Skip to content

Hashcat

GPU-accelerated password recovery benchmark

VerifiedPentesting· Credential & Hash AuditingAdvancedOpen sourceEntry revised 10 Jan 2026
  • Windows
  • macOS
  • Linux
  • Kali
  • Parrot
  • Arch
  • Fedora
  • Source

Overview

8 commands documented

Hashcat is an offline password-recovery benchmark and audit tool. It runs candidate words through a hashing kernel on the GPU or CPU and compares digests, which makes it useful for measuring how quickly a policy's passwords fall to a modern attack.

Legitimate use is against hashes you own or are authorized to test: your own lab captures, a client's export supplied in the scope document, or benchmarking hardware. Any other use against other people's credentials is unlawful.

Supported platforms

8

Documented install or usage guidance

Learning curve

advanced

Difficulty of becoming productive, not of the underlying theory

Tags

hashing, password audit, gpu, wordlist, rules

Dataset entry

hashcat.ts

Reviewed 2026-01-10

Installation

Grouped by platform. Elevation requirements are marked per method.

Official 7-Zip archive

RecommendedreleaseOfficial

Windows builds are distributed as signed archives on the project's download page; extract to a folder and run hashcat.exe from there.

  • Antivirus and SmartScreen frequently flag the binary. Exclude the lab folder deliberately, not blindly.
Open official source

Package availability follows your distribution and enabled repositories. Entry revised 10 Jan 2026 — confirm the current release on the project's own download page.

Commands

8 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Identify the hash type

bash

A helper bundled with the project estimates the hash mode so you do not guess a numeric mode.

hashid '5f4dcc3b5aa765d61d8327deb882cf99'

Notes

  • `hashcat --example_hashes` is the built-in reference of every mode with a sample digest.

02Straight wordlist attack

bash

Tests each candidate word against every hash in the file.

hashcat -m 0 -a 0 captures/hashes.txt /usr/share/wordlists/rockyou.txt

Notes

  • `-m 0` is MD5, `-a 0` is the straight attack. `-o recovered.txt` writes results, `--show` lists already-recovered plaintexts without re-running.

03Wordlist with rules

bash

Applies mangling rules (capitalisation, appending years, leet substitution) to each base word.

hashcat -m 100 -a 0 -r rules/best64.rule captures/sha1.txt company-wordlist.txt

Notes

  • Rules turn one list into thousands of variants; expect the candidate rate to fall accordingly. `rules/` ships with the project.

04Brute force with a mask

bash

Enumerates a pattern instead of the whole keyspace — the practical way to test a stated policy.

hashcat -m 1000 -a 3 captures/ntlm.txt '?u?l?l?l?l?d?d'

Example output

Illustrative only — real output depends on the target, version and your position on the network.

Session..........: hashcat
Speed.#1.........: 21474836 ks/s
Recovered........: 4125/10000 (41.25%)

Notes

  • Always state a keyspace estimate before starting a mask attack — `?u?l?l?l?l?d?d` alone is billions of candidates.

05Hybrid word + mask

bash

Appends a mask suffix to each word, which mirrors how users extend a common base.

hashcat -m 1000 -a 6 base-words.txt '?d?d?d' --increment

06Benchmark and device check

bash

Measures candidate rates per mode so you can compare hardware or estimate an audit's runtime.

hashcat -b -m 1000

Notes

  • `hashcat -I` shows devices and driver versions; `--backend-ignore-dev` excludes an accelerator that is causing kernel errors.

07Pause and resume a long audit

bash

Sessions store the restore point so an overnight run survives a reboot.

hashcat --session corp-q1 --restore

Notes

  • Restore files live in the session directory (on Linux: `~/.local/share/hashcat/`). Keep them with the engagement record and delete them at the end.

08Verify what has already been recovered

bash

Reads matches from the potfile instead of re-cracking hashes an earlier run already solved.

hashcat -m 0 --show captures/hashes.txt
  • The potfile stores plaintext. Treat it as sensitive material: encrypted storage, restricted access, deletion at engagement close.

Worked examples

Sequences of commands in the order they are used, with what you should expect to learn from each.

Auditing a password policy, defensibly

The security policy requires 8+ characters with a class. The client exports salted SHA-1 of all accounts for a controlled audit.

  1. 1

    Confirm the mode and rate on your hardware

    hashcat -b -m 100 | tail -n 12
  2. 2

    Baseline: top corporate-password lists against the export

    hashcat -m 100 -a 0 -o out/corpo.txt in/sha1.txt /usr/share/wordlists/rockyou.txt
  3. 3

    Policy-shaped mask for the remaining hashes

    hashcat -m 100 -a 3 --markov 1 --session corpo-policy in/sha1.txt '?u?l?l?l?l?d?d?d'
  4. 4

    Report the percentage and time-to-recover, not the plaintexts

    wc -l out/corpo.txt in/sha1.txt

A defensible statement of exposure: what fraction of accounts fell within X hours, and which policy change would raise the cost.

What it is used for

  • Password policy audit

    Quantify how fast an organisation's hashes fall under realistic attacks.

  • Recovery of your own material

    Recover access to a disk or archive you own, with your own wordlist.

  • Hardware benchmarking

    Compare GPU kernels for hashing cost analysis.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"No devices or left active kernels detected"Cause 1/4

Possible causes

  • Missing or mismatched OpenCL/CUDA driver, or the user lacks permission for the device.

Usual fix

Install the vendor driver (not just the runtime), re-check with `hashcat -I`, and on Linux add the user to the `video` group or run with the correct udev access.

hashcat -I
sudo usermod -aG video $USER
"Hash-mode (-m) expected, but not specified" / constant hash-mode mismatchCause 2/4

Possible causes

  • Wrong mode for the digest format, or extra text around the hash (usernames, separators).

Usual fix

Check the digest against `--example_hashes`, and use the `sep`/`-j`/`-k` options or a small awk pass to isolate the hash field. NTLM from a `pwdump` file needs `-m 1000` with the second column only.

awk -F: '{print $2}' /tmp/lab/pwdump > in/ntlm.txt
Run completes with 0 of 0 cracked and 'Exhausted'Cause 3/4

Possible causes

  • The candidate space genuinely did not contain the plaintexts — not a tool failure.

Usual fix

Change strategy: better base list, rules, hybrid or a wider mask. Record the candidate count you actually covered so the negative result is meaningful.

Antivirus removes the binary on WindowsCause 4/4

Possible causes

  • Recovery tools are commonly flagged.

Usual fix

Run the audit in an isolated lab VM, restore the file from the official archive, and never disable protections wholesale on a workstation.

Tips

  • Estimate keyspace and expected runtime before starting; `--keyspace` gives the candidate count and the benchmark gives the rate.
  • Order attacks cheap-first: straight, then rules, then hybrid, then mask. Most of an audit's value arrives in the first two.
  • `--username` when hashes include a user prefix, `--show` to avoid re-running solved ones, `--left` to retry only unsolved.
  • Store the potfile, session restore and outputs under encryption, and delete them when the engagement closes.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Pentesting

Looking for alternatives?

John the Ripper cover adjacent parts of the same job.

Compare side by side