Skip to main content

Password Audits
& Recovery Services

Proven Active Directory password security audits and recovery services for Fortune 500 enterprises and government agencies since 2015 with solutions that can be tailored to meet your specific needs.

2,000,000+
Real AD Hashes Cracked
200+
Supported Hash Formats
20+
Years Experience

Enterprise Services

Enterprise-Wide Password Security Audits

In-depth assessment of your organization's password security posture with clear remediation steps

Critical Document Recovery for Business Continuity

Rapid recovery of password-protected business-critical files during M&A, litigation, or emergency situations

Compliance Validation & Reporting

Meet regulatory requirements with executive-ready reports on password policy effectiveness

Key Capabilities

High-performance Distributed Cracking Grid

  • Secure, scalable, and extensible
  • Company-owned and -controlled compute (no cloud or third-party access)
  • 24/7/365 recovery efforts
  • Custom dictionary and rule development
  • Targeted brute force mask attacks

Periodic Active Directory Audits

  • Monthly, quarterly, etc.
  • Reports detailing audit results, policy violations, and historical trends
  • Managed on-prem solutions
  • Email alerting for enterprise deployments

Enterprise Solutions

Flexible engagement models designed for enterprise scale and compliance requirements

Enterprise Contract

Custom Pricing
  • Annual or multi-year contracts
  • Quarterly security audits
  • Executive reporting
  • Priority SLA support

On-Premises Solution

Dedicated Appliance
  • Deployed in your data center
  • No data leaves your network
  • Full administrative control
  • Training & support included
  • Regular updates & maintenance

Success Stories

Proven results with enterprise clients, government agencies, and critical business recovery

Fortune 500 Food & Beverage Company

99.8% Success Rate

Cracked 99.8% of 260,000 password hashes. Passwords complied with documented policies, but policies didn't prevent major trends and predictable user behavior. Identified administrators abusing privileges to reuse passwords, evading password history controls.

Impact: Complete policy overhaul and administrator privilege restructuring

Law Firm eDiscovery

Days vs. Months

A firm was processing thousands of password-protected Microsoft Office and PDF documents for eDiscovery. After commercial password cracking software proved ineffective, they engaged KoreLogic's PRS. We accomplished more in days than they had managed in months.

Impact: Urgent legal deadlines met with thousands of documents processed

Major Retailer Audit

84% in 24 Hours

Leveraged PRS to understand user compliance and satisfy audit requirements. 84% of the organization's 11,000 user passwords were found in 24 hours, leading to policy change discussions that ended with a complete revamp of their security policies.

Impact: Enterprise-wide security policy transformation and compliance achievement

Small Business Recovery

Livelihood Saved

A couple ran a small business together; the husband did all bookkeeping and kept business/personal financial account information in an encrypted spreadsheet. When he passed away suddenly, his wife couldn't access any information. We decrypted the spreadsheet, saving her hours of effort and immeasurable frustration.

Impact: Business and personal financial recovery during tragedy

Fortune 500 Legal Team

Custom Solution

Recovery of encrypted files from a CD used by a former employee of an acquired company. KoreLogic reverse-engineered the proprietary encryption to gain access to the files when standard approaches failed.

Impact: Key acquisition data recovered through specialized cryptanalysis

IRS Audit Emergency

Minutes

A private citizen being audited by the IRS urgently needed access to password-protected PDF files containing audit-relevant information. After unsuccessful attempts to recall/guess/recover passwords, PRS recovered the passwords in a fraction of a compute hour (mere minutes).

Impact: Urgent audit deadline met, potential penalties avoided