john-the-ripper.md (19354B)
1 --- 2 title: "John the Ripper" 3 description: "John the Ripper: 2john extractors, formats, wordlist/incremental/rules modes and session control." 4 category: password-attacks 5 tags: [password-attacks, cracking, hashes] 6 tools: [John the Ripper] 7 difficulty: intermediate 8 updated: "2026-09-13" 9 source: "vault:PasswordAttacks/john-cheatsheet.md" 10 --- 11 12 # John the Ripper 13 14 > **What this covers —** Full workflow for **John the Ripper (Jumbo)**: identifying a hash, picking the correct `--format=` value for every hash type, preparing hashes with the `*2john` helpers, and every cracking mode flag. For the GPU-heavy equivalents see Hashcat. 15 16 Use **John the Ripper Jumbo** (`john-jumbo`, the community build shipped on Kali/Parrot). The stock upstream build supports far fewer formats. All commands below assume the Jumbo build. 17 18 ## Table of Contents 19 20 1. [Quick Workflow](#1-quick-workflow) 21 2. [Identifying the Hash](#2-identifying-the-hash) 22 3. [`--format=` Flag for Every Hash Type](#3-format-flag-for-every-hash-type) 23 4. [Preparing Hashes — the `*2john` Helpers](#4-preparing-hashes--the-2john-helpers) 24 5. [Cracking Mode Flags](#5-cracking-mode-flags) 25 6. [Rules, Masks & Tuning](#6-rules-masks--tuning) 26 7. [Session, Output & Status Flags](#7-session-output--status-flags) 27 8. [Running It — Worked Examples](#8-running-it--worked-examples) 28 9. [Alternative Approaches & Modern Tooling](#9-alternative-approaches--modern-tooling) 29 30 ## 1. Quick Workflow 31 32 <figure class="flow plate corners"> 33 <figcaption class="flow__cap"><span class="flow__kind">Quick crack workflow</span><span class="flow__dir">LR</span></figcaption> 34 <div class="flow__body"> 35 <div class="flow__diagram" data-dir="lr"> 36 <div class="flow-rank"><div class="flow-node is-entry">Obtain hash<span class="sub">or artefact</span></div></div> 37 <div class="flow-edge"></div> 38 <div class="flow-rank"><div class="flow-node">Convert with<span class="sub">*2john helper</span></div></div> 39 <div class="flow-edge"></div> 40 <div class="flow-rank"><div class="flow-node">Identify format<span class="sub">hashid / --list=formats</span></div></div> 41 <div class="flow-edge"></div> 42 <div class="flow-rank"><div class="flow-node">Pick --format=NAME</div></div> 43 <div class="flow-edge"></div> 44 <div class="flow-rank"><div class="flow-node">Crack:<span class="sub">wordlist -> rules -> incremental</span></div></div> 45 <div class="flow-edge"></div> 46 <div class="flow-rank"><div class="flow-node is-goal">john --show<span class="sub">recover plaintext</span></div></div> 47 </div> 48 </div> 49 </figure> 50 51 ```bash 52 # The canonical three-liner 53 zip2john secret.zip > hash.txt # 1. convert artefact -> john hash 54 john --format=zip --wordlist=rockyou.txt hash.txt # 2. crack 55 john --show --format=zip hash.txt # 3. reveal cracked passwords 56 ``` 57 58 > **Tip — cracked passwords live in `~/.john/john.pot`.** John never re-cracks a hash it has already solved. `--show` reads from the pot file. To force a fresh run, delete or point away from the pot: `--pot=/tmp/fresh.pot`. 59 60 ## 2. Identifying the Hash 61 62 ```bash 63 # Best-effort identification (installed as `hashid` or `hash-identifier`) 64 hashid '$6$rounds=5000$abc$...' 