Finds shares you did not know about
NoCredEx finds every share in your network, including hidden ones, those behind DFS namespaces and forgotten folders on admin PCs. It scans what really exists, not just what is on a list.
NoCredEx finds passwords, API keys, connection strings and much more on your shares, from one Windows PC or server. Coming soon.
Almost done.
You will receive an email from us shortly. Please click the confirmation link in it; only then are you on the list. No email? Please check your spam folder too.
Not zero-days. Files that someone saved and nobody deleted.
“Teams regularly find drives containing cleartext credentials for service accounts, web applications, and even domain administrators.”
controlled through one domain service account whose password sat in plaintext in an XML file. Found without any admin rights.
XML file on an SCCM distribution point CISA AA26-237Afrom getting in until LockBit started encrypting the entire network. On the way, the attackers found a text file with the Domain Admin password.
Text file on a file server The DFIR Reportwith the admin password for Uber's password vault. According to the attacker, that opened AWS, Google Cloud and Slack.
PowerShell script on a network share BleepingComputerNoCredEx is a Windows application that needs neither an installation on the file servers nor a cloud.
NoCredEx finds every share in your network, including hidden ones, those behind DFS namespaces and forgotten folders on admin PCs. It scans what really exists, not just what is on a list.
Detects passwords, API keys, private keys, tokens and connection strings, plus rule packs for AWS, Azure, GitHub and many more. Every finding is rated by severity, so you know what to fix first.
Runs on a Windows PC or server and reads Windows, Samba and NAS shares. Nothing is installed on the file servers, and files are only ever read.
Set up once on a Windows server, NoCredEx checks your shares automatically as a service: daily, hourly or on your own schedule. Because it only reads changed files, even large shares are done in minutes.
Once a password is removed from the file, the next scan closes the finding and records how long the fix took. Findings marked as false positives do not come back.
Whether five shares or five hundred: where needed, you decide who is responsible for each share. That person receives new findings automatically by Teams, Slack or email.
See at a glance whether your risk is falling: open findings over time, time to remediate, SLA compliance per severity and passwords that sit on several servers. The reports are suitable as evidence for audits, for example under ISO 27001 or NIS2.
No extra portal to watch: after every scan NoCredEx sends critical findings to your SIEM, to Teams or another integration. The password itself is never transmitted.
NoCredEx finds credentials on your shares before an attacker does. Optionally it also searches your network for unknown shares and forgotten shared folders on admin PCs, and reports critical findings automatically via Teams, Slack, email or syslog.
A credential scanner, also called a secret scanner, searches files for credentials that should not be there: passwords, API keys, tokens, private keys and connection strings. NoCredEx is built for network drives and SMB shares: scripts, configuration files and documents on Windows file servers, Samba and NAS systems and shared folders on admin PCs. Every finding is rated by severity, and the password itself is never stored.
NoCredEx is currently in quality assurance and will be released soon. When it is ready, you will be the first to get an email, before the public announcement.
Yes. For quality assurance we are looking for a few companies that test NoCredEx in their own environment before the release and give us feedback. Write to office@nocredex.at, ideally with a few details about your environment, such as the number of file servers and the systems you use (Windows, Samba, NAS).
Nothing. You only receive the confirmation of your signup and one email as soon as NoCredEx is available for download.
No. The software runs entirely inside your network. Found credentials exist only in memory during the scan and are never written to disk, exported or transmitted.
No. NoCredEx runs entirely inside your network and can be operated completely offline. Machines without internet access can be activated too: the app creates an activation code, you enter it on our website from any device with internet access and then transfer the activation into the app. Integrations such as Teams or Slack are optional.
NoCredEx is developed in Austria by Bernhard Bruckner, Dipl.-Ing., BSc. Behind it are a degree in information security from St. Pölten University of Applied Sciences and more than 13 years in IT as an administrator, software developer and most recently cybersecurity specialist in a corporate environment. More at bbruckner.at.
One email address. A confirmation now, one email when it launches.
Almost done.
You will receive an email from us shortly. Please click the confirmation link in it; only then are you on the list. No email? Please check your spam folder too.
No newsletter, no resale of your address, unsubscribe any time via the link in our emails.