agentsclimarketplace

Hashcat

Skill jph4cks/redhound-arsenal/hashcat

76 AI-agent security skills for Kali Linux tools — pentest, red team, forensics, OSINT, and more. Machine-readable skill definitions by Red Hound InfoSec.

Install
npx -y skills add jph4cks/redhound-arsenal --skill hashcat

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 6 stars6 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Operate hashcat — the world's fastest CPU/GPU-based password recovery tool. Use when cracking password hashes obtained during a pentest, CTF, or red team engagement, when the user asks about offline password cracking, hash identification, rule-based attacks, mask attacks, combinator attacks, or integrating hashcat with secretsdump/mimikatz output. Covers installation with GPU drivers, all attack modes (-a 0/1/3/6/7), hash types (-m), rule engines, mask charsets, potfile management, session control, brain server, distributed cracking, and end-to-end AD credential cracking workflows.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

14.4 KB, ~4.4k tokens by cl100k_base, as published. Nobody here has run it

hashcat Agent Skill

When to Use This Skill

Use this skill when:

  • Cracking hashes captured from an AD environment (NTLM, NetNTLMv2, Kerberoast, AS-REP)
  • The user asks about offline password recovery or wordlist/rule/mask attacks
  • Integrating hashcat with impacket secretsdump, Responder, or mimikatz lsadump output
  • Benchmarking GPU hash speeds or optimizing cracking performance
  • Building custom rule sets or mask policies for targeted campaigns

What hashcat Does

hashcat is an advanced CPU and GPU accelerated password recovery utility supporting over 300 hash types. It is the de-facto standard offline cracker used in penetration testing to recover plaintext credentials from captured hashes, enabling pass-the-hash, lateral movement, and further AD compromise. It supports six attack modes ranging from pure dictionary to hybrid mask attacks and includes a powerful rule engine for wordlist mutation.

Installation

Pre-built binary (recommended)

# Download latest release
wget https://hashcat.net/files/hashcat-6.2.6.tar.gz
tar xf hashcat-6.2.6.tar.gz
cd hashcat-6.2.6/
./hashcat --version

# Or install via package manager (Kali/Parrot)
sudo apt install hashcat

GPU drivers (critical for performance)

# NVIDIA — install CUDA toolkit
sudo apt install nvidia-driver nvidia-cuda-toolkit
# Verify GPU is detected
./hashcat -I

# AMD — install ROCm or AMDGPU-PRO with OpenCL
sudo apt install rocm-opencl-runtime
# Or use the AMDGPU-PRO driver with opencl component

# CPU-only fallback (10-100x slower, no driver required)
./hashcat --force   # suppress GPU errors, runs on CPU

Docker (CPU-only)

docker run --rm -it dizcza/docker-hashcat hashcat --version
# GPU passthrough (NVIDIA)
docker run --rm --gpus all -v $(pwd):/data dizcza/docker-hashcat hashcat \
  -m 1000 /data/hashes.txt /data/rockyou.txt

Core Concepts

Attack Modes (-a)

ModeNameDescription
-a 0DictionaryWordlist ± rules
-a 1CombinatorConcat two wordlists
-a 3Brute-force/MaskPositional charsets
-a 6Hybrid wordlist+maskWord then mask suffix
-a 7Hybrid mask+wordlistMask prefix then word

Hash Types (-m) — Common Pentest Values

-mHash TypeExample context
0MD5Web app databases
100SHA-1Legacy apps
1000NTLMWindows SAM / NTDS
1400SHA-256Linux shadow ($5$)
1800sha512cryptLinux shadow ($6$)
3200bcryptModern web apps
5500NetNTLMv1Responder capture
5600NetNTLMv2Responder capture
13100Kerberoast (TGS-REP)SPN ticket cracking
18200AS-REP RoastingNo-preauth accounts
19600Kerberos 5 TGT (etype 17)AES-128 TGT
19700Kerberos 5 TGT (etype 18)AES-256 TGT
22000WPA-PBKDF2-PMKIDWi-Fi
2500WPA/WPA2 (old format).hccapx

Mask Charsets

TokenCharset
?labcdefghijklmnopqrstuvwxyz
?uABCDEFGHIJKLMNOPQRSTUVWXYZ
?d0123456789
?sSpecial characters (32 symbols)
?a?l + ?u + ?d + ?s (all printable)
?h0-9a-f (hex lowercase)
?H0-9A-F (hex uppercase)

