Skip to content

Comparison · neutral framing

hashcat vs john

Both work offline against captured hashes. The practical difference is GPU throughput and kernel breadth versus format agility and rules tooling.

HashcatJohn the Ripperrevised 10 Jan 2026

Attributes

Values describe documented behaviour. Anything workload- or hardware-dependent is written as a practice, not a number.

Engine

  • GPU acceleration

    hashcat
    Primary design
    john
    Optional OpenCL/CUDA builds
  • Hash format detection

    hashcat
    Manual mode selection
    john
    Documented

Modes

  • Mask/keyspace attacks

    hashcat
    Extensive
    john
    Incremental modes
  • Rule language

    hashcat
    Rule files
    john
    Rules + single-shot

Operation

  • Resume/restore

    hashcat
    Documented
    john
    Documented
  • Benchmark built in

    hashcat
    Documented
    john
    `--test` / `--stress`
  • Works without extra drivers

    hashcat
    Not a feature
    john
    Documented

Handling

  • Sensitive output files

    hashcat
    potfile + .restoreContain plaintext — protect and delete
    john
    pot file + sessionsSame obligation

Hashcat

Kernel-based cracking on GPUs with explicit hash modes and attack modes.

Strengths

  • Highest throughput on common formats
  • Straight/rules/hybrid/mask/broadcast attack modes
  • Benchmark mode for keyspace-vs-time planning
  • Potfile + session restore for long audits

Limitations

  • You choose the numeric mode yourself; wrong mode means zero results
  • Driver and device setup is a real dependency

Consider Hashcat when

  • — Large candidate volume against common digest formats
  • — Measuring how fast a policy falls on known hardware

John the Ripper

CPU-first auditor with format auto-detection, single-shot mode and a deep rule language.

Strengths

  • Detects formats and handles unusual ones
  • `unshadow` and friends for local policy review
  • Session/potfile workflow is simple to script
  • No GPU driver dependency

Limitations

  • Lower raw speed on GPU-friendly formats
  • Build variants differ in supported formats

Consider John the Ripper when

  • — Unknown or exotic digest formats
  • — A quick `--single` pass over a local audit file
  • — Rule experimentation before committing a run

The same job, both ways

Cheap first, expensive second

hashcat

hashcat -m 1000 -a 3 hashes.txt '?u?l?l?l?l?d?d' --session policy

john

john --single hashes.txt && john --wordlist=base.txt --rules hashes.txt

Order matters for the report: state which candidate space was actually covered.

Sources

Both columns should be checkable against upstream documentation.