65 hashid -m 'hash' # also prints the matching hashcat -m mode 66 67 # List every format John supports (grep for what you need) 68 john --list=formats 69 john --list=formats | tr ',' '\n' | grep -i ntlm 70 71 # Show the subformats/notes for one format 72 john --list=format-details --format=krb5tgs 73 ``` 74 75 > **Warning — `hashid` guesses, it does not confirm.** Multiple algorithms share a length/shape (e.g. raw MD5 vs NTLM vs raw-MD4 are all 32 hex chars). If the first `--format` fails, try the siblings in the table below before assuming the hash is wrong. 76 77 ## 3. `--format=` Flag for Every Hash Type 78 79 The value passed to `--format=` is John's internal format name, **not** a hashcat mode number. Below are the ones you will actually meet on HTB/CPTS boxes and real engagements. Names are case-insensitive. 80 81 ### Raw / unsalted digests 82 83 | Hash type | `--format=` | Notes | 84 | :-- | :-- | :-- | 85 | MD5 (raw) | `raw-md5` | 32 hex | 86 | MD4 (raw) | `raw-md4` | 32 hex | 87 | SHA-1 | `raw-sha1` | 40 hex | 88 | SHA-224 | `raw-sha224` | | 89 | SHA-256 | `raw-sha256` | 64 hex | 90 | SHA-384 | `raw-sha384` | | 91 | SHA-512 | `raw-sha512` | 128 hex | 92 | SHA3-256 / 512 | `raw-sha3` | | 93 | RIPEMD-160 | `ripemd-160` | | 94 | Whirlpool | `whirlpool` | | 95 | BLAKE2b-512 | `raw-blake2` | | 96 | GOST R 34.11-94 | `gost` | | 97 98 ### OS / login hashes 99 100 | Hash type | `--format=` | Notes | 101 | :-- | :-- | :-- | 102 | DES crypt (traditional) | `descrypt` | 13 chars | 103 | MD5 crypt `$1$` | `md5crypt` | Linux/BSD, Cisco-IOS | 104 | bcrypt `$2a$`/`$2b$`/`$2y$` | `bcrypt` | very slow, GPU-resistant | 105 | SHA-256 crypt `$5$` | `sha256crypt` | Linux | 106 | SHA-512 crypt `$6$` | `sha512crypt` | modern Linux `/etc/shadow` | 107 | scrypt `$7$` | `scrypt` | | 108 | Argon2 | `argon2` | i / id / d variants | 109 | Apache `$apr1$` | `md5crypt` (or `apache-md5`) | htpasswd MD5 | 110 | AIX smd5 / ssha | `aix-smd5` / `aix-ssha256` | | 111 | macOS 10.8+ | `pbkdf2-hmac-sha512` | via `ml2john` | 112 113 ### Windows / Active Directory 114 115 | Hash type | `--format=` | Notes | 116 | :-- | :-- | :-- | 117 | NTLM (NT hash) | `nt` | AD user hash, 32 hex | 118 | LM (legacy) | `lm` | | 119 | NetNTLMv1 | `netntlm` | Responder capture | 120 | NetNTLMv2 | `netntlmv2` | Responder capture (most common) | 121 | MS-Cache v1 (DCC) | `mscash` | | 122 | MS-Cache v2 (DCC2) | `mscash2` | domain cached creds | 123 | Kerberos AS-REP (roast) | `krb5asrep` | from `GetNPUsers.py` | 124 | Kerberos TGS (roast) | `krb5tgs` | from `GetUserSPNs.py` | 125 | Kerberos pre-auth (etype 23) | `krb5pa-md5` | | 126 | DPAPI masterkey | `dpapimk` | | 127 128 ### Databases 129 130 | Hash type | `--format=` | Notes | 131 | :-- | :-- | :-- | 132 | MySQL ≤ 4.0 | `mysql` | 16 hex | 133 | MySQL 4.1+/5+ | `mysql-sha1` | leading `*` | 134 | PostgreSQL MD5 | `postgres` | | 135 | MSSQL 2000 | `mssql` | | 136 | MSSQL 2005 | `mssql05` | | 137 | MSSQL 2012/2014 | `mssql12` | | 138 | Oracle 7-10g | `oracle` | | 139 | Oracle 11g | `oracle11` | | 140 | Oracle 12c | `oracle12c` | | 141 | MongoDB SCRAM-SHA-1 | `mongodb` | | 142 143 ### Apps, archives & files 144 145 | Hash type | `--format=` | Prepare with | 146 | :-- | :-- | :-- | 147 | ZIP (classic/AES) | `zip` / `pkzip` | `zip2john` | 148 | RAR3 / RAR5 | `rar` / `rar5` | `rar2john` | 149 | 7-Zip | `7z` | `7z2john` | 150 | PDF | `pdf` | `pdf2john` | 151 | Office 2007-2013+ | `office` | `office2john` | 152 | Old Office (97-2003) | `oldoffice` | `office2john` | 153 | OpenDocument | `odf` | `odf2john` | 154 | KeePass 1/2 | `keepass` | `keepass2john` | 155 | SSH private key | `ssh` | `ssh2john` | 156 | GPG/PGP secret key | `gpg` | `gpg2john` | 157 | LUKS | `luks` | `luks2john` | 158 | BitLocker | `bitlocker` | `bitlocker2john` | 159 | macOS keychain | `keychain` | `keychain2john` | 160 | Bitcoin/Ethereum wallet | `bitcoin` / `ethereum` | `bitcoin2john` / `ethereum2john` | 161 | WPA/WPA2 handshake | `wpapsk` | `hcxpcapngtool` then `wpapcap2john` | 162 | htpasswd (bcrypt) | `bcrypt` | already a hash | 163 | JWT (HS256 etc.) | `HMAC-SHA256` | strip and format manually, or use hashcat `-m 16500` | 164 165 > **Note — formatting upgrade.** Store the `--format=` value in your notes **next to the artefact type**, not the hash string. On a real box you rarely know the algorithm until you have run the `*2john` helper — the helper output line usually starts with `$name$`, which tells you the format immediately (e.g. `$krb5tgs$23$...` → `--format=krb5tgs`). 166 167 ## 4. Preparing Hashes — the `*2john` Helpers 168 169 Most non-trivial targets are not bare hashes; they are files or captures. The `*2john` scripts extract a crackable hash string. Run `ls /usr/share/john/*2john*` and `ls /usr/bin/*2john` to see what is installed. 170 171 ```bash 172 ssh2john id_rsa > ssh.hash 173 zip2john archive.zip > zip.hash 174 rar2john archive.rar > rar.hash 175 7z2john archive.7z > 7z.hash # may be 7z2john.pl 176 pdf2john secret.pdf > pdf.hash 177 office2john report.docx > office.hash 178 keepass2john Database.kdbx > kp.hash 179 gpg2john secret.gpg > gpg.hash 180 ``` 181 182 ```bash 183 # Then crack — format is often auto-detected, but pin it to be safe: 184 john --wordlist=/usr/share/wordlists/rockyou.txt --format=ssh ssh.hash 185 ``` 186 187 ## 5. Cracking Mode Flags 188 189 <figure class="flow plate corners"> 190 <figcaption class="flow__cap"><span class="flow__kind">Cracking mode escalation</span><span class="flow__dir">TD</span></figcaption> 191 <div class="flow__body"> 192 <div class="flow__diagram" data-dir="td"> 193 <div class="flow-rank"><div class="flow-node is-entry">--single</div></div> 194 <div class="flow-edge"><span class="flow-edge__label">fast, uses GECOS/username</span></div> 195 <div class="flow-rank"><div class="flow-node">--wordlist</div></div> 196 <div class="flow-edge"><span class="flow-edge__label">+ mangling</span></div> 197 <div class="flow-rank"><div class="flow-node">--wordlist + --rules</div></div> 198 <div class="flow-edge"><span class="flow-edge__label">exhausted</span></div> 199 <div class="flow-rank"><div class="flow-node">--mask</div></div> 200 <div class="flow-edge"><span class="flow-edge__label">structured</span></div> 201 <div class="flow-rank"><div class="flow-node">--incremental</div></div> 202 <div class="flow-edge"><span class="flow-edge__label">brute-force, last resort</span></div> 203 <div class="flow-rank"><div class="flow-node">done or give up</div></div> 204 </div> 205 </div> 206 </figure> 207 208 | Flag | Mode | Use when | 209 | :-- | :-- | :-- | 210 | `--single` | Single crack | Fast first pass; derives candidates from the username/GECOS fields in the hash file | 211 | `--wordlist=FILE` | Dictionary | You have a wordlist (default go-to) | 212 | `--wordlist=FILE --rules` | Dictionary + mangling | Apply word-mangling rules (see below) | 213 | `--incremental[=MODE]` | Brute-force | Wordlists exhausted; `MODE` = `ASCII`, `Digits`, `Alpha`, `LM_ASCII`… | 214 | `--mask=?u?l?l?l?d?d` | Mask/brute | You know the password pattern | 215 | `--external=NAME` | External | Custom C-like generators in `john.conf` | 216 | `--loopback` | Loopback | Feed already-cracked passwords back as a wordlist | 217 | `--prince=FILE` | PRINCE | Combinator-style candidate generation | 218 219 ```bash 220 # Classic escalating attack on a shadow file 221 john --single passwd.hash 222 john --wordlist=rockyou.txt passwd.hash 223 john --wordlist=rockyou.txt --rules=Jumbo passwd.hash 224 john --incremental passwd.hash 225 ``` 226 227 > **Tip — combine `--single` first, it is free.