CLI Reference

Dictionary Attack (-a 0)

# Basic dictionary attack
hashcat -m 1000 hashes.txt /usr/share/wordlists/rockyou.txt

# With rule file
hashcat -m 1000 hashes.txt rockyou.txt -r /usr/share/hashcat/rules/best64.rule

# Multiple rule files (stacked)
hashcat -m 1000 hashes.txt rockyou.txt \
  -r rules/best64.rule -r rules/toggles1.rule

# With OneRuleToRuleThemAll
hashcat -m 1000 hashes.txt rockyou.txt \
  -r /opt/OneRuleToRuleThemAll/OneRuleToRuleThemAll.rule

# dive.rule (2.3M rules — slow, thorough)
hashcat -m 1000 hashes.txt rockyou.txt -r rules/dive.rule

Mask Attack (-a 3)

# 8-char all lowercase
hashcat -m 1000 hashes.txt -a 3 ?l?l?l?l?l?l?l?l

# 8-char mixed: upper, lower, digit, special
hashcat -m 1000 hashes.txt -a 3 ?u?l?l?l?l?d?d?s

# Variable length with --increment
hashcat -m 1000 hashes.txt -a 3 --increment --increment-min 6 \
  --increment-max 10 ?a?a?a?a?a?a?a?a?a?a

# Corporate password pattern: Word + 4 digits
hashcat -m 1000 hashes.txt -a 3 -1 ?u?l ?1?l?l?l?l?l?d?d?d?d

# Custom charset with -1 through -4
hashcat -m 1000 hashes.txt -a 3 -1 "?u?l" -2 "?d!" ?1?1?1?1?2?2

Combinator Attack (-a 1)

# Combine two wordlists: word1 + word2 concatenated
hashcat -m 1000 hashes.txt -a 1 words1.txt words2.txt

# With rules on left/right wordlist
hashcat -m 1000 hashes.txt -a 1 words1.txt words2.txt \
  -j 'c' -k '$1'   # capitalize left, append '1' to right

Hybrid Attacks (-a 6 / -a 7)

# Wordlist + mask suffix (Password123!)
hashcat -m 1000 hashes.txt -a 6 rockyou.txt ?d?d?d?s

# Mask prefix + wordlist (123!Password)
hashcat -m 1000 hashes.txt -a 7 ?d?d?d?s rockyou.txt

Performance Flags

# Optimized kernels (limits password length to 31 chars)
hashcat -m 1000 hashes.txt rockyou.txt -O

# Workload profile (1=minimal, 2=default, 3=high, 4=nightmare)
hashcat -m 1000 hashes.txt rockyou.txt -w 3

# Specify device (GPU 1 only)
hashcat -m 1000 hashes.txt rockyou.txt -d 1

# Limit GPU utilization
hashcat -m 1000 hashes.txt rockyou.txt --gpu-temp-abort 90

# Status update interval
hashcat -m 1000 hashes.txt rockyou.txt --status --status-timer 10

Session Management

# Named session
hashcat -m 1000 hashes.txt rockyou.txt --session mysession

# Restore interrupted session
hashcat --session mysession --restore

# List restore files
ls ~/.local/share/hashcat/sessions/
# or on Windows: %AppData%\hashcat\sessions\

Potfile Management

# Default potfile location: ~/.local/share/hashcat/hashcat.potfile
# Show cracked hashes from potfile
hashcat -m 1000 hashes.txt --show

# Output cracked results to file
hashcat -m 1000 hashes.txt rockyou.txt -o cracked.txt

# Output format: hash:plain (default 3), or just plain (2)
hashcat -m 1000 hashes.txt rockyou.txt -o cracked.txt --outfile-format 2

# Disable potfile (re-crack everything)
hashcat -m 1000 hashes.txt rockyou.txt --potfile-disable

# Use custom potfile
hashcat -m 1000 hashes.txt rockyou.txt --potfile-path ./engagement.potfile

Benchmark Mode

# Benchmark all hash types
hashcat -b

# Benchmark specific hash type
hashcat -b -m 1000
hashcat -b -m 3200   # bcrypt is always slow (~100 H/s even on GPU)

Rule-Based Attacks

Hashcat rules are single-character transformations applied to each word in a wordlist.

