GO KALI FREE

Hashcat

Password Attacks

Advancedmedium risk

Hashcat is the world's fastest and most advanced password recovery utility, supporting five unique modes of attack for over 300 highly optimized hashing algorithms. It leverages GPU power for incredible speed.

Installation

sudo apt install hashcat

Basic Syntax

hashcat -m <hash_type> -a <attack_mode> <hash_file> [wordlist]

Quick Facts

Full Name
Hashcat
License
MIT License
Author
Atom (hashcat.net)
Written In
C
Platforms
Linux, Windows, macOS
Category
Password Recovery (Offline)
Hash Types Supported
300+
Attack Modes
5 (Dictionary, Combinator, Brute-force, Hybrid, Rule-based)

Tool Overview

Hashcat is the world's fastest and most advanced password recovery utility. It leverages GPU (Graphics Processing Unit) acceleration to achieve speeds impossible with CPU-only tools, making it the go-to choice for offline hash cracking.

Originally released in 2009, Hashcat supports over 300 hash types including MD5, SHA-1, SHA-256, NTLM, bcrypt, WPA/WPA2, and many more. Its five attack modes — dictionary, combinator, brute-force, hybrid, and rule-based — provide flexibility for any password auditing scenario.

Hashcat is an essential tool in penetration testing, security auditing, and red team engagements. Security professionals use it to verify password policies by cracking hashes extracted from SAM databases, Active Directory, and web applications.

Common Commands

hashcat -m 0 -a 0 hashes.txt rockyou.txtMD5 dictionary attack - Cracking MD5 hashes with wordlist
hashcat -m 1000 -a 0 hashes.txt wordlist.txtNTLM hash cracking - Cracking Windows password hashes
hashcat -m 0 -a 3 hashes.txt ?a?a?a?a?a?aBrute force attack - When wordlist fails, try all combinations
hashcat -m 2500 -a 0 capture.hccapx wordlist.txtWPA/WPA2 cracking - Cracking WiFi handshake captures
hashcat --show hashes.txtShow cracked passwords - View previously cracked hashes
hashcat -m 0 -a 0 hashes.txt wordlist.txt -r rules/best64.ruleDictionary with rules - More effective wordlist attack
hashcat -m 22000 -a 0 capture.hc22000 wordlist.txtModern WPA cracking - Crack PMKID/EAPOL in the 22000 format
hashcat -m 1800 -a 0 shadow.txt rockyou.txtLinux shadow - Crack sha512crypt hashes from /etc/shadow
hashcat -m 13100 -a 0 kerb.txt wordlist.txtKerberoast - Crack TGS-REP (Kerberos) service ticket hashes
hashcat -m 1000 -a 6 hashes.txt wordlist.txt ?d?d?d?dHybrid attack - Append a 4-digit mask to each wordlist word
hashcat -m 0 -a 0 hashes.txt wordlist.txt -O -w 3Optimized/fast - Enable optimized kernels and high workload
hashcat -bBenchmark - Measure GPU cracking speed for every hash mode
hashcat -m 0 hashes.txt wordlist.txt --potfile-path=custom.potCustom potfile - Store cracked results in a specific potfile
hashcat -m 0 -a 0 hashes.txt wordlist.txt --session=job1Named session - Enable resume with --restore for long jobs
hashcat --restore --session=job1Resume - Continue a previously interrupted named session

Step-by-Step Guide

  1. 1Identify hash type (use hash-identifier if needed)
  2. 2Find corresponding hashcat mode number (-m)
  3. 3Prepare hash file (one hash per line)
  4. 4Choose attack mode and wordlist
  5. 5Run hashcat and monitor progress
  6. 6Use --show to see cracked passwords

Warnings

Use Cases

Password Auditing

Verify organizational password policies by cracking hashes from SAM databases and Active Directory.

WPA/WPA2 Recovery

Crack WiFi handshake captures to test wireless network security.

CTF Challenges

Solve cryptography and password cracking challenges in capture-the-flag competitions.

