daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

hashcat.md (9593B)


      1 ---
      2 title: "Hashcat"
      3 description: "Hashcat cracking: attack modes, hash-mode selection, rules, masks, wordlists and performance tuning."
      4 category: password-attacks
      5 tags: [password-attacks, cracking, hashes]
      6 tools: [Hashcat]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:PasswordAttacks/hashcat-cheatsheet.md"
     10 ---
     11 
     12 # Hashcat
     13 
     14 > **What this covers —** The full **hashcat** workflow: attack modes (`-a`), the common `-m` mode numbers, masks, rules, tuning, and status/restore. For CPU-side cracking and file extraction, see John the Ripper.
     15 
     16 Hashcat is **GPU-first**: it excels at fast/salted digests (MD5, SHA-x, NTLM, WPA) at enormous candidate rates. Pin the correct `-m` (hash type) and `-a` (attack mode) on every run.
     17 
     18 ## Table of Contents
     19 
     20 1. [Command Anatomy](#1-command-anatomy)
     21 2. [Attack Modes (`-a`)](#2-attack-modes--a)
     22 3. [Common Hash Modes (`-m`)](#3-common-hash-modes--m)
     23 4. [Mask Attack Reference](#4-mask-attack-reference)
     24 5. [Rules](#5-rules)
     25 6. [Tuning & Performance](#6-tuning--performance)
     26 7. [Status, Restore & Output](#7-status-restore--output)
     27 8. [Questions & Answers](#8-questions--answers)
     28 9. [Alternative Approaches & Modern Tooling](#9-alternative-approaches--modern-tooling)
     29 
     30 ## 1. Command Anatomy
     31 
     32 <figure class="flow plate corners">
     33 <figcaption class="flow__cap"><span class="flow__kind">Command anatomy</span><span class="flow__dir">LR</span></figcaption>
     34 <div class="flow__body">
     35 <div class="flow__diagram" data-dir="lr">
     36 <div class="flow-rank"><div class="flow-node is-entry">hashcat</div></div>
     37 <div class="flow-edge"></div>
     38 <div class="flow-rank"><div class="flow-node">-m MODE<span class="sub">hash type</span></div></div>
     39 <div class="flow-edge"></div>
     40 <div class="flow-rank"><div class="flow-node">-a ATTACK<span class="sub">0/1/3/6/7</span></div></div>
     41 <div class="flow-edge"></div>
     42 <div class="flow-rank"><div class="flow-node">hashfile</div></div>
     43 <div class="flow-edge"></div>
     44 <div class="flow-rank"><div class="flow-node">wordlist / mask</div></div>
     45 <div class="flow-edge"></div>
     46 <div class="flow-rank"><div class="flow-node">-r rules<span class="sub">-O -w tuning</span></div></div>
     47 </div>
     48 </div>
     49 </figure>
     50 
     51 ```bash
     52 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt -r best64.rule -O -w 3
     53 #         │        │    │        │           │            │  └ workload profile
     54 #         │        │    │        │           └ rules file  └ optimised kernel
     55 #         │        │    │        └ wordlist / mask
     56 #         │        │    └ hash file
     57 #         │        └ attack mode
     58 #         └ hash type (mode)
     59 ```
     60 
     61 ## 2. Attack Modes (`-a`)
     62 
     63 | `-a` | Mode | What it does |
     64 | :-- | :-- | :-- |
     65 | `0` | Straight | Wordlist (optionally + rules). The default. |
     66 | `1` | Combination | Concatenate every word of list A with every word of list B |
     67 | `3` | Brute-force / Mask | Try candidates matching a mask pattern |
     68 | `6` | Hybrid Wordlist + Mask | `word` then appended mask (e.g. `pass` + `?d?d?d`) |
     69 | `7` | Hybrid Mask + Wordlist | mask then prepended word |
     70 | `9` | Association | One-hash-to-one-candidate (usernames, hints) |
     71 
     72 ```bash
     73 hashcat -m 0 -a 0 hashes.txt rockyou.txt              # straight
     74 hashcat -m 0 -a 1 hashes.txt left.txt right.txt       # combination
     75 hashcat -m 0 -a 3 hashes.txt '?u?l?l?l?l?d?d'         # mask
     76 hashcat -m 0 -a 6 hashes.txt rockyou.txt '?d?d?d'     # word + 3 digits
     77 hashcat -m 0 -a 7 hashes.txt '?d?d?d' rockyou.txt     # 3 digits + word
     78 ```
     79 
     80 ## 3. Common Hash Modes (`-m`)
     81 
     82 The most frequent ones on HTB/CPTS boxes and real engagements. Use `hashcat --help | grep -i <name>` for anything not listed here.