** `--single` runs in seconds and catches passwords derived from the username (e.g. user `admin` → `admin123`, `Admin!`). Always run it before touching a wordlist. 228 229 ## 6. Rules, Masks & Tuning 230 231 ```bash 232 # Built-in rule sets (defined in /etc/john/john.conf) 233 john --wordlist=rockyou.txt --rules=Single hash.txt 234 john --wordlist=rockyou.txt --rules=Jumbo hash.txt # large, thorough 235 john --wordlist=rockyou.txt --rules=KoreLogic hash.txt 236 237 # Mask attack — placeholders: 238 # ?l lower ?u upper ?d digit ?s special ?a all ?h/?H hex 239 john --mask='?u?l?l?l?l?d?d' hash.txt 240 john --mask='Summer?d?d?d?d' hash.txt # e.g. Summer2024 241 242 # Hybrid: wordlist + appended mask 243 john --wordlist=rockyou.txt --mask='?w?d?d?d' hash.txt # word + 3 digits 244 245 # Fork across CPU cores (Jumbo) 246 john --fork=4 --wordlist=rockyou.txt hash.txt 247 248 # Limit runtime / candidate count 249 john --wordlist=rockyou.txt --max-run-time=300 hash.txt 250 ``` 251 252 ## 7. Session, Output & Status Flags 253 254 ```bash 255 john --show hash.txt # print cracked plaintexts 256 john --show --format=nt hash.txt # pin format when showing 257 john --show=left hash.txt # show still-uncracked hashes 258 259 john --session=engagement hash.txt # named session (resumable) 260 john --restore=engagement # resume it after Ctrl-C / crash 261 john --status=engagement # check progress of a running session 262 263 # During a live run: press any key for a status line, 'q' to quit gracefully 264 265 john --pot=/tmp/custom.pot hash.txt # use an alternate pot file 266 john --list=formats # all supported formats 267 john --test --format=sha512crypt # benchmark one format (speeds) 268 ``` 269 270 ## 8. Running It — Worked Examples 271 272 Every example is the same two steps: **crack** with a format + wordlist, then **`--show`** the plaintext. Pin `--format=` so John never guesses wrong on a shared hash length. 273 274 ### NetNTLMv2 (Responder capture) 275 276 ```bash 277 # Crack — file holds the $NETNTLMv2$ line captured by Responder / ntlmrelayx 278 john --format=netntlmv2 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt p.agila.ntlmv2 279 280 # Show the recovered password 281 john --show --format=netntlmv2 p.agila.ntlmv2 282 ``` 283 284 ### NTLM / NT hash (dumped from a DC) 285 286 ```bash 287 john --format=nt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt ntlm.txt 288 john --show --format=nt ntlm.txt 289 ``` 290 291 ### Kerberoast — TGS ticket (`GetUserSPNs.py`) 292 293 ```bash 294 # Output line begins with $krb5tgs$23$... 295 john --format=krb5tgs --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt spns.txt 296 john --show --format=krb5tgs spns.txt 297 ``` 298 299 ### AS-REP roast (`GetNPUsers.py`) 300 301 ```bash 302 # Output line begins with $krb5asrep$23$... 303 john --format=krb5asrep --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt asrep.txt 304 john --show --format=krb5asrep asrep.txt 305 ``` 306 307 ### Linux `/etc/shadow` (`$6$` = sha512crypt) 308 309 ```bash 310 # Merge passwd + shadow first so --single can use usernames 311 unshadow /etc/passwd /etc/shadow > unshadowed.txt 312 john --format=sha512crypt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt unshadowed.txt 313 john --show --format=sha512crypt unshadowed.txt 314 ``` 315 316 ### SSH private key 317 318 ```bash 319 ssh2john id_rsa > ssh.hash 320 john --format=ssh --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt ssh.hash 321 john --show --format=ssh ssh.hash 322 ``` 323 324 ### ZIP archive 325 326 ```bash 327 zip2john secret.zip > zip.hash 328 john --format=zip --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt zip.hash 329 john --show --format=zip zip.hash 330 ``` 331 332 ### KeePass database 333 334 ```bash 335 keepass2john Database.kdbx > kp.hash 336 john --format=keepass --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt kp.hash 337 john --show --format=keepass kp.hash 338 ``` 339 340 ### Office document 341 342 ```bash 343 office2john report.docx > office.hash 344 john --format=office --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt office.hash 345 john --show --format=office office.hash 346 ``` 347 348 ### RAR archive 349 350 ```bash 351 rar2john archive.rar > rar.hash 352 # rar2john stamps $rar5$ or $RAR3$ into the line — use rar5 for the former 353 john --format=rar5 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt rar.hash 354 john --show --format=rar5 rar.hash 355 ``` 356 357 ### 7-Zip archive 358 359 ```bash 360 7z2john archive.7z > 7z.hash # may be 7z2john.pl on some builds 361 john --format=7z --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt 7z.hash 362 john --show --format=7z 7z.hash 363 ``` 364 365 ### PDF 366 367 ```bash 368 pdf2john secret.pdf > pdf.hash 369 john --format=pdf --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt pdf.hash 370 john --show --format=pdf pdf.hash 371 ``` 372 373 ### GPG / PGP secret key 374 375 ```bash 376 gpg2john secret.gpg > gpg.hash 377 john --format=gpg --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt gpg.hash 378 john --show --format=gpg gpg.hash 379 ``` 380 381 ### NetNTLMv1 (Responder capture) 382 383 ```bash 384 john --format=netntlm --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt netntlmv1.txt 385 john --show --format=netntlm netntlmv1.txt 386 ``` 387 388 ### Domain cached creds — MS-Cache v2 (DCC2) 389 390 ```bash 391 # Format: username:$DCC2$10240#username#hash 392 john --format=mscash2 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt dcc2.txt 393 john --show --format=mscash2 dcc2.txt 394 ``` 395 396 ### bcrypt (htpasswd / app DB, `$2a$`/`$2b$`/`$2y$`) 397 398 ```bash 399 # Already a hash — no *2john needed. Slow; keep the wordlist tight. 400 john --format=bcrypt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt bcrypt.txt 401 john --show --format=bcrypt bcrypt.txt 402 ``` 403 404 ### Raw MD5 (unsalted digest) 405 406 ```bash 407 john --format=raw-md5 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt md5.txt 408 john --show --format=raw-md5 md5.txt 409 ``` 410 411 ### LUKS full-disk encryption 412 413 ```bash 414 luks2john disk.img > luks.hash # or point at the LUKS device/partition 415 john --format=luks --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt luks.hash 416 john --show --format=luks luks.hash 417 ``` 418 419 ### WPA/WPA2 handshake 420 421 ```bash 422 # Convert the capture, then crack the PSK 423 