How many #DFIR people are encountering hashed known_hosts files in the wild? Makes tracking lateral movement much more painful @hal_pomeranz
2
3
10
Replying to @attrc
@attrc Still uncommon in my cases. Btw, have you seen the "known hosts bruteforcer" script? See my github-- I contributed a bit of code.

Nov 2, 2015 · 8:23 PM UTC

1
1
Replying to @hal_pomeranz
@hal_pomeranz @attrc John the Ripper has known_hosts support as well - convert first with included known_hosts2john.py [fixed typo]