Built-in Rule Files (Kali: /usr/share/hashcat/rules/)

FileRulesUse Case
best64.rule64Fast, high-value mutations
rockyou-30000.rule30kBroad coverage
dive.rule99k+Exhaustive, slow
toggles1-5.rulevariesCase toggling
leetspeak.rule~20e→3, a→@, etc.
unix-ninja-leetspeak.rule~60Extended leet

OneRuleToRuleThemAll

git clone https://github.com/NotSoSecure/password_cracking_rules /opt/OneRuleToRuleThemAll
hashcat -m 1000 hashes.txt rockyou.txt \
  -r /opt/OneRuleToRuleThemAll/OneRuleToRuleThemAll.rule

Custom Rule Syntax

:       No-op (identity)
l       Lowercase all
u       Uppercase all
c       Capitalize first
C       Lowercase first, uppercase rest
t       Toggle all
T N     Toggle char at position N
r       Reverse
d       Duplicate
p N     Append word N times
$X      Append character X
^X      Prepend character X
[ ]     Delete first / last char
{ }     Rotate left / right
D N     Delete char at position N
i N X   Insert char X at position N
o N X   Overwrite char at position N with X

Generate rules with hashcat --generate-rules

hashcat --generate-rules 1000 --generate-rules-seed 12345 > custom.rule
hashcat -m 1000 hashes.txt rockyou.txt -r custom.rule

Common Workflows

AD Credential Cracking Pipeline (secretsdump → hashcat)

# 1. Dump NTDS with secretsdump
impacket-secretsdump -just-dc-ntlm DOMAIN/[email protected] \
  -outputfile ntds_dump

# 2. Extract NTLM hashes (user:rid:lmhash:nthash format)
cut -d: -f4 ntds_dump.ntds > ntlm_hashes.txt

# 3. Phase 1 — fast dictionary
hashcat -m 1000 ntlm_hashes.txt rockyou.txt -O -w 3

# 4. Phase 2 — dictionary + best rules
hashcat -m 1000 ntlm_hashes.txt rockyou.txt \
  -r rules/best64.rule -r rules/d3ad0ne.rule -O -w 3

# 5. Phase 3 — targeted corporate mask (Word + year + !)
hashcat -m 1000 ntlm_hashes.txt -a 6 \
  /usr/share/wordlists/rockyou.txt ?d?d?d?d?s -O

# 6. Show results
hashcat -m 1000 ntlm_hashes.txt --show | tee cracked_ntlm.txt

Kerberoasting Crack

# Hashes from GetUserSPNs.py (Impacket) or Rubeus
impacket-GetUserSPNs -request DOMAIN/user:pass@dc01 \
  -outputfile kerberoast_hashes.txt

# Crack TGS-REP (etype 23 = RC4-HMAC)
hashcat -m 13100 kerberoast_hashes.txt rockyou.txt \
  -r rules/best64.rule -O -w 3

# AES-256 TGS (etype 18) — much slower
hashcat -m 19700 kerberoast_hashes.txt rockyou.txt -O

AS-REP Roasting Crack

# Hashes from GetNPUsers.py
hashcat -m 18200 asrep_hashes.txt rockyou.txt \
  -r rules/best64.rule -O -w 3

NetNTLMv2 (Responder Capture)

# Responder captures: /usr/share/responder/logs/*.txt
hashcat -m 5600 responder_hashes.txt rockyou.txt \
  -r rules/best64.rule -O -w 3

bcrypt Cracking (slow but necessary)

# bcrypt is rate-limited — use targeted wordlists
hashcat -m 3200 bcrypt_hashes.txt targeted_wordlist.txt \
  -r rules/best64.rule -w 3
# ~100-500 H/s even on high-end GPU

Advanced Techniques

Brain Server (deduplication across distributed clients)

# Start brain server
hashcat --brain-server --brain-password secret123

# Client connects to brain (avoids re-cracking same candidates)
hashcat -m 1000 hashes.txt rockyou.txt \
  --brain-client --brain-server 192.168.1.10 \
  --brain-client-features 3 --brain-password secret123

Distributed Cracking (keyspace splitting)