wpapcap2john capture.cap > wpa.hash 424 john --format=wpapsk --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt wpa.hash 425 john --show --format=wpapsk wpa.hash 426 ``` 427 428 ### LM hash (legacy Windows) 429 430 ```bash 431 # LM is uppercase-only and split into two 7-char halves — cracks fast 432 john --format=lm --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt lm.txt 433 john --show --format=lm lm.txt 434 ``` 435 436 ### md5crypt (`$1$` — Linux/BSD, Cisco IOS type 5) 437 438 ```bash 439 john --format=md5crypt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt md5crypt.txt 440 john --show --format=md5crypt md5crypt.txt 441 ``` 442 443 ### DES crypt (traditional 13-char Unix) 444 445 ```bash 446 john --format=descrypt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt descrypt.txt 447 john --show --format=descrypt descrypt.txt 448 ``` 449 450 ### MySQL 4.1+ / 5+ (leading `*`) 451 452 ```bash 453 john --format=mysql-sha1 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt mysql.txt 454 john --show --format=mysql-sha1 mysql.txt 455 ``` 456 457 ### MSSQL 2012/2014 458 459 ```bash 460 john --format=mssql12 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt mssql.txt 461 john --show --format=mssql12 mssql.txt 462 ``` 463 464 ### Oracle 11g 465 466 ```bash 467 john --format=oracle11 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt oracle.txt 468 john --show --format=oracle11 oracle.txt 469 ``` 470 471 ### BitLocker volume 472 473 ```bash 474 bitlocker2john -i disk.img > bitlocker.hash 475 john --format=bitlocker --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt bitlocker.hash 476 john --show --format=bitlocker bitlocker.hash 477 ``` 478 479 ### macOS keychain 480 481 ```bash 482 keychain2john login.keychain-db > keychain.hash 483 john --format=keychain --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt keychain.hash 484 john --show --format=keychain keychain.hash 485 ``` 486 487 ### Bitcoin / crypto wallet 488 489 ```bash 490 bitcoin2john wallet.dat > wallet.hash 491 john --format=bitcoin --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt wallet.hash 492 john --show --format=bitcoin wallet.hash 493 ``` 494 495 ### DPAPI masterkey 496 497 ```bash 498 # Extract with dpapi.py (impacket) or the DPAPImk2john helper first 499 john --format=dpapimk --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt dpapi.hash 500 john --show --format=dpapimk dpapi.hash 501 ``` 502 503 > **Tip — benchmark before a slow run.** `john --test --format=bcrypt` prints c/s (candidates per second) so you know whether a wordlist run is minutes or days. Omit `--format=` to benchmark everything. 504 505 ## 9. Alternative Approaches & Modern Tooling 506 507 > **Tip — move salted-but-fast hashes to a GPU.** John is CPU-first. For raw MD5/SHA/NTLM and other GPU-friendly algorithms, **hashcat** on a GPU is often 10–100× faster. Keep John for formats hashcat lacks and for its superb `*2john` extractors and `--single`/rules ergonomics. 508 509 > **Note — `hashid` → mode mapping.** `hashid -m` prints the matching **hashcat** `-m` number. There is no clean one-liner mapping to John format names, so keep the table in §3 as your lookup. 510 511 > **Warning — prefer `hcxpcapngtool` for Wi-Fi.** The older `wpapcap2john` path is fragile with modern captures. Convert with `hcxpcapngtool` (from `hcxtools`) to a `.hc22000` and crack in hashcat `-m 22000`, which is the current standard for WPA/WPA2/WPA3-SAE.