Frequently asked questions

NOTE: You cannot use hashcat to recover online accounts (like Gmail, Instagram, Facebook, Twitter, etc.), because hashcat has no way to work on online accounts.

Source code

hashcat suite

Beyond hashcat itself, there are other useful utilities from the same team, maintained in separate repositories.

Documentation for the older programs, hashcat-legacy, oclHashcat, oclHashcat-plus and oclHashcat-lite, is in the Archive, along with everything else on this wiki that is no longer current.

Core attack modes

A few of these are in hashcat's master branch and not yet in the 7.1.2 release. They are marked, and a precompiled master build is at hashcat.net/beta.

  • Dictionary attack - tries all words in a list. This is also called “straight” mode (attack mode 0, -a 0)
  • Combinator attack - concatenating words from multiple wordlists (-a 1)
  • Brute-force attack and Mask attack - trying all characters from given charsets, per position (-a 3)
  • PCFG attack - a trained grammar makes the candidates, most likely ones first (-a 4) (master, see beta)
  • Table attack - a table defines the possible characters at each position (-a 5) (master, see beta)
  • Hybrid attack - the mask follows the word (-a 6) or precedes it (-a 7), or places the word within the mask (-a 12, master, see beta)
  • Generic attack - candidates come from a feed, which is a small plugin you can write yourself (-a 8) (master, see beta)
  • Association attack - use an username, a filename, a hint, or any other pieces of information which could have had an influence in the password generation to attack one specific hash (-a 9)

Other attacks

Most important wiki pages

Patches, tips and tricks

Archive

Pages describing programs that no longer exist, features that were removed, and techniques that still work but have a better replacement now, are collected in the Archive. They are kept because links to them exist all over the internet, and each one says at the top what to read instead.

Howtos, Videos, Papers, Articles, etc. in the wild

If your hashcat article is not listed, tell us. We would love to link it here.

General guides

Hardware

Common issues

Specific attacks

Specific targets

Input sources

Cloud and scale

Contests

Team Hashcat's writeups, the tools and rule files built during a contest, and the record of results all live in one repository now:

For an overview of Team Hashcat, see the FAQ. The repository has the latest contest results.

Older writeups that were published elsewhere before the repository existed:

Other common tools

  • hashcat-utils - small utilities for advanced password cracking
  • hashcat's test_module_runner.py - generate test hashes for a given hash mode. Almost every mode has a Python test module on master now, and the Perl driver is gone. The exceptions are the ones that need a real file rather than a generated hash string: TrueCrypt and VeraCrypt run from the containers in tools/tc_tests and tools/vc_tests, and a few others from the vector built into the plugin. On the 7.1.2 release the equivalent tool is tools/test.pl.
  • Cencforce - text encoding forensics: encode, decode and transcode across 106 character encodings, for when a hash or a wordlist is in an encoding you cannot identify
  • hashgen - quickly generate some common hash types from wordlists
  • hashpipe - multi-threaded hash verification
  • hcxdumptool and hcxtools - the modern way to capture and process Wi-Fi hashes
  • John the Ripper - supports some hash types hashcat does not
  • MDXfind - supports multiple iterations of many hash types (CPU only). It is open source now, and the older techsolvency download page marks itself historical.
  • PACK - tools to analyze cracked passwords and generate masks that match password policies
  • pack2 - split strings on character boundaries, filter by mask, generate stats, unhex HEX
  • procrule - multi-threaded rule processor for wordlists. It takes hashcat and John rules, drops any candidate a rule left unchanged, dedupes its own output and handles $HEX[] transparently
  • RuleProcessorY - the same job as procrule, with multibyte character support. Both apply rules on the CPU, which is slower than applying them on the GPU, so they earn their place when you need the candidates written out
  • rling - fast dedupe and sorting of large lists
  • rlite - a lighter alternative to rling for sorting, deduplicating lists against one another and simple analytics, with no extra dependencies to install
  • rulecat - mutate rules for hashcat, John the Ripper and MDXfind
  • rurasort - wordlist processing
  • uSlider - get a sliding window of substrings from a wordlist, with $HEX[] and UTF-8 support. It supersedes slider, which is still there but has not moved since 2023.
  • wlclass - classify a wordlist in one streaming pass: encoding, script, language evidence, and the parts that are not passwords at all

Other

Except where otherwise noted, content on this wiki is licensed under the following license: Public Domain