discovered 03 Aug 2026
NTLMX
→ View on GitHubNTLMX is a post-exploitation tool designed for extracting local NTLM user password hashes from the Windows registry, supporting both modern AES-128-CBC techniques introduced in Windows 10 and traditional MD5/RC4 methods for earlier versions. The tool requires SYSTEM privileges to operate and can be easily installed via PowerShell Gallery or from the GitHub repository. It has been validated on multiple Windows versions, ensuring compatibility across various PowerShell environments.