← All cheat sheets

HASHCAT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tools: Hashcat / John Rule & Mask Builder, Hash Identifier

BASIC SYNTAX#

hashcat -m <mode> -a <attack> <hashfile> <wordlist/mask>
hashcat -m 0 -a 0 hash.txt wordlist.txt

COMMON OPTIONS#

-m <mode>         Hash type (see modes below)
-a <attack>       Attack mode (0-7)
-o <file>         Output file for cracked hashes
-r <file>         Rules file
-w <level>        Workload profile (1-4)
--show            Show already cracked hashes
--left            Show uncracked hashes
--status          Enable status screen
--force           Ignore warnings
-O                Optimized kernels (faster, length limit)
--potfile-path    Custom potfile path
--session         Session name for restore
--restore         Restore session
-j <rule>         Single rule for left wordlist
-k <rule>         Single rule for right wordlist

ATTACK MODES (-a)#

0 = Dictionary attack (straight)
1 = Combination attack
3 = Brute-force/Mask attack
6 = Dictionary + Mask
7 = Mask + Dictionary
9 = Association attack

COMMON HASH MODES (-m)#

# Unix/Linux
500     md5crypt ($1$)
1800    sha512crypt ($6$)
7400    sha256crypt ($5$)
3200    bcrypt ($2*$)
1500    descrypt
22     Juniper NetScreen/SSG

# Windows
0       MD5
100     SHA1
1000    NTLM
3000    LM
5600    NetNTLMv2
5500    NetNTLMv1
1100    Domain Cached Credentials (DCC)
2100    Domain Cached Credentials 2 (DCC2)

# Web Applications
0       MD5
100     SHA1
1400    SHA256
1700    SHA512
10      md5($pass.$salt)
20      md5($salt.$pass)
3200    bcrypt
400     phpass (WordPress, Drupal, etc.)
2611    vBulletin < v3.8.5
2711    vBulletin >= v3.8.5
121     SMF > v1.1
11      Joomla < 2.5.18
400     Joomla >= 2.5.18

# Database
0       MySQL323
300     MySQL4.1/MySQL5
1731    MSSQL (2012, 2014)
112     Oracle S: Type (Oracle 11+)
3100    Oracle H: Type (Oracle 7-10)
12300   Oracle T: Type (Oracle 12+)
50      HMAC-MD5

# Network
2500    WPA/WPA2
22000   WPA-PBKDF2-PMKID+EAPOL
16800   WPA-PMKID-PBKDF2
5500    NetNTLMv1
5600    NetNTLMv2
7300    IPMI2 RAKP
8300    DNSSEC (NSEC3)

# Kerberos
13100   Kerberos 5 TGS-REP (etype 23)
18200   Kerberos 5 AS-REP (etype 23)
19600   Kerberos 5 TGS-REP (etype 17)
19700   Kerberos 5 TGS-REP (etype 18)

# Documents/Archives
9400    MS Office 2007
9500    MS Office 2010
9600    MS Office 2013
11300   Bitcoin wallet
12500   RAR3-hp
13000   RAR5
11600   7-Zip
13600   WinZip
16200   Apple Secure Notes
18300   Apple File System (APFS)

# Cloud
21800   Electrum Wallet
21600   Web2py pbkdf2-sha512
22500   MultiBit Classic
22700   MultiBit HD
22911   RSA/DSA/EC/OpenSSH Private Keys

MASK ATTACK (-a 3)#

# Charset placeholders
?l = abcdefghijklmnopqrstuvwxyz
?u = ABCDEFGHIJKLMNOPQRSTUVWXYZ
?d = 0123456789
?s = special characters (!@#$%^&*...)
?a = ?l?u?d?s (all)
?b = 0x00-0xff

# Examples
hashcat -m 0 -a 3 hash.txt ?l?l?l?l?l?l          # 6 lowercase
hashcat -m 0 -a 3 hash.txt ?u?l?l?l?l?l?d?d      # Ullllldd
hashcat -m 0 -a 3 hash.txt ?d?d?d?d?d?d          # 6 digits
hashcat -m 0 -a 3 hash.txt password?d?d?d        # password + 3 digits
hashcat -m 0 -a 3 hash.txt ?a?a?a?a?a?a?a?a      # 8 any chars

# Custom charset
hashcat -m 0 -a 3 hash.txt -1 ?l?d ?1?1?1?1?1    # lowercase + digits
hashcat -m 0 -a 3 hash.txt -1 abc -2 123 ?1?1?2?2  # custom sets

