secret*, *credential*, *login*, *account* |
| 5 | Content scan | 70+ tuned credential regexes with false-positive filtering |
Stages 1 and 5 perform the deepest inspection. Stages 2–4 are intentionally fast filename and extension passes.
Each finding is filtered before it reaches the final results, and findings are surfaced as the scan progresses rather than being hidden until the end.
git clone https://github.com/NeCr00/Credential-Hunting.git
cd Credential-Hunting
chmod +x credshunter.sh
sudo ./credshunter.sh -p / -o loot.txtgit clone https://github.com/NeCr00/Credential-Hunting.git
cd Credential-Hunting
.\credshunter.ps1 -Path C:\ -OutputFile loot.txtElevated execution is recommended when you want access to protected credential locations such as SAM / SYSTEM hives, vault directories, or other privileged stores.
Full host sweep with findings written to a file:
sudo ./credshunter.sh -p / -o loot.txtScan selected locations only:
./credshunter.sh -p /home -p /var/www -p /optTargeted scan without the slower recursive content stage:
./credshunter.sh -p /var/www -p /home --no-stage5Exclude a directory tree:
./credshunter.sh -p / -x /var/lib/customer-appFull C:\ sweep:
.\credshunter.ps1 -Path C:\ -OutputFile loot.txtScan multiple locations:
.\credshunter.ps1 -Path C:\Users,C:\inetpubWeb / database host with SQL and CSV-style data scanning enabled:
.\credshunter.ps1 -Path D:\ -IncludeDataDisable built-in system / vendor exclusions:
.\credshunter.ps1 -Path C:\ -NoDefaultExcludeCredsHunter is pipe-friendly. Use --no-color on Linux or -NoColor on Windows when redirecting or filtering output.
Results are grouped by usefulness and confidence, with the most important findings shown first.
| Tag | Meaning |
|---|---|
[CRITICAL] |
Confirmed credential container |
[HIGH] |
Reusable password, hash, GPP cpassword, or equivalent credential material |
[KEY] |
Private key or other key material, including readable SAM / SYSTEM hive findings |
[INTEREST] |
High-value file or location worth manual review |
[NAME] |
Suspicious filename — useful as a review hint |
A sensitive result in CRITICAL, HIGH, or KEY causes a non-zero sensitive-findings exit status. INTEREST and NAME findings alone do not.
For example:
./credshunter.sh -p /etc && echo "No high-confidence credential findings"| Goal | Linux | Windows |
|---|---|---|
| Add scan paths | -p PATH / --path PATH |
-Path PATH |
| Exclude paths | -x PATH / --exclude PATH |
-ExcludePath PATH |
| Scan every readable text file in Stage 5 | -a / --all |
-All |
| Change file-size cap | -m N / --max-size N |
-MaxFileSizeMB N |
| Disable size cap | --no-size-limit |
-NoSizeLimit |
| Write findings to file | -o FILE / --output FILE |
-OutputFile FILE |
| Skip OS-level checks | -s / --skip-system / --no-stage1 |
-SkipSystem / -NoStage1 |
| Skip a stage | --no-stage2 ... --no-stage5 |
-NoStage2 ... -NoStage5 |
| Reduce status output | -q / --quiet |
-Quiet |
| Disable ANSI colors | --no-color |
-NoColor |
| Include SQL / CSV-style data files | — | -IncludeData |
| Disable default vendor/system exclusions | — | -NoDefaultExclude |
The default maximum file size is 5 MB. Increase it when credentials may live in larger logs, dumps, or configuration exports, or disable the cap when appropriate.
The pattern libraries and file-type lists are intentionally kept in clearly labeled configuration arrays inside each script.
You can extend or trim:
- Stage 2 credential-container extensions
- Stage 3 high-value file types and exact filenames
- Stage 4 suspicious filename tokens
- Stage 5 content-scan extensions
- Credential detection patterns
- False-positive filters
Edit the relevant list in one place; the scanning workflow does not need to be rewritten.
| Platform | Requirements |
|---|---|
| Linux | Bash 4+, find, grep, awk, sed, stat |
| Linux — optional | realpath, file |
| Windows | PowerShell 5.1+ |
| Privileges | Elevated execution is optional, but increases visibility into protected credential locations |
The Linux implementation is designed for common distributions including Debian/Ubuntu, RHEL-family systems, Arch, and Alpine.
Does CredsHunter change anything on the host?
No. The scanner is read-only. It writes only to the output file you explicitly choose, does not transmit findings over the network, and cleans up its temporary working data on exit.
Why are AWS, GitHub, Slack, JWT, and generic API tokens ignored?
By design. CredsHunter is optimized for credentials that are useful for local privilege escalation and in-network lateral movement. Cloud and SaaS tokens are a major source of false-positive noise during this type of assessment.
Local cloud-CLI credential files and locations may still be surfaced for review; the tool simply avoids treating generic cloud/SaaS token patterns as primary reusable-credential findings.
Stage 5 is slow. How can I speed it up?
Narrow the scope with -p / -Path, exclude noisy trees, keep the default file-size limit, or skip the recursive content scan with --no-stage5 / -NoStage5.
A credential was missed. What should I check?
Confirm that the target file:
- Is inside the selected scan path.
- Is not inside an excluded path.
- Is below the configured size limit.
- Uses an extension included in Stage 5.
For a broader check, use -a / --all on Linux or -All on Windows.
For deeper project documentation, usage notes, and additional information, visit the Credential-Hunting Wiki.
Contributions are welcome.
If you have a useful credential pattern, a false-positive reduction, a platform-specific credential location, or an improvement to scan performance and output quality, feel free to open an issue or pull request.
CredsHunter is intended for authorized security testing, internal penetration testing, red-team engagements, labs, and CTF environments.
Only run it on systems you own or have explicit permission to assess.