Password Cracking & Hash Identification
Offline password recovery: Hashcat modes cheat sheet, John the Ripper formats, and dictionary mutation rules.
hashcatjohnhash-identifier
High-performance GPU cracking with Hashcat recovers plaintext credentials from dumped password hashes.
1. Hashcat Essential Modes Reference
| Mode (-m) | Hash Format | Typical Source |
|---|---|---|
| 1000 | NTLM | Windows SAM / NTDS.dit |
| 1800 | SHA512crypt ($6$) | Linux /etc/shadow |
| 13100 | Kerberos 5 TGS | Active Directory Kerberoasting |
| 18200 | Kerberos 5 AS-REP | Active Directory AS-REP Roasting |
| 3200 | bcrypt ($2y$, $2a$) | Modern Web Databases |
| 16500 | JWT (JSON Web Token) | Web API Tokens |
2. Command Examples
- Crack NTLM:
hashcat -m 1000 ntlm.hashes /usr/share/wordlists/rockyou.txt -O
- Crack Kerberoast:
hashcat -m 13100 kerberoast.hashes /usr/share/wordlists/rockyou.txt -O
Use cracked administrative credentials for lateral movement in 06. Active Directory Attack Paths & Domain Enumeration.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 02. Web Content Discovery & Directory Fuzzing
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 06. Active Directory Attack Paths & Domain Enumeration
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 08. Active Directory Certificate Services (AD CS) Abuse
- 09. Pivoting, Tunnels & Lateral Movement
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox