hashcat.md (9593B)
1 --- 2 title: "Hashcat" 3 description: "Hashcat cracking: attack modes, hash-mode selection, rules, masks, wordlists and performance tuning." 4 category: password-attacks 5 tags: [password-attacks, cracking, hashes] 6 tools: [Hashcat] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:PasswordAttacks/hashcat-cheatsheet.md" 10 --- 11 12 # Hashcat 13 14 > **What this covers —** The full **hashcat** workflow: attack modes (`-a`), the common `-m` mode numbers, masks, rules, tuning, and status/restore. For CPU-side cracking and file extraction, see John the Ripper. 15 16 Hashcat is **GPU-first**: it excels at fast/salted digests (MD5, SHA-x, NTLM, WPA) at enormous candidate rates. Pin the correct `-m` (hash type) and `-a` (attack mode) on every run. 17 18 ## Table of Contents 19 20 1. [Command Anatomy](#1-command-anatomy) 21 2. [Attack Modes (`-a`)](#2-attack-modes--a) 22 3. [Common Hash Modes (`-m`)](#3-common-hash-modes--m) 23 4. [Mask Attack Reference](#4-mask-attack-reference) 24 5. [Rules](#5-rules) 25 6. [Tuning & Performance](#6-tuning--performance) 26 7. [Status, Restore & Output](#7-status-restore--output) 27 8. [Questions & Answers](#8-questions--answers) 28 9. [Alternative Approaches & Modern Tooling](#9-alternative-approaches--modern-tooling) 29 30 ## 1. Command Anatomy 31 32 <figure class="flow plate corners"> 33 <figcaption class="flow__cap"><span class="flow__kind">Command anatomy</span><span class="flow__dir">LR</span></figcaption> 34 <div class="flow__body"> 35 <div class="flow__diagram" data-dir="lr"> 36 <div class="flow-rank"><div class="flow-node is-entry">hashcat</div></div> 37 <div class="flow-edge"></div> 38 <div class="flow-rank"><div class="flow-node">-m MODE<span class="sub">hash type</span></div></div> 39 <div class="flow-edge"></div> 40 <div class="flow-rank"><div class="flow-node">-a ATTACK<span class="sub">0/1/3/6/7</span></div></div> 41 <div class="flow-edge"></div> 42 <div class="flow-rank"><div class="flow-node">hashfile</div></div> 43 <div class="flow-edge"></div> 44 <div class="flow-rank"><div class="flow-node">wordlist / mask</div></div> 45 <div class="flow-edge"></div> 46 <div class="flow-rank"><div class="flow-node">-r rules<span class="sub">-O -w tuning</span></div></div> 47 </div> 48 </div> 49 </figure> 50 51 ```bash 52 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt -r best64.rule -O -w 3 53 # │ │ │ │ │ │ └ workload profile 54 # │ │ │ │ └ rules file └ optimised kernel 55 # │ │ │ └ wordlist / mask 56 # │ │ └ hash file 57 # │ └ attack mode 58 # └ hash type (mode) 59 ``` 60 61 ## 2. Attack Modes (`-a`) 62 63 | `-a` | Mode | What it does | 64 | :-- | :-- | :-- | 65 | `0` | Straight | Wordlist (optionally + rules). The default. | 66 | `1` | Combination | Concatenate every word of list A with every word of list B | 67 | `3` | Brute-force / Mask | Try candidates matching a mask pattern | 68 | `6` | Hybrid Wordlist + Mask | `word` then appended mask (e.g. `pass` + `?d?d?d`) | 69 | `7` | Hybrid Mask + Wordlist | mask then prepended word | 70 | `9` | Association | One-hash-to-one-candidate (usernames, hints) | 71 72 ```bash 73 hashcat -m 0 -a 0 hashes.txt rockyou.txt # straight 74 hashcat -m 0 -a 1 hashes.txt left.txt right.txt # combination 75 hashcat -m 0 -a 3 hashes.txt '?u?l?l?l?l?d?d' # mask 76 hashcat -m 0 -a 6 hashes.txt rockyou.txt '?d?d?d' # word + 3 digits 77 hashcat -m 0 -a 7 hashes.txt '?d?d?d' rockyou.txt # 3 digits + word 78 ``` 79 80 ## 3. Common Hash Modes (`-m`) 81 82 The most frequent ones on HTB/CPTS boxes and real engagements. Use `hashcat --help | grep -i <name>` for anything not listed here. 83 84 | `-m` | Hash type | John equiv (`--format=`) | 85 | --: | :-- | :-- | 86 | `0` | MD5 | `raw-md5` | 87 | `100` | SHA1 | `raw-sha1` | 88 | `1400` | SHA2-256 | `raw-sha256` | 89 | `1700` | SHA2-512 | `raw-sha512` | 90 | `900` | MD4 | `raw-md4` | 91 | `500` | md5crypt `$1$` | `md5crypt` | 92 | `1800` | sha512crypt `$6$` | `sha512crypt` | 93 | `7400` | sha256crypt `$5$` | `sha256crypt` | 94 | `3200` | bcrypt `$2*$` | `bcrypt` | 95 | `1000` | NTLM | `nt` | 96 | `3000` | LM | `lm` | 97 | `5500` | NetNTLMv1 | `netntlm` | 98 | `5600` | NetNTLMv2 | `netntlmv2` | 99 | `1100` | DCC (MS Cache) | `mscash` | 100 | `2100` | DCC2 (MS Cache 2) | `mscash2` | 101 | `18200` | Kerberos AS-REP | `krb5asrep` | 102 | `13100` | Kerberos TGS-REP | `krb5tgs` | 103 | `19700` | Kerberos TGS-REP (AES256) | — | 104 | `22000` | WPA-PBKDF2-PMKID+EAPOL | `wpapsk` | 105 | `16500` | JWT (HS256/384/512) | — | 106 | `13400` | KeePass 1/2 | `keepass` | 107 | `11600` | 7-Zip | `7z` | 108 | `13600` | WinZip | `zip` | 109 | `12500` | RAR3 | `rar` | 110 | `13000` | RAR5 | `rar5` | 111 | `10500` | PDF 1.4-1.6 | `pdf` | 112 | `9600` | Office 2013 | `office` | 113 | `22911` | SSH RSA/DSA key | `ssh` | 114 115 ```bash 116 hashcat -m 13100 -a 0 kerberoast.txt rockyou.txt # Kerberoasting 117 hashcat -m 22000 -a 0 handshake.hc22000 rockyou.txt # WPA2 118 hashcat -m 1000 -a 3 ntlm.txt '?a?a?a?a?a?a?a?a' # 8-char NTLM brute 119 ``` 120 121 > **Tip — identify the mode fast.** `hashid -m '<hash>'` prints the matching hashcat `-m` number. `hashcat --identify hashes.txt` (newer builds) lists candidate modes for a file directly. 122 123 ## 4. Mask Attack Reference 124 125 | Token | Charset | 126 | :-- | :-- | 127 | `?l` | `abcdefghijklmnopqrstuvwxyz` | 128 | `?u` | `ABCDEFGHIJKLMNOPQRSTUVWXYZ` | 129 | `?d` | `0123456789` | 130 | `?s` | special chars ``!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~`` | 131 | `?a` | `?l?u?d?s` (all printable ASCII) | 132 | `?b` | `0x00–0xff` (raw bytes) | 133 | `?h` / `?H` | hex `0-9a-f` / `0-9A-F` | 134 135 ```bash 136 # Fixed length 8, first upper then lowers then 2 digits 137 hashcat -m 0 -a 3 hashes.txt '?u?l?l?l?l?l?d?d' 138 139 # Custom charset in slot 1 (-1), then use ?1 140 hashcat -m 0 -a 3 hashes.txt -1 '?l?d' '?1?1?1?1?1?1' 141 142 # Incrementing length brute force (1..8 chars of ?a) 143 hashcat -m 0 -a 3 --increment --increment-min=1 --increment-max=8 hashes.txt '?a?a?a?a?a?a?a?a' 144 ``` 145 146 ## 5. Rules 147 148 ```bash 149 hashcat -m 0 -a 0 hashes.txt rockyou.txt -r /usr/share/hashcat/rules/best64.rule 150 hashcat -m 0 -a 0 hashes.txt rockyou.txt -r rules/dive.rule # huge 151 hashcat -m 0 -a 0 hashes.txt rockyou.txt -r r1.rule -r r2.rule # stack rules 152 153 # Generate random rules on the fly 154 hashcat -m 0 -a 0 hashes.txt rockyou.txt -g 10000 # 10k random rules 155 ``` 156 157 Popular built-in rule files (in `/usr/share/hashcat/rules/`): `best64.rule` (fast, high-value), `rockyou-30000.rule`, `dive.rule` (exhaustive), `OneRuleToRuleThemAll.rule` (community favourite, add manually). 158 159 ## 6. Tuning & Performance 160 161 ```bash 162 -O # optimised kernel (faster, caps password length ~31 — usually fine) 163 -w 1|2|3|4 # workload profile: 3 = desktop default, 4 = headless/dedicated 164 --force # ignore warnings (use sparingly; can mask real GPU issues) 165 -D 1 # use CPU devices; -D 2 = GPU only 166 -d 1 # select device 1 (see hashcat -I for device list) 167 --status --status-timer=10 # periodic status lines every 10s 168 hashcat -b # benchmark all modes 169 hashcat -b -m 1000 # benchmark just NTLM 170 ``` 171 172 > **Warning — `-O` trades length for speed.** The optimised kernel limits candidate length (≈31 for most modes). For long passphrases (WPA, KeePass) drop `-O` so you don't silently skip valid candidates. 173 174 ## 7. Status, Restore & Output 175 176 ```bash 177 # Live keys during a run: s = status, p = pause, r = resume, b = bypass, q = quit 178 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt --session=job1 # named session 179 hashcat --session=job1 --restore # resume after stop 180 181 hashcat -m 1000 ntlm.txt rockyou.txt --potfile-path=/tmp/x.pot # custom pot 182 hashcat -m 1000 ntlm.txt --show # show cracked (from pot) 183 hashcat -m 1000 ntlm.txt --left # show still-uncracked 184 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt -o cracked.txt # write results to file 185 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt --outfile-format=2 # 2 = plain only 186 ``` 187 188 ## 8. Questions & Answers 189 190 ### Q: How do I crack a Kerberoast TGS hash? 191 ```bash 192 hashcat -m 13100 -a 0 spns.txt /usr/share/wordlists/rockyou.txt -O 193 ``` 194 **Answer:** mode `13100`, straight attack. AS-REP roast uses `18200`. 195 196 ### Q: How do I crack an NTLM hash dumped from a DC? 197 ```bash 198 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt -r best64.rule 199 ``` 200 **Answer:** mode `1000`. NetNTLMv2 from Responder = `5600`. 201 202 ### Q: How do I brute-force an 8-character all-ASCII password? 203 ```bash 204 hashcat -m 1000 -a 3 ntlm.txt '?a?a?a?a?a?a?a?a' -O -w 3 205 ``` 206 **Answer:** mask attack (`-a 3`) with eight `?a` tokens. 207 208 ### Q: How do I crack a WPA2 handshake? 209 ```bash 210 hcxpcapngtool -o handshake.hc22000 capture.pcapng # convert 211 hashcat -m 22000 -a 0 handshake.hc22000 rockyou.txt # crack 212 ``` 213 **Answer:** convert to `.hc22000` then mode `22000`. 214 215 ## 9. Alternative Approaches & Modern Tooling 216 217 > **Tip — use the right tool per hash.** **Hashcat** wins on GPU-friendly hashes (raw MD5/SHA, NTLM, WPA, Kerberos). **John** wins on file extraction (`*2john`), `--single` username mangling, and formats hashcat lacks. Identify with `hashid`, then choose. 218 219 > **Note — `22000` replaces `2500`/`16800`.** Mode `22000` (PMKID+EAPOL) is the current unified WPA mode. The older `2500` (`.hccapx`) and `16800` (PMKID-only) are deprecated — always convert captures with `hcxpcapngtool` to `.hc22000`. 220 221 > **Warning — wordlist + rules beats pure brute-force.** A rules run over `rockyou.txt` (`-r OneRuleToRuleThemAll.rule`) covers vastly more realistic passwords per second than a blind `?a?a?a?a…` mask. Reach for masks only when you know the password structure.