
Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to extract AD details and internal IPs.
__ __ __
____ / /_/ /___ ___ ______________ __ __/ /_
/ __ \/ __/ / __ `__ \/ ___/ ___/ __ \/ / / / __/
/ / / / /_/ / / / / / (__ ) /__/ /_/ / /_/ / /_
/_/ /_/\__/_/_/ /_/ /_/____/\___/\____/\__,_/\__/
hunting exposed NTLM
BoydHacks · github.com/BoydHacks
One tool to squeeze every drop of information out of internet-exposed NTLM endpoints.
An unauthenticated NTLM negotiation leaks a surprising amount of internal Active Directory detail before a single credential is ever sent. ntlmscout sends an NTLM Type-1 (NEGOTIATE) message across a wide range of transports, fully decodes the Type-2 (CHALLENGE) that comes back, and pulls out everything: internal NetBIOS/DNS host and domain names, the AD forest, the OS build (mapped to a friendly Windows version), the server clock (and skew), negotiate flags, and every AV_PAIR — then enriches it with adjacent unauthenticated disclosures and an optional, lockout-safe password spray.
Pure standard library. Single file. Python 3.7+. No dependencies.
IOXIDResolver::ServerAlive2 (TCP 135), and TLS/RDP certificate IP SANs.X-FEServer/X-CalculatedBETarget header leaks, and anonymous LDAP rootDSE enrichment (naming contexts, dnsHostName, AD functional levels).git clone https://github.com/BoydHacks/ntlmscout
cd ntlmscout
python3 ntlmscout.py --help
No pip install, no virtualenv — it only uses the Python standard library.
# recon a single IP or host (full sweep of every NTLM-capable port)
python3 ntlmscout.py 203.0.113.10
python3 ntlmscout.py mail.example.com
# a specific endpoint, or a whole range, or a target list
python3 ntlmscout.py https://mail.example.com/ews/
python3 ntlmscout.py 10.0.0.0/24
python3 ntlmscout.py -I targets.txt --json results.json
# route everything through Burp / a CONNECT proxy
python3 ntlmscout.py -I targets.txt --proxy 127.0.0.1:8080
# lockout-safe password spray against the best endpoint
python3 ntlmscout.py --spray -I hosts.txt -u users.txt -p 'Winter2026!' --delay 1800
Recon is a full sweep by default. Trim it with --no-discover (skip the HTTP path wordlist) or --no-internal-ip (skip the cert/OXID/IIS checks). See --help for the full menu.
========================================================================
HOST: 203.0.113.10 (EXCH01.corp.example.com)
------------------------------------------------------------------------
External address : 203.0.113.10
Internal address : 10.0.0.25
Realm : CORP
Realm type : domain
NetBIOS host : EXCH01
NetBIOS domain : CORP
DNS host : EXCH01.corp.example.com
DNS domain : corp.example.com
DNS forest : corp.example.com
OS : Windows Server 2019
OS build : 10.0.17763
Server time (UTC) : 2026-01-01 12:00:00
Time skew (s) : -0.1
Role : Domain member
NTLM endpoints identified: 4
- https://203.0.113.10/ews/
- https://203.0.113.10/rpc/
- https://203.0.113.10/autodiscover/
- smb://203.0.113.10:445
========================================================================
[+] 4 exposed NTLM endpoint(s) on 1 of 1 host(s).
The discovered endpoints are listed on-screen automatically. Add -o log.txt
for a full per-field log, or --json/--csv for machine-readable output.
Spray mode is opt-in and hardwired to password-spray ordering — one password is tried across every account per round, so no account ever sees more than one attempt per round. Set --delay to the target's lockout observation window and confirm the lockout policy before running. It reports valid, cleanly-rejected, and inconclusive results separately so a negative result is trustworthy rather than an artifact of a broken oracle.
ntlmscout stands on the shoulders of the researchers and tools that pioneered NTLM endpoint reconnaissance. Their ideas, techniques, and endpoint wordlists directly informed this project:
*-ntlm-info NSE scripts — Justin Cacak (http/imap/pop3/smtp/nntp/telnet/ms-sql) and Tom Sellers (rdp): the per-protocol recipes for coaxing a Type-2 out of each service.IOXIDResolver::ServerAlive2 internal-address technique and NTLM relay/posture concepts.Protocol details follow Microsoft's [MS-NLMP] Open Specification and Eric Glass's classic davenport NTLM notes. The IIS internal-IP disclosure is CVE-2000-0649.
If your work belongs here and I've missed you, open an issue — credit is due and I'll add it.
BoydHacks — github.com/BoydHacks