{"id":196236,"date":"2026-02-19T15:46:01","date_gmt":"2026-02-19T14:46:01","guid":{"rendered":"https:\/\/liora.io\/en\/?p=196236"},"modified":"2026-08-24T21:26:46","modified_gmt":"2026-08-24T20:26:46","slug":"all-about-hashcat","status":"publish","type":"post","link":"https:\/\/liora.io\/en\/all-about-hashcat","title":{"rendered":"Hashcat: Description, Operation, and Usage"},"content":{"rendered":"\n<p><strong><strong>Are you wondering how cybersecurity experts test the strength of passwords?<\/strong> To understand this, you need to know what a hash is: a unique, unreadable fingerprint that protects passwords without storing them in plain text. However, when these fingerprints fall into the wrong hands, specialized software can attempt to crack them. This is where <strong>Hashcat<\/strong> comes into play-a powerful, legal, and remarkably effective tool for auditing your security systems.<\/strong><\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"hashcat-the-essentials\">Hashcat: the essentials<\/h2>\n\n\n<ul class=\"wp-block-list\">\n<li>\ud83d\udd13 <strong>Hashcat<\/strong> is the fastest open-source password-recovery tool, used by pentesters and security teams to test how resistant password hashes really are.<\/li>\n<li>\ud83c\udfaf <strong>Attack modes<\/strong>: dictionary (mode 0) combined with rules is the highest-yield combo; brute-force\/mask, hybrid and association cover the rest.<\/li>\n<li>\ud83e\uddee <strong>300+ hash types<\/strong> supported ,  MD5, SHA-1, bcrypt, PBKDF2 and WPA2 (mode 22000).<\/li>\n<li>\u2696\ufe0f <strong>Legal use only<\/strong>: run it exclusively on systems you own or are explicitly authorized to test.<\/li>\n<li>\ud83d\udee0\ufe0f <strong>Alternatives<\/strong>: John the Ripper for offline auditing, THC Hydra for online network services.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-hashcat\">What is Hashcat?<\/h2>\n\n\n<h3 class=\"wp-block-heading\" id=\"understanding-hashes-and-their-role-in-security\">Understanding Hashes and Their Role in Security<\/h3>\n\n\n<p>Before delving into Hashcat, you need to define what a <strong>hash<\/strong> is. When a password is stored on a server, it is rarely kept in plain text. Instead, a hashing function transforms this password into a <strong>unique and irreversible fingerprint<\/strong>, called a <em>hash<\/em>. This secures passwords by replacing them with an unreadable fingerprint while still allowing the system to verify their validity without ever needing to know or display the original password.<\/p>\n\n\n<p>However, if <a href=\"https:\/\/liora.io\/en\/all-about-cybercrime\">an attacker<\/a> obtains these fingerprints, they may try to retrieve the original passwords by testing thousands of combinations using <strong>powerful decryption tools<\/strong>. It is precisely this type of task that <strong>Hashcat<\/strong> facilitates in a legal and controlled context.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"hashcat-an-ethical-hacking-tool-focused-on-pentesting\">Hashcat: An Ethical Hacking Tool Focused on Pentesting<\/h3>\n\n\n<p>Hashcat is a <strong>password recovery<\/strong> tool that is powerful, fast, and widely used in <a href=\"https:\/\/liora.io\/en\/cybersecurity-the-ultimate-guide\">cybersecurity<\/a>. Its goal is not to hack but to <strong>test the robustness of your systems<\/strong> during a pentest performed by an expert or <a href=\"https:\/\/liora.io\/en\/all-about-certified-ethical-hackers\">a Certified Ethical Hacker<\/a>.<\/p>\n\n\n<p>Its use is perfectly <strong>legal<\/strong>, provided you have the <strong>explicit permission<\/strong> of the system owner. Without this consent, its use could be considered an offense or even an attempt at intrusion.<\/p>\n\n\n<figure class=\"wp-block-image size-full\" style=\"margin-top:32px;margin-bottom:32px\"><img alt=\"Flowchart illustrating how hashcat attempts to crack password hashes in a legal pentesting context\" decoding=\"async\" height=\"1024\" loading=\"lazy\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2025\/05\/ChatGPT-Image-8-avr.-2025-17_09_11.png\" style=\"width:100%;height:auto\" width=\"1536\"\/><\/figure>\n\n\n<p><strong>Train in Ethical Hacking<\/strong> Master pentesting tools and techniques with our cybersecurity programmes.