     83 
     84 | `-m` | Hash type | John equiv (`--format=`) |
     85 | --: | :-- | :-- |
     86 | `0` | MD5 | `raw-md5` |
     87 | `100` | SHA1 | `raw-sha1` |
     88 | `1400` | SHA2-256 | `raw-sha256` |
     89 | `1700` | SHA2-512 | `raw-sha512` |
     90 | `900` | MD4 | `raw-md4` |
     91 | `500` | md5crypt `$1$` | `md5crypt` |
     92 | `1800` | sha512crypt `$6$` | `sha512crypt` |
     93 | `7400` | sha256crypt `$5$` | `sha256crypt` |
     94 | `3200` | bcrypt `$2*$` | `bcrypt` |
     95 | `1000` | NTLM | `nt` |
     96 | `3000` | LM | `lm` |
     97 | `5500` | NetNTLMv1 | `netntlm` |
     98 | `5600` | NetNTLMv2 | `netntlmv2` |
     99 | `1100` | DCC (MS Cache) | `mscash` |
    100 | `2100` | DCC2 (MS Cache 2) | `mscash2` |
    101 | `18200` | Kerberos AS-REP | `krb5asrep` |
    102 | `13100` | Kerberos TGS-REP | `krb5tgs` |
    103 | `19700` | Kerberos TGS-REP (AES256) | — |
    104 | `22000` | WPA-PBKDF2-PMKID+EAPOL | `wpapsk` |
    105 | `16500` | JWT (HS256/384/512) | — |
    106 | `13400` | KeePass 1/2 | `keepass` |
    107 | `11600` | 7-Zip | `7z` |
    108 | `13600` | WinZip | `zip` |
    109 | `12500` | RAR3 | `rar` |
    110 | `13000` | RAR5 | `rar5` |
    111 | `10500` | PDF 1.4-1.6 | `pdf` |
    112 | `9600` | Office 2013 | `office` |
    113 | `22911` | SSH RSA/DSA key | `ssh` |
    114 
    115 ```bash
    116 hashcat -m 13100 -a 0 kerberoast.txt rockyou.txt    # Kerberoasting
    117 hashcat -m 22000 -a 0 handshake.hc22000 rockyou.txt # WPA2
    118 hashcat -m 1000  -a 3 ntlm.txt '?a?a?a?a?a?a?a?a'   # 8-char NTLM brute
    119 ```
    120 
    121 > **Tip — identify the mode fast.** `hashid -m '<hash>'` prints the matching hashcat `-m` number. `hashcat --identify hashes.txt` (newer builds) lists candidate modes for a file directly.
    122 
    123 ## 4. Mask Attack Reference
    124 
    125 | Token | Charset |
    126 | :-- | :-- |
    127 | `?l` | `abcdefghijklmnopqrstuvwxyz` |
    128 | `?u` | `ABCDEFGHIJKLMNOPQRSTUVWXYZ` |
    129 | `?d` | `0123456789` |
    130 | `?s` | special chars ``!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~`` |
    131 | `?a` | `?l?u?d?s` (all printable ASCII) |
    132 | `?b` | `0x00–0xff` (raw bytes) |
    133 | `?h` / `?H` | hex `0-9a-f` / `0-9A-F` |
    134 
    135 ```bash
    136 # Fixed length 8, first upper then lowers then 2 digits
    137 hashcat -m 0 -a 3 hashes.txt '?u?l?l?l?l?l?d?d'
    138 
    139 # Custom charset in slot 1 (-1), then use ?1
    140 hashcat -m 0 -a 3 hashes.txt -1 '?l?d' '?1?1?1?1?1?1'
    141 
    142 # Incrementing length brute force (1..8 chars of ?a)
    143 hashcat -m 0 -a 3 --increment --increment-min=1 --increment-max=8 hashes.txt '?a?a?a?a?a?a?a?a'
    144 ```
    145 
    146 ## 5. Rules
    147 
    148 ```bash
    149 hashcat -m 0 -a 0 hashes.txt rockyou.txt -r /usr/share/hashcat/rules/best64.rule
    150 hashcat -m 0 -a 0 hashes.txt rockyou.txt -r rules/dive.rule            # huge
    151 hashcat -m 0 -a 0 hashes.txt rockyou.txt -r r1.rule -r r2.rule         # stack rules
    152 
    153 # Generate random rules on the fly
    154 hashcat -m 0 -a 0 hashes.txt rockyou.txt -g 10000                      # 10k random rules
    155 ```
    156 
    157 Popular built-in rule files (in `/usr/share/hashcat/rules/`): `best64.rule` (fast, high-value), `rockyou-30000.rule`, `dive.rule` (exhaustive), `OneRuleToRuleThemAll.rule` (community favourite, add manually).
