Comparison · neutral framing
hashcat vs john
Both work offline against captured hashes. The practical difference is GPU throughput and kernel breadth versus format agility and rules tooling.
Attributes
Values describe documented behaviour. Anything workload- or hardware-dependent is written as a practice, not a number.
Engine
GPU acceleration
- hashcat
- Primary design
- john
- Optional OpenCL/CUDA builds
Hash format detection
- hashcat
- Manual mode selection
- john
- Documented
Modes
Mask/keyspace attacks
- hashcat
- Extensive
- john
- Incremental modes
Rule language
- hashcat
- Rule files
- john
- Rules + single-shot
Operation
Resume/restore
- hashcat
- Documented
- john
- Documented
Benchmark built in
- hashcat
- Documented
- john
- `--test` / `--stress`
Works without extra drivers
- hashcat
- Not a feature
- john
- Documented
Handling
Sensitive output files
- hashcat
- potfile + .restoreContain plaintext — protect and delete
- john
- pot file + sessionsSame obligation
Hashcat
Kernel-based cracking on GPUs with explicit hash modes and attack modes.
Strengths
- Highest throughput on common formats
- Straight/rules/hybrid/mask/broadcast attack modes
- Benchmark mode for keyspace-vs-time planning
- Potfile + session restore for long audits
Limitations
- You choose the numeric mode yourself; wrong mode means zero results
- Driver and device setup is a real dependency
Consider Hashcat when
- — Large candidate volume against common digest formats
- — Measuring how fast a policy falls on known hardware
John the Ripper
CPU-first auditor with format auto-detection, single-shot mode and a deep rule language.
Strengths
- Detects formats and handles unusual ones
- `unshadow` and friends for local policy review
- Session/potfile workflow is simple to script
- No GPU driver dependency
Limitations
- Lower raw speed on GPU-friendly formats
- Build variants differ in supported formats
Consider John the Ripper when
- — Unknown or exotic digest formats
- — A quick `--single` pass over a local audit file
- — Rule experimentation before committing a run
The same job, both ways
Cheap first, expensive second
hashcat
hashcat -m 1000 -a 3 hashes.txt '?u?l?l?l?l?d?d' --session policy
john
john --single hashes.txt && john --wordlist=base.txt --rules hashes.txt
Order matters for the report: state which candidate space was actually covered.
Sources
Both columns should be checkable against upstream documentation.