Incident Response

Recover compromised passwords during forensic investigations after data breaches.

Compliance Testing

Validate that password complexity requirements are actually effective against modern attacks.

Key Features

People Also Ask

Is it legal to use Hashcat?

Hashcat itself is a legitimate password-recovery and security-auditing tool. It is legal to use on hashes from systems, accounts, or files that you own or have explicit written authorization to test — for example during a sanctioned penetration test or when recovering your own forgotten password. Cracking hashes you do not own or lack permission to test is illegal in most jurisdictions.

What is the difference between dictionary and brute-force attack modes in Hashcat?

A dictionary attack (`-a 0`) tries every word from a wordlist such as `rockyou.txt`, which is fast and effective against human-chosen passwords. A brute-force / mask attack (`-a 3`) generates every possible combination for a defined pattern, e.g. `hashcat -a 3 -m 0 hashes.txt ?a?a?a?a?a?a` for six mixed characters. Dictionary attacks are usually tried first because they are far quicker.

How long does Hashcat take to crack a password?

It depends entirely on the hash algorithm, the password's length and complexity, and your GPU. Fast hashes like MD5 or NTLM can be tested at billions of guesses per second, while slow hashes like bcrypt are deliberately thousands of times slower. Run `hashcat -b -m <mode>` to benchmark your hardware and estimate feasibility before starting.

What is a potfile in Hashcat?

The potfile (`hashcat.potfile`, stored under `~/.local/share/hashcat/`) records every hash Hashcat has already cracked together with its plaintext. Recovered results are read from it automatically, so re-running a job shows previous successes instantly. Use `--show` to display cracked results or `--potfile-disable` to ignore it.

Does Hashcat run on Windows and macOS?

Yes. Hashcat is cross-platform and provides binaries for Windows, macOS, and Linux, though Kali Linux includes it by default. Performance depends on having working OpenCL or CUDA GPU drivers; run `hashcat -I` to confirm your device is detected on any platform.

What does the 'Exhausted' status mean in Hashcat?

'Exhausted' means Hashcat tried every candidate in your attack — the whole wordlist or the full mask keyspace — without cracking the remaining hashes. It is not an error; it simply means that particular attack did not find the password. Try a larger wordlist, add mutation rules with `-r`, or switch to a different mask.

Related Tools

John the Ripper

Password Attacks

CPU-based password cracker with automatic hash detection and extensive format support.

THC Hydra

Password Attacks

Online brute-force tool for testing login services with cracked credentials.

CeWL

Password Attacks

Custom wordlist generator for creating targeted dictionaries from target websites.

Crunch

Password Attacks

Pattern-based wordlist generator for creating custom password candidates.

Medusa

Password Attacks

Online brute-force tool for testing cracked credentials against live services.

Frequently Asked Questions

What is Hashcat used for?

Hashcat is used for offline password recovery and security auditing. It takes captured password hashes and attempts to find the original plaintext by testing millions of candidates per second using GPU acceleration. It supports over 300 hash types including MD5, SHA, NTLM, bcrypt, and WPA2.

What hash types does Hashcat support?

Hashcat supports over 300 hash types including MD5 (mode 0), SHA-1 (mode 100), SHA-256 (mode 1400), NTLM (mode 1000), bcrypt (mode 3200), WPA/WPA2 (mode 2500), and many more. Each hash type has a specific mode number used with the -m flag.

Do I need a GPU for Hashcat?

While Hashcat can run on CPU alone, it is designed for GPU acceleration and performs significantly better with a compatible NVIDIA or AMD GPU. Without a GPU, John the Ripper may be more practical for CPU-based cracking.

How do I identify a hash type for Hashcat?

You can identify hash types using tools like hash-identifier, or by examining the hash length and format. MD5 hashes are 32 hexadecimal characters, SHA-256 are 64 characters, and NTLM hashes are typically 32 characters extracted from Windows systems.

What are Hashcat rule-based attacks?

