home/toolvault/password attacks/hashcat

Hashcat //

Password Attacksgpu cracking

The world's fastest password cracker, powered by your GPU. Stolen hash databases stop being blobs of hex and start being proof of weak password policies.

difficulty · intermediate
10 min
time to first win
5
guided steps
0
students started here*

HOW TO USE HASHCAT

Follow the steps — click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

hashcat — guided lab session
static view
step 01

Identify the hash type

hashcat --identify hashes.txt (or: name-that-hash)

Wrong mode = guaranteed failure. ID first, always.

step 02

Benchmark (fun!)

hashcat -b

Watch hardware chew through billions of guesses. Science.

step 03

Straight wordlist attack

hashcat -m 1000 hashes.txt rockyou.txt

-m selects hash mode; NTLM (1000) is the classic Windows dump.

step 04

Add mutation rules

hashcat -m 1000 hashes.txt rockyou.txt -r rules/best64.rule

Rules turn 'password' into P@ssw0rd2026! automatically.

step 05

Show the loot

hashcat -m 1000 hashes.txt rockyou.txt --show

--show and --left let you report coverage for writeups.

THE WORKFLOW AT A GLANCE

🗄️
Hashes
dump / leak
🔍
Identify
mode -m N
📚
Wordlist
rockyou + rules
⚡
Crack
GPU at max
📊
Report
--show results
LEARNING CURVE
intermediate — 10 min to first win

FLAGS & SUPER-MOVES

-m Nhash mode (1000 NTLM, 0 MD5, 1800 sha512crypt…)
-a 0/3/6/7straight/mask/combo/hybrid
-r rulemutation rules
(?l?d…)mask syntax: ?l ?u ?d ?s ?a
--show/--leftcracked / remaining
-w 3workload: faster

PRO TIPS

01

rockyou.txt + best64.rule solves most CTF/lab hashes in minutes.

rockyou.txt + best64.rule solves most CTF/lab hashes in minutes.

02

Hybrid attack -a 6 wordlist ?d?d?d?d nails 'Company2026!' style passwords.

Hybrid attack -a 6 wordlist ?d?d?d?d nails 'Company2026!' style passwords.

03

No GPU? Use --force with CPU or crack smaller samples; or use John.

No GPU? Use --force with CPU or crack smaller samples; or use John.

04

Legally

Legally: only hashes you own — lab dumps, CTF files, authorized audits.

⚖️

Golden rule

Use Hashcat only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox — plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 · v2 immersive · latest news
Made for learners, everywhere · 2026
*plausibly. verify commands with official docs.