# hashcat and its predecessors were developed and are maintained by:

Jens "atom" Steube <jens.steube@gmail.com> (@hashcat)

# The following people contributed code to hashcat:

Philipp "philsmd" Schmidt <philsmd@hashcat.net> (@philsmd)

* Multiple kernel modules
* Hardware monitor maintenance
* Test Suite maintenance
* Makefile maintenance
* Potfile feature
* Maskfile feature
* Induction directory feature
* Loopback file feature
* Userinput sanity checks

Gabriele "matrix" Gristina <matrix@hashcat.net> (@gm4tr1x)

* Multiple kernel modules
* Compressed wordlist feature
* OpenCL Info feature
* Apple Metal Runtime API feature
* Apple macOS port
* Apple Silicon support
* Universal binary on Apple Silicon
* Add support to character class rules
* Hardware monitor initial code base and maintenance
* Test suite initial code base and maintenance
* Edge case testing suite
* Makefile initial code base and maintenance
* Multithreading initial code base
* MultiGPU initial code base
* Benchmarks initial code base
* hashcat-toolchain docker

Ahmed "ahmed-alnassif" Al-Nassif <mr.ahmed.nassif@gmail.com> (@ahmed-alnassif)

* Android port with Termux support
* Android build documentation and setup guide

Jean-Christophe "Fist0urs" Delaunay <jean-christophe.delaunay@synacktiv.com> (@Fist0urs)

* Kerberos TGS Rep enctype 23 kernel module
* Kerberos TGS Rep enctype 17/18 kernel module
* AxCrypt kernel module
* KeePass (KDBX v2/v3) kernel module
* DPAPImk v1 and v2 kernel module

Jeremi "epixoip" Gosney <jgosney@terahash.com> (@jmgosney)

* Oracle Transportation Manager SHA256 kernel module
* Continuous work pushing hashcat to run on large clusters
* Conducting Hashcat trainings
* Moderating the hashcat forum
* Helping tons of new users find their way into the hashcat universe

magnum

* RAR3 Huffman validity check in the -m 23800 kernel module

Other contributors to hashcat

* A full list and their commits can be found here: https://github.com/hashcat/hashcat/graphs/contributors

# hashcat relies on some libraries, including:

* liblzma by Lasse Collin and Igor Pavlov (loaded at runtime)
* zlib by Jean-loup Gailly and Mark Adler (loaded at runtime)
* zstd by Yann Collet (@Cyan4973) (loaded at runtime)
* micro-ecc by Ken MacKay (used as reference for some secp256k1 operations)
* PPMd var.H by Dmitry Shkarin and Dmitry Subbotin, in Igor Pavlov's 7-Zip implementation (vendored)

# hashcat implements the following algorithms designed by others:

* Probabilistic Context-Free Grammars for password guessing, by Matt Weir (@lakiw), with Sudhir Aggarwal, Breno de Medeiros and Bill Glodek. Attack mode 4 uses this model and reads rulesets trained by Matt Weir's pcfg_cracker. hashcat contains none of its code and enumerates the grammar differently, but the attack is based on their work.

* OMEN, an ordered Markov enumerator for password guessing, by Markus Duermuth, Fabian Angelstorf, Claude Castelluccia, Daniele Perito and Abdelberi Chaabane. A ruleset trained below full coverage assigns the probability mass not covered by the grammar to an escape. OMEN supplies that escape model, which hashcat evaluates on the host where its trellis can be traversed.

* xxHash by Yann Collet (@Cyan4973). paw64, hashcat's 64-bit identity hash, contains no xxHash code and produces different digests. It follows the design principles established by xxHash: short and long inputs benefit from different processing, while multiplication, folding and a strong final avalanche provide sufficient mixing.

# The following people also helped the project:

Martin "purehate" Bos <purehate@derbycon.com> (@cantcomputer)

* First to present hashcat to a wider audience through talks and tutorials
* Helped bring hashcat to Kali

Per Thorsheim <per@thorsheim.net> (@thorsheim)

* Organized PasswordsCon, the first conference of its kind
* Encouraged public presentations about the project

Rick "Minga" Redman and KoreLogic <mingakore@gmail.com> (@CrackMeIfYouCan)

* Organized Crack Me If You Can, the first password-cracking contest of its kind
* Advanced password-cracking techniques

Brandon Chalk <brandon@casaba.com> (@brandoncasaba)
* Kerberos Pre-Auth 17/18 kernel module, ported from @Fist0urs TGS kernel modules

Jamie Riden <jamie@blacktraffic.co.uk>
* Web2py pbkdf2-sha512 plugin

Dylan Evans <fin3ss3g0d@pm.me> (@fin3ss3g0d)
* Apache Shiro 1 SHA-512 plugin

Costin Enache <costin@detack.de>
* RACF KDFAES module
* IBM AS400 DES and SSHA1 modules
* Cisco-ISE Hashed Password (SHA256) module

Vlad Drumea (vlad.drumea@vladdba.com)
* MSSQL (2025) module

Shooter3k
* Multibyte characters written directly in rule operands, and UTF-8 console output on Windows
* Narrowing the potfile search and batching the cracked result writes
* An optional breakdown of where a run's wall-clock time is spent
* Long-standing bugfix ideas in rule file loading, --show and --left, --loopback, and checkpointing
* Rules applied to the fully assembled candidate in the mask and hybrid attack modes
* Moving a running attack through its keyspace, and extending its deadline, from the status screen
* Faster --stdout rules, an early outfile check, and a report of devices that did not start

!!! All the package maintainers of hashcat !!!