# Split mask keyspace across 4 nodes using --keyspace
hashcat -m 1000 hashes.txt -a 3 ?a?a?a?a?a?a?a?a \
  --keyspace    # prints total keyspace (e.g., 96^8 = 7.2T)

# Node 1: first quarter
hashcat -m 1000 hashes.txt -a 3 ?a?a?a?a?a?a?a?a \
  --skip 0 --limit 1800000000000

# Node 2: second quarter
hashcat -m 1000 hashes.txt -a 3 ?a?a?a?a?a?a?a?a \
  --skip 1800000000000 --limit 1800000000000

Prince Attack (with princeprocessor)

# princeprocessor generates PRINCE algorithm candidates
git clone https://github.com/hashcat/princeprocessor
cd princeprocessor/src && make
./pp64.bin --pw-min 6 --pw-max 10 < wordlist.txt | \
  hashcat -m 1000 hashes.txt --stdin

Loopback Attack (crack → feed cracked back as wordlist)

# hashcat 6.x supports loopback natively
hashcat -m 1000 hashes.txt rockyou.txt \
  -r rules/best64.rule --loopback
# Cracked plaintexts fed back through rules until exhausted

Create Targeted Wordlist from OSINT

# CeWL — crawl target website for wordlist
cewl https://target.corp.com -d 2 -m 6 -w target_words.txt

# Combine with rules
hashcat -m 1000 hashes.txt target_words.txt \
  -r rules/best64.rule -r rules/leetspeak.rule

Integration with Other Tools

secretsdump (Impacket)

# Remote NTDS dump (DCSync equivalent)
impacket-secretsdump DOMAIN/[email protected] -just-dc-ntlm \
  -outputfile dump
# Output: dump.ntds — format user:rid:lmhash:nthash

# Local SYSTEM+NTDS extraction
impacket-secretsdump -system SYSTEM -ntds ntds.dit LOCAL

mimikatz NTLM output

# mimikatz sekurlsa::logonpasswords outputs:
#   NTLM : aad3b435b51404eeaad3b435b51404ee  (LM blank)
# Extract NTLM values to file, then:
hashcat -m 1000 ntlm_from_mimi.txt rockyou.txt -O

Responder integration

# Responder logs: /usr/share/responder/logs/
cat /usr/share/responder/logs/*NTLMv2*.txt > all_netntlmv2.txt
hashcat -m 5600 all_netntlmv2.txt rockyou.txt \
  -r rules/best64.rule -O -w 3

Identify hash type with hashid / haiti

pip install hashid
hashid '$6$rounds=656000$Gu6bJBZMKOwf1T8c$...'  # SHA-512 crypt
hashid 'aad3b435b51404eeaad3b435b51404ee'          # LM Hash

# haiti (more accurate)
gem install haiti-hash
haiti '5f4dcc3b5aa765d61d8327deb882cf99'  # → MD5

Troubleshooting

No OpenCL devices found / clGetPlatformIDs() failed

# Install OpenCL runtime
sudo apt install ocl-icd-opencl-dev opencl-headers
# For NVIDIA, ensure nvidia-opencl-dev is installed
hashcat -I   # list devices; add --force only as last resort

Token length exception

# Hash format wrong — check delimiter and format
# NetNTLMv2 must have full challenge field:
# user::domain:challenge:HMAC:blob
hashcat -m 5600 hash.txt wordlist.txt --hex-salt

Cracked but --show shows nothing

# Potfile may be disabled or wrong path
hashcat -m 1000 hashes.txt --show --potfile-path ./engagement.potfile

Speed drops during attack

# GPU thermal throttling — monitor temps
nvidia-smi -l 1
# Reduce workload: -w 2 instead of -w 3/4
# Set --gpu-temp-abort 85

Status: Exhausted with 0 cracked

# Wordlist may be wrong encoding — convert to UTF-8
iconv -f latin1 -t utf8 wordlist.txt -o wordlist_utf8.txt
# Or the hash type may be wrong — re-identify with hashid

Built by Red Hound InfoSec — On-demand offensive security expertise for SMBs. 20+ years of Fortune 500 experience. Penetration testing, attack surface analysis, and security consulting.

Related reading: 5 Active Directory Misconfigurations We See in Every Engagement

redhound.us | GitHub | Book a consultation

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 327,069. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.