Frequently asked questions
Source code
hashcat suite
Beyond hashcat itself, there are other useful utilities from the same team, maintained in separate repositories.
hashcat - World's fastest and most advanced password recovery utility (
source)
-
maskprocessor - High-performance word generator with a per-position configurable charset (
source)
-
-
kwprocessor - Advanced keyboard-walk generator with configurable basechars, keymap and routes (
source)
Documentation for the older programs, hashcat-legacy, oclHashcat, oclHashcat-plus and oclHashcat-lite, is in the Archive, along with everything else on this wiki that is no longer current.
Core attack modes
A few of these are in hashcat's master branch and not yet in the 7.1.2 release. They are marked, and a precompiled master build is at hashcat.net/beta.
Dictionary attack - tries all words in a list. This is also called “straight” mode (attack mode 0,
-a 0)
-
-
PCFG attack - a trained grammar makes the candidates, most likely ones first (
-a 4)
(master, see beta)
Table attack - a table defines the possible characters at each position (
-a 5)
(master, see beta)
Hybrid attack - the mask follows the word (
-a 6) or precedes it (
-a 7), or places the word within the mask (
-a 12, master, see
beta)
Generic attack - candidates come from a feed, which is a small plugin you can write yourself (
-a 8)
(master, see beta)
Association attack - use an username, a filename, a hint, or any other pieces of information which could have had an influence in the password generation to attack one specific hash (
-a 9)
Other attacks
Rule-based attack - applies rules to words from wordlists and works with every attack mode
-
Most important wiki pages
Patches, tips and tricks
Archive
Pages describing programs that no longer exist, features that were removed, and techniques that still work but have a better replacement now, are collected in the Archive. They are kept because links to them exist all over the internet, and each one says at the top what to read instead.
Howtos, Videos, Papers, Articles, etc. in the wild
If your hashcat article is not listed, tell us. We would love to link it here.
General guides
Hardware
Common issues
Specific attacks
-
-
Hashcat Per Position Markov Chains (Trustwave took the article down and archive.org has no copy)
-
Rule-Fu: The art of word mangling (ob-security.info is a parked domain now)
-
Cracking an MD5 of an IP address (phillips321.co.uk, gone)
-
-
-
-
-
-
clem9669's rules - small, medium and large rulesets aimed at how people actually build a password, plus a case and an emoji one
Hob0Rules (unmaintained, archived on GitHub since 2019) -
hob064.rule and
d3adhob0.rule, built from password statistics rather than by hand
-
Specific targets
-
-
-
-
-
Cracking IKE Mission:Improbable (Part 2) (Trustwave took it down)
-
-
-
-
How to Extract OS X Mavericks Password Hash for Cracking With Hashcat (michaelfairley.co is gone)
-
-
-
Cracking TrueCrypt: container, non-system, system, hidden (0x31.de is gone. A later version of that site served adware, so do not go hunting for a copy of it)
-
-
-
-
-
-
SecLists - the standard collection of wordlists for security testing, kept up to date
Cloud and scale
Hashtopolis - multi-rig clustering server software, and the one most people use
Hashview - the alternative that is actively worked on, a web front end that queues and tracks jobs. It has never cut a tagged release, so you are building from the branch
-
-
Contests
Team Hashcat's writeups, the tools and rule files built during a contest, and the record of results all live in one repository now:
For an overview of Team Hashcat, see the FAQ. The repository has the latest contest results.
Older writeups that were published elsewhere before the repository existed:
-
hashcat's
test_module_runner.py - generate test hashes for a given hash mode. Almost every mode has a Python test module on master now, and the Perl driver is gone. The exceptions are the ones that need a real file rather than a generated hash string: TrueCrypt and VeraCrypt run from the containers in
tools/tc_tests and
tools/vc_tests, and a few others from the vector built into the plugin. On the 7.1.2 release the equivalent tool is
tools/test.pl.
Cencforce - text encoding forensics: encode, decode and transcode across 106 character encodings, for when a hash or a wordlist is in an encoding you cannot identify
hashgen - quickly generate some common hash types from wordlists
hashpipe - multi-threaded hash verification
-
-
MDXfind - supports multiple iterations of many hash types (CPU only). It is open source now, and the older techsolvency download page marks itself historical.
PACK - tools to analyze cracked passwords and generate masks that match password policies
pack2 - split strings on character boundaries, filter by mask, generate stats, unhex HEX
procrule - multi-threaded rule processor for wordlists. It takes hashcat and John rules, drops any candidate a rule left unchanged, dedupes its own output and handles
$HEX[] transparently
RuleProcessorY - the same job as procrule, with multibyte character support. Both apply rules on the CPU, which is slower than applying them on the GPU, so they earn their place when you need the candidates written out
rling - fast dedupe and sorting of large lists
rlite - a lighter alternative to rling for sorting, deduplicating lists against one another and simple analytics, with no extra dependencies to install
rulecat - mutate rules for hashcat, John the Ripper and MDXfind
-
uSlider - get a sliding window of substrings from a wordlist, with
$HEX[] and UTF-8 support. It supersedes
slider, which is still there but has not moved since 2023.
wlclass - classify a wordlist in one streaming pass: encoding, script, language evidence, and the parts that are not passwords at all
Other