<\/p>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex is-content-justification-center wp-container-core-buttons-is-layout-5ee10de4\" style=\"margin-top:32px;margin-bottom:32px\"><div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/liora.io\/en\/courses\">Learn about Pentest<\/a><\/div><\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"why-use-hashcat-common-use-cases\">Why Use Hashcat: Common Use Cases<\/h2>\n\n\n<p>Whether you are a cybersecurity auditor, SOC analyst, <a href=\"https:\/\/liora.io\/en\/pentester-what-is-it\">pentester<\/a>, or simply passionate about computer security, Hashcat is an essential tool for understanding and testing the robustness of passwords. Designed to perform <strong>high-performance brute-force<\/strong> or <strong>dictionary attacks<\/strong>, it allows you to simulate realistic compromise scenarios and assess the security of hashing systems. Used within a legal and ethical framework, Hashcat helps you identify weaknesses in password policies, enhance protection measures, and serves as a powerful ally in any intrusion test or <a href=\"https:\/\/liora.io\/en\/all-about-security-audit\">security audit<\/a> effort.<\/p>\n\n\n<p>It is commonly used for:<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Auditing the strength of passwords<\/strong> within a company,<\/li>\n<li><strong>Conducting pentests<\/strong> (simulated intrusion tests),<\/li>\n<li><strong>Training technical profiles<\/strong> within cybersecurity or ethical hacking curricula.<\/li>\n<\/ul>\n\n\n<p>Hashcat allows you to <strong>simulate realistic attacks<\/strong>, thereby strengthening your security policies.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"how-does-hashcat-work\">How Does Hashcat Work?<\/h2>\n\n\n<h3 class=\"wp-block-heading\" id=\"different-types-of-attacks-brute-force-dictionary-combined\">Different Types of Attacks (Brute-Force, Dictionary, Combined\u2026)<\/h3>\n\n\n<h4 class=\"wp-block-heading\" id=\"attack-modes-overview\">Attack Modes Overview<\/h4>\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table>\n<thead>\n<tr>\n<th>Attack type<\/th>\n<th>Description<\/th>\n<th>Advantages<\/th>\n<th>Disadvantages<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Brute force<\/td>\n<td>Tests all possible combinations until the password is found.<\/td>\n<td>Exhaustive method that guarantees a result if the password is short or simple.<\/td>\n<td>Very slow for long or complex passwords and requires significant computing power.<\/td>\n<\/tr>\n<tr>\n<td>Dictionary<\/td>\n<td>Uses a predefined list of common passwords.<\/td>\n<td>Fast, especially when using well-crafted dictionaries.<\/td>\n<td>Ineffective if the password is original or uncommon.<\/td>\n<\/tr>\n<tr>\n<td>Combined<\/td>\n<td>Combines two or more words from one or several dictionary files.<\/td>\n<td>Produces more complex combinations from simple words.<\/td>\n<td>Slower than a basic attack and requires a high-quality word database.<\/td>\n<\/tr>\n<tr>\n<td>Hybrid<\/td>\n<td>Adds prefixes or suffixes to dictionary words, such as numbers or years.<\/td>\n<td>Mimics human password habits like appending dates or symbols.<\/td>\n<td>Less effective if the password does not follow predictable patterns.<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/figure>\n\n\n<h3 class=\"wp-block-heading\" id=\"what-algorithms-are-supported\">What Algorithms Are Supported?<\/h3>\n\n\n<p>Where Hashcat shines is in its <strong>compatibility with over 300 <\/strong><a href=\"https:\/\/liora.io\/en\/algorithm-what-is-it\">algorithms<\/a>:<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li>Classics like <strong>MD5<\/strong>, <strong>SHA-1<\/strong>, <strong>SHA-256<\/strong>,<\/li>\n<li>More robust ones like <strong>bcrypt<\/strong> or <strong>PBKDF2<\/strong>,<\/li>\n<li>As well as protocols related to Wi-Fi security (<strong>WPA\/WPA2<\/strong>) or cryptocurrencies.<\/li>\n<\/ul>\n\n\n<p>No matter your need, Hashcat offers <strong>rare versatility<\/strong>, essential for auditing any type of environment.<\/p>\n\n\n<figure class=\"wp-block-image size-full\" style=\"margin-top:32px;margin-bottom:32px\"><img alt=\"Comprehensive diagram showing 300+ supported hash algorithms in hashcat including MD5, SHA and bcrypt\" decoding=\"async\" height=\"1024\" loading=\"lazy\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2025\/05\/ChatGPT-Image-8-avr.-2025-17_15_57.png\" style=\"width:100%;height:auto\" width=\"1536\"\/><\/figure>\n\n\n<h2 class=\"wp-block-heading\" id=\"how-to-install-hashcat\">How to Install Hashcat?<\/h2>\n\n\n<h3 class=\"wp-block-heading\" id=\"technical-prerequisites-gpu-system-etc\">Technical Prerequisites (GPU, System, etc.)<\/h3>\n\n\n<p>Before diving into installation, it is crucial to understand what you need to run Hashcat properly. <strong>Hashcat primarily leverages your<\/strong> GPU to expedite the password recovery process. The more powerful your graphics card, the faster and more effective the software will be.<\/p>\n\n\n<p>If you are using an <strong>NVIDIA<\/strong> card, you will need to install the appropriate CUDA drivers. For <strong>AMD<\/strong>, the OpenCL drivers are required. Also, ensure that you have an up-to-date <strong>64-bit system<\/strong> with a functional terminal or command prompt.<\/p>\n\n\n<p>Let&#8217;s proceed with the installation according to your <a href=\"https:\/\/liora.io\/en\/all-about-network-operating-system\">operating system<\/a>.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"install-hashcat-on-windows\">Install Hashcat on Windows<\/h3>\n\n\n<p>On <a href=\"https:\/\/liora.io\/en\/all-about-windows-server\">Windows<\/a>, the installation is quite straightforward. Start by visiting the <strong>official Hashcat website<\/strong> to download the latest stable version. Once the compressed file is downloaded, <strong>extract it into a dedicated folder<\/strong> using WinRAR or 7-Zip. After extracting the files, open the command prompt, navigate to the installation directory using the <strong>cd<\/strong> command, then run <strong>hashcat.exe<\/strong> to verify everything works correctly.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"install-hashcat-on-macos\">Install Hashcat on macOS<\/h3>\n\n\n<p>On <a href=\"https:\/\/liora.io\/en\/all-about-macos\">macOS<\/a>, the installation requires a bit more diligence. Apple limits low-level access to the GPU, so performance might be lower, but the tool remains functional. Start by downloading the macOS version from the official site. Then use Terminal to <strong>extract and navigate into the installation folder<\/strong>. If you receive an error message about permissions, allow execution via <strong>System Preferences &gt; Security &amp; Privacy<\/strong>. Finally, <strong>.\/hashcat<\/strong> from the terminal to launch the software.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"install-hashcat-on-linux\">Install Hashcat on Linux<\/h3>\n\n\n<p>On <a href=\"https:\/\/liora.io\/en\/linux-the-preferred-os-for-developers\">Linux<\/a>, Hashcat installs easily if you follow the correct steps. After downloading the archive from the official site, use the command <strong>tar -xvf<\/strong> to extract the content. Once the drivers are in place, navigate to the installation folder, then simply run <strong>.\/hashcat<\/strong> to launch the tool. You&#8217;re prepared to tackle the rest.<\/p>\n\n\n<figure class=\"wp-block-image size-full\" style=\"margin-top:32px;margin-bottom:32px\"><img alt=\"Linux terminal showing tar extraction and hashcat launch command for installation on Linux systems\" decoding=\"async\" height=\"1024\" loading=\"lazy\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2025\/05\/ChatGPT-Image-8-avr.-2025-17_20_50.png\" style=\"width:100%;height:auto\" width=\"1536\"\/><\/figure>\n\n\n<p><strong>Get Started with Pentesting<\/strong> Learn to use ethical hacking tools in real-world scenarios with Liora&#8217;s cybersecurity courses.<\/p>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex is-content-justification-center wp-container-core-buttons-is-layout-5ee10de4\" style=\"margin-top:32px;margin-bottom:32px\"><div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/liora.io\/en\/courses\">Get started with Pentest<\/a><\/div><\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"how-to-use-hashcat-effectively\">How to Use Hashcat Effectively?<\/h2>\n\n\n<p>Let&#8217;s move to the crucial step: <strong>usage<\/strong>. Hashcat is powerful, but you need to know how to use it. Don&#8217;t worry; once the basics are mastered, everything becomes smooth.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"basic-commands-to-know\">Basic Commands to Know<\/h3>\n\n\n<h4 class=\"wp-block-heading\" id=\"essential-hashcat-commands\">Essential Hashcat Commands<\/h4>\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table>\n<thead>\n<tr>\n<th>Command<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>hashcat -h<\/code><\/td>\n<td>Displays the built-in help and the full list of available options.<\/td>\n<\/tr>\n<tr>\n<td><code>hashcