Tools Hub/
Crypto & Password Analysis
2 SPECIALIST TOOLS
INTERMEDIATE TIER
GPU ACCELERATION & JUMBO
T1110.002Password CrackingHashcat GPU Hash CrackerIntermediate

1. Mental Model & Architectural Core

CORE OPERATIONAL PURPOSE

Hashcat is the world's fastest password recovery tool, using GPU acceleration to crack hash types from NTLM and MD5 to bcrypt and Kerberos TGS. It supports dictionary attacks, rule-based mutations, brute-force mask attacks, and hybrid combinations processing billions of candidate passwords per second.

MENTAL MODEL ANALOGY

A password hash is a fingerprint. If you have someone's fingerprint, you can't reverse it back to the finger directly but you can take millions of fingers (candidate passwords), fingerprint each one in real time, and compare until you find a match. Hashcat does this with GPU parallelization at 1+ billion attempts per second.

When to Deploy
  • Crack NTLM hashes from Windows SAM dumps, NTDS.dit, or Responder captures
  • Crack Kerberoast TGS hashes (etype 23, mode 13100)
  • Crack AS-REP Roast hashes (mode 18200)
  • Crack NetNTLMv2 challenge-response hashes captured via Responder
  • Verify password policy effectiveness by testing crack rates
Real-World Scenarios
  • secretsdump output → crack NTLM hashes against rockyou.txt + OneRuleToRuleThemAll rule
  • Kerberoast TGS tickets → target RC4 (etype 23) tickets with rockyou + corporate rule sets
  • NetNTLMv2 from Responder → crack with wordlist in minutes on modern GPU
HOW IT WORKS PROTOCOL & MEMORY INTERNALS

Hashcat leverages OpenCL/CUDA to parallelize hash computation across GPU shader units. A single RTX 4090 can compute 300 billion MD5 hashes or 50 billion NTLM hashes per second. Rule-based attacks apply transformation rules (append numbers, capitalize first letter, l33t substitution) to each wordlist entry before hashing, exponentially expanding the candidate space from a smaller wordlist.

2. Syntax, Flags & Live Telemetry

Flags & Options Reference
13 OPTIONS
Flag / OptionDescription
-m 1000Hash mode 1000 = NTLM (Windows password hash)
-m 13100Hash mode 13100 = Kerberos 5 TGS-REP etype 23 (Kerberoast)
-m 18200Hash mode 18200 = Kerberos 5 AS-REP etype 23 (AS-REP Roast)
-m 5600Hash mode 5600 = NetNTLMv2 (Responder captures)
-m 3200Hash mode 3200 = bcrypt (slow, requires patience)
-a 0Attack mode 0 = Dictionary attack (wordlist + optional rules)
-a 3Attack mode 3 = Brute-force mask attack
-r /usr/share/hashcat/rules/OneRuleToRuleThemAll.ruleApply OneRule mutation rules to every wordlist entry
--forceForce execution even with driver warnings
--statusShow live cracking progress and speed during attack
--showShow already-cracked hashes from potfile
-o cracked.txtSave cracked passwords to output file
--potfile-disableDisable potfile (re-crack known hashes)
Crack NTLM hashes from secretsdump
COMMAND
hashcat -m 1000 -a 0 ntlm_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/OneRuleToRuleThemAll.rule --force
Crack NTLM hashes from secretsdump
LIVE EXEC
[*] Hash type: NTLM (mode 1000)
[*] Speed: 52.3 GH/s (RTX 4090)
[*] Progress: 89.5% through rockyou.txt + OneRule mutations
[!] 31d6cfe0d16ae931b73c59d7e0c089c0:Password1!
[!] a0b8d61a4fd0e72e4b5e8c5c5dd3d72a:Spring2026!
[✓] 47/156 hashes cracked (30%). Session complete.
Crack Kerberoast TGS hashes
COMMAND
hashcat -m 13100 -a 0 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r best64.rule --force
Crack Kerberoast TGS hashes
LIVE EXEC
[*] Hash type: Kerberos 5 TGS-REP etype 23 (mode 13100)
[*] Speed: 892.4 MH/s
[!] $krb5tgs$23$*svc_mssql...:P@ssword2024!
[✓] 1 of 2 TGS hashes cracked. Service account password: P@ssword2024!
FORENSIC ANALYSIS & OPERATOR INSIGHT

Always use OneRuleToRuleThemAll.rule for corporate password cracking it is statistically the single most effective ruleset. Then try KoreLogicRulesAppendNumSpecial, then nsa-rules. 80% of corporate passwords crack within 3 rulesets against rockyou.txt.

3. Hands-On Practice Labs & Cyber Ranges

Practice environments are curated from PortSwigger, OffSec, HackTheBox, and TryHackMe. Complete these labs to earn credentials and build verified hands-on skills.

4. Detection & Prevention Playbook

MITRE ATT&CK TACTICS
TA0006 Credential Access
HOW TO DETECT LOG SOURCES & TELEMETRY
Process execution logs (detecting offline cracking tools)Account lockout eventsCredential dumping detection upstream
HOW TO PREVENT & MITIGATE
  • Enforce minimum 15-character passwords with complexity requirements
  • Block common passwords using Microsoft Entra Password Protection (banned password list)
  • Use Argon2id or bcrypt for application passwords instead of MD5/SHA1
  • Detect hash dumping events before hashes reach the cracker