The world's fastest password cracker, powered by your GPU. Stolen hash databases stop being blobs of hex and start being proof of weak password policies.
Follow the steps — click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Wrong mode = guaranteed failure. ID first, always.
Watch hardware chew through billions of guesses. Science.
-m selects hash mode; NTLM (1000) is the classic Windows dump.
Rules turn 'password' into P@ssw0rd2026! automatically.
--show and --left let you report coverage for writeups.
| -m N | hash mode (1000 NTLM, 0 MD5, 1800 sha512crypt…) |
| -a 0/3/6/7 | straight/mask/combo/hybrid |
| -r rule | mutation rules |
| (?l?d…) | mask syntax: ?l ?u ?d ?s ?a |
| --show/--left | cracked / remaining |
| -w 3 | workload: faster |
rockyou.txt + best64.rule solves most CTF/lab hashes in minutes.
Hybrid attack -a 6 wordlist ?d?d?d?d nails 'Company2026!' style passwords.
No GPU? Use --force with CPU or crack smaller samples; or use John.
Legally: only hashes you own — lab dumps, CTF files, authorized audits.
Use Hashcat only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox — plenty of legal targets, zero risk.