Coming soon
Credential scanner for network shares

Somewhere on your file servers, a password from 2019 still works.

NoCredEx finds passwords, API keys, connection strings and much more on your shares, from one Windows PC or server. Coming soon.

Almost done.

You will receive an email from us shortly. Please click the confirmation link in it; only then are you on the list. No email? Please check your spam folder too.

More than 140 detection rules 0 agents on your file servers Developed in Austria 100 % on-premises
NoCredEx– No Credentials ExposedDiscoveryScanFindingsDashboard
ScopeOU=FileServers · 10.0.20.0/24
incl. hidden shares
\\fs01\IT
\\fs01\Scripts
\\fs01\DevOps$hidden
\\nas-hr\Archive
\\fs02\Backup$hidden
5 shares found, 2 hidden
Targets3 shares · \\fs01\IT, \\fs01\Scripts, \\fs01\DevOps$
140+ rules
0 / 19,203 files0 findings
All 5CRIT 2HIGH 2MED 1
Crit\\fs01\IT\Deploy\web.config : 6Connection StringOpen
Crit\\fs01\Scripts\nightly-backup.ps1 : 14Service AccountOpen
High\\fs01\DevOps$\.env : 2AWS Access KeyOpen
High\\fs01\IT\Certs\api-client.pem : 1Private KeyOpen
Med\\fs01\IT\Deploy\web.example.config : 6Connection StringOpen
\\fs01\IT\Deploy\web.config
5<connectionStrings>
6<add name="ERP" connectionString="Server=sql01;Password=Summer2019!" />
7</connectionStrings>
\\fs01\IT\Deploy\web.example.config
5<!-- template: replace before deployment -->
6<add name="ERP" connectionString="Server=sql01;Password=changeme" />
7</connectionStrings>
One week after the first scan
Open findings5at first scan: 5
Time to remediate2.0 dayscritical: 1.1 days
SLA compliance80 %1 critical over 24 h

Three incidents, one pattern: the password was in a file on a server.

Not zero-days. Files that someone saved and nobody deleted.

“Teams regularly find drives containing cleartext credentials for service accounts, web applications, and even domain administrators.”
NSA and CISA, Top Ten Cybersecurity Misconfigurations, number 8 of 10 · AA23-278A
  1. 2026-08 ~1,000 accounts

    controlled through one domain service account whose password sat in plaintext in an XML file. Found without any admin rights.

    XML file on an SCCM distribution point CISA AA26-237A
  2. 2024-02 2 hours

    from getting in until LockBit started encrypting the entire network. On the way, the attackers found a text file with the Domain Admin password.

    Text file on a file server The DFIR Report
  3. 2022-09 1 script

    with the admin password for Uber's password vault. According to the attacker, that opened AWS, Google Cloud and Slack.

    PowerShell script on a network share BleepingComputer

Features at a glance

NoCredEx is a Windows application that needs neither an installation on the file servers nor a cloud.

Finds shares you did not know about

NoCredEx finds every share in your network, including hidden ones, those behind DFS namespaces and forgotten folders on admin PCs. It scans what really exists, not just what is on a list.

More than 140 detection rules

Detects passwords, API keys, private keys, tokens and connection strings, plus rule packs for AWS, Azure, GitHub and many more. Every finding is rated by severity, so you know what to fix first.

No agents, read-only

Runs on a Windows PC or server and reads Windows, Samba and NAS shares. Nothing is installed on the file servers, and files are only ever read.

Keeps watching your shares

Set up once on a Windows server, NoCredEx checks your shares automatically as a service: daily, hourly or on your own schedule. Because it only reads changed files, even large shares are done in minutes.

Closed automatically once fixed

Once a password is removed from the file, the next scan closes the finding and records how long the fix took. Findings marked as false positives do not come back.

One responsible person per share

Whether five shares or five hundred: where needed, you decide who is responsible for each share. That person receives new findings automatically by Teams, Slack or email.

Progress you can prove

See at a glance whether your risk is falling: open findings over time, time to remediate, SLA compliance per severity and passwords that sit on several servers. The reports are suitable as evidence for audits, for example under ISO 27001 or NIS2.

Alerts straight to your SIEM or Teams

No extra portal to watch: after every scan NoCredEx sends critical findings to your SIEM, to Teams or another integration. The password itself is never transmitted.

One tool, one job.

NoCredEx finds credentials on your shares before an attacker does. Optionally it also searches your network for unknown shares and forgotten shared folders on admin PCs, and reports critical findings automatically via Teams, Slack, email or syslog.

Frequently asked questions about NoCredEx

What is a credential scanner for file servers?

A credential scanner, also called a secret scanner, searches files for credentials that should not be there: passwords, API keys, tokens, private keys and connection strings. NoCredEx is built for network drives and SMB shares: scripts, configuration files and documents on Windows file servers, Samba and NAS systems and shared folders on admin PCs. Every finding is rated by severity, and the password itself is never stored.

When will NoCredEx be available?

NoCredEx is currently in quality assurance and will be released soon. When it is ready, you will be the first to get an email, before the public announcement.

Can I test NoCredEx before the release?

Yes. For quality assurance we are looking for a few companies that test NoCredEx in their own environment before the release and give us feedback. Write to office@nocredex.at, ideally with a few details about your environment, such as the number of file servers and the systems you use (Windows, Samba, NAS).

What does joining the waitlist commit me to?

Nothing. You only receive the confirmation of your signup and one email as soon as NoCredEx is available for download.

Does NoCredEx send data anywhere?

No. The software runs entirely inside your network. Found credentials exist only in memory during the scan and are never written to disk, exported or transmitted.

Does NoCredEx need a cloud or internet connection?

No. NoCredEx runs entirely inside your network and can be operated completely offline. Machines without internet access can be activated too: the app creates an activation code, you enter it on our website from any device with internet access and then transfer the activation into the app. Integrations such as Teams or Slack are optional.

Who is behind NoCredEx?

NoCredEx is developed in Austria by Bernhard Bruckner, Dipl.-Ing., BSc. Behind it are a degree in information security from St. Pölten University of Applied Sciences and more than 13 years in IT as an administrator, software developer and most recently cybersecurity specialist in a corporate environment. More at bbruckner.at.

Be the first to see what's on your servers.

One email address. A confirmation now, one email when it launches.

Almost done.

You will receive an email from us shortly. Please click the confirmation link in it; only then are you on the list. No email? Please check your spam folder too.

No newsletter, no resale of your address, unsubscribe any time via the link in our emails.