Rule-based attacks apply mutation rules to wordlist entries to generate password candidates. Built-in rules like best64.rule and dive.rule transform base words by adding numbers, symbols, case changes, and common substitutions. Rules are defined in .rule files.

How do I crack WPA2 handshakes with Hashcat?

Capture a WPA2 handshake using airodump-ng, convert it to .hccapx format using hcxpcapngtool, then run: hashcat -m 22000 capture.hccapx wordlist.txt. For PMKID attacks, use -m 22001 with the captured PMKID directly.

How do I optimize Hashcat performance?

Use the largest wordlist possible, enable rules for mutations, set optimal workload with -w 3 or -w 4, use --force for testing, and ensure proper GPU cooling. For multi-GPU setups, use -d to select specific devices.

Can Hashcat crack salted hashes?

Yes. For salted hashes, provide the salt using the appropriate hash mode. For example, mode 10 is MD5 with salt, mode 1200 is SHA1 with salt. The hash format is hash:salt. Some modes support multiple salts for batch cracking.

What is the difference between Hashcat and John the Ripper?

Hashcat is GPU-accelerated and offers maximum speed for large hash sets. John the Ripper runs on CPU, automatically detects hash types, and supports more formats like encrypted archives. Use Hashcat for speed; John for convenience and format coverage.

How do I check Hashcat installation and GPU support?

Run hashcat -I to display installed OpenCL devices, driver versions, and supported hash types. This verifies your GPU is detected and shows its compute capability for optimal cracking performance.

Can Hashcat crack passwords from a Windows SAM database?

Yes, first extract hashes using secretsdump.py, samdump2, or Mimikatz, then crack with hashcat -m 1000 for NTLM or -m 3000 for LM hashes. NTLM mode is the most common for modern Windows systems.

What is Hashcat's brain feature?

Hashcat Brain is a learned-password tracking system that prevents testing previously tried candidates. Enable with --brain-server and --brain-client flags to share tested-password databases across multiple cracking sessions.

How do I crack MD5 hashes with Hashcat?

Use mode 0 for raw MD5: hashcat -m 0 hashes.txt wordlist.txt. For MD5 with salt, use mode 10: hashcat -m 10 hash.txt wordlist.txt. The hash format is hash:salt for salted variants.

Can Hashcat crack Kerberos hashes?

Yes, Hashcat supports Kerberos 5 AS-REP (mode 18200) and Kerberoasting TGS (mode 13100) hashes. Extract Kerberos hashes using Impacket's GetUserSPNs.py or Rubeus for offline cracking.

How do I resume a paused Hashcat session?

Use hashcat --show -session=restore to resume the last session, or hashcat --session=SESSION_NAME to resume a specific named session. Hashcat automatically saves progress for interruption recovery.

What is a mask attack in Hashcat?

A mask attack tests candidates matching a specific pattern using placeholders: ?l (lowercase), ?u (uppercase), ?d (digits), ?s (symbols), ?a (all). For example, hashcat -a 3 hashes.txt ?u?l?l?l?l?d?d tests a pattern of ULLLLDD.

How do I use Hashcat with rules for password mutations?

Rules transform wordlist entries using built-in or custom rule files: hashcat -r best64.rule hashes.txt wordlist.txt. Rules add numbers, change case, append symbols, and apply common password patterns to base words.

Can Hashcat crack iOS backup passwords?

Yes, use mode 14700 for iTunes backup passwords: hashcat -m 14700 itunes_backup_hash.txt wordlist.txt. Extract the hash from the iOS backup using specialized tools before cracking.

How do I use Hashcat on cloud GPU instances?

Launch cloud GPU instances (AWS p3, GCP a100, Azure NC) with NVIDIA drivers installed, install Hashcat, and run your cracking session. Cloud GPUs offer massive parallelism but incur costs per hour.

Tags

#password-attacks

Output Explanation

Output shows cracking speed, progress percentage, and cracked passwords in format hash:password. Status shows estimated time remaining.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.