# Increment mode
hashcat -m 0 -a 3 hash.txt ?a?a?a?a?a?a --increment --increment-min=4

DICTIONARY ATTACK (-a 0)#

hashcat -m 0 -a 0 hash.txt wordlist.txt
hashcat -m 0 -a 0 hash.txt wordlist.txt -r rules/best64.rule
hashcat -m 0 -a 0 hash.txt wordlist1.txt wordlist2.txt

COMBINATION ATTACK (-a 1)#

hashcat -m 0 -a 1 hash.txt wordlist1.txt wordlist2.txt

HYBRID ATTACKS (-a 6, -a 7)#

# Dictionary + Mask
hashcat -m 0 -a 6 hash.txt wordlist.txt ?d?d?d?d

# Mask + Dictionary
hashcat -m 0 -a 7 hash.txt ?d?d?d?d wordlist.txt

RULES#

# Built-in rules (in rules/ folder)
best64.rule
rockyou-30000.rule
d3ad0ne.rule
dive.rule
generated.rule
generated2.rule
Incisive-leetspeak.rule
InsidePro-HashManager.rule
InsidePro-PasswordsPro.rule
leetspeak.rule
oscommerce.rule
T0XlC.rule
toggles1.rule to toggles5.rule

# Common rule functions
:       Do nothing
l       Lowercase all
u       Uppercase all
c       Capitalize first, lower rest
C       Lowercase first, upper rest
t       Toggle case all
$X      Append character X
^X      Prepend character X
d       Duplicate word
r       Reverse word
[       Delete first character
]       Delete last character
sXY     Replace X with Y

# Example usage
hashcat -m 0 -a 0 hash.txt wordlist.txt -r rules/best64.rule
hashcat -m 0 -a 0 hash.txt wordlist.txt -r rule1.rule -r rule2.rule

WORKLOAD PROFILES (-w)#

1 = Low (desktop usage during crack)
2 = Default
3 = High
4 = Nightmare (may freeze system)

PRACTICAL EXAMPLES#

# MD5 dictionary attack
hashcat -m 0 -a 0 md5.txt /usr/share/wordlists/rockyou.txt

# NTLM with rules
hashcat -m 1000 -a 0 ntlm.txt rockyou.txt -r rules/best64.rule

# WPA2 cracking
hashcat -m 22000 capture.hc22000 rockyou.txt

# SHA256 brute force 8 chars
hashcat -m 1400 -a 3 sha256.txt ?a?a?a?a?a?a?a?a

# Kerberos TGS cracking
hashcat -m 13100 -a 0 kerberos.txt wordlist.txt

# bcrypt slow but possible
hashcat -m 3200 -a 0 bcrypt.txt wordlist.txt -w 3

# NetNTLMv2
hashcat -m 5600 -a 0 netntlmv2.txt rockyou.txt

# Show cracked passwords
hashcat -m 0 hash.txt --show

# Restore session
hashcat --session=mysession -m 0 -a 0 hash.txt wordlist.txt
hashcat --restore --session=mysession

PERFORMANCE TIPS#

# Use optimized kernels (faster but limited length)
hashcat -O ...

# Adjust workload
hashcat -w 3 ...

# Use GPU-specific tuning
hashcat --force --opencl-device-types 1,2

# Check benchmark
hashcat -b -m 0

# Monitor temperature
hashcat --hwmon-temp-abort=90

OUTPUT#

# Save to file
hashcat -m 0 -a 0 hash.txt wordlist.txt -o cracked.txt

# Output format
hashcat -m 0 -a 0 hash.txt wordlist.txt -o cracked.txt --outfile-format=2
# 1 = hash[:salt]
# 2 = plain
# 3 = hash[:salt]:plain
# 4 = hex_plain
# 5 = hash[:salt]:hex_plain

HASH EXTRACTION#

# From /etc/shadow
cat /etc/shadow | grep -v '!' | grep -v '*' > hashes.txt

# From Windows (Mimikatz output)
# From SAM database
# From NTDS.dit (secretsdump.py)

# Identify hash type
hashid hash
hash-identifier
hashcat --example-hashes | grep -A2 "MODE:"

TROUBLESHOOTING#

# If GPU not detected
hashcat -I                    # Show devices
hashcat --force               # Force operation
hashcat --opencl-device-types 1,2

# If running out of memory
hashcat -n 1                  # Reduce threads
hashcat -O                    # Use optimized kernels

# Session management
hashcat --session=name        # Name session
hashcat --restore             # Resume session
hashcat -s 1000000            # Skip first N words
hashcat -l 1000000            # Process only N words