    158 
    159 ## 6. Tuning & Performance
    160 
    161 ```bash
    162 -O                    # optimised kernel (faster, caps password length ~31 — usually fine)
    163 -w 1|2|3|4            # workload profile: 3 = desktop default, 4 = headless/dedicated
    164 --force               # ignore warnings (use sparingly; can mask real GPU issues)
    165 -D 1                  # use CPU devices;  -D 2 = GPU only
    166 -d 1                  # select device 1 (see hashcat -I for device list)
    167 --status --status-timer=10   # periodic status lines every 10s
    168 hashcat -b                    # benchmark all modes
    169 hashcat -b -m 1000            # benchmark just NTLM
    170 ```
    171 
    172 > **Warning — `-O` trades length for speed.** The optimised kernel limits candidate length (≈31 for most modes). For long passphrases (WPA, KeePass) drop `-O` so you don't silently skip valid candidates.
    173 
    174 ## 7. Status, Restore & Output
    175 
    176 ```bash
    177 # Live keys during a run:  s = status, p = pause, r = resume, b = bypass, q = quit
    178 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt --session=job1        # named session
    179 hashcat --session=job1 --restore                               # resume after stop
    180 
    181 hashcat -m 1000 ntlm.txt rockyou.txt --potfile-path=/tmp/x.pot # custom pot
    182 hashcat -m 1000 ntlm.txt --show                                # show cracked (from pot)
    183 hashcat -m 1000 ntlm.txt --left                                # show still-uncracked
    184 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt -o cracked.txt       # write results to file
    185 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt --outfile-format=2   # 2 = plain only
    186 ```
    187 
    188 ## 8. Questions & Answers
    189 
    190 ### Q: How do I crack a Kerberoast TGS hash?
    191 ```bash
    192 hashcat -m 13100 -a 0 spns.txt /usr/share/wordlists/rockyou.txt -O
    193 ```
    194 **Answer:** mode `13100`, straight attack. AS-REP roast uses `18200`.
    195 
    196 ### Q: How do I crack an NTLM hash dumped from a DC?
    197 ```bash
    198 hashcat -m 1000 -a 0 ntlm.txt rockyou.txt -r best64.rule
    199 ```
    200 **Answer:** mode `1000`. NetNTLMv2 from Responder = `5600`.
    201 
    202 ### Q: How do I brute-force an 8-character all-ASCII password?
    203 ```bash
    204 hashcat -m 1000 -a 3 ntlm.txt '?a?a?a?a?a?a?a?a' -O -w 3
    205 ```
    206 **Answer:** mask attack (`-a 3`) with eight `?a` tokens.
    207 
    208 ### Q: How do I crack a WPA2 handshake?
    209 ```bash
    210 hcxpcapngtool -o handshake.hc22000 capture.pcapng     # convert
    211 hashcat -m 22000 -a 0 handshake.hc22000 rockyou.txt   # crack
    212 ```
    213 **Answer:** convert to `.hc22000` then mode `22000`.
    214 
    215 ## 9. Alternative Approaches & Modern Tooling
    216 
    217 > **Tip — use the right tool per hash.** **Hashcat** wins on GPU-friendly hashes (raw MD5/SHA, NTLM, WPA, Kerberos). **John** wins on file extraction (`*2john`), `--single` username mangling, and formats hashcat lacks. Identify with `hashid`, then choose.
    218 
    219 > **Note — `22000` replaces `2500`/`16800`.** Mode `22000` (PMKID+EAPOL) is the current unified WPA mode. The older `2500` (`.hccapx`) and `16800` (PMKID-only) are deprecated — always convert captures with `hcxpcapngtool` to `.hc22000`.
    220 
    221 > **Warning — wordlist + rules beats pure brute-force.** A rules run over `rockyou.txt` (`-r OneRuleToRuleThemAll.rule`) covers vastly more realistic passwords per second than a blind `?a?a?a?a…` mask. Reach for masks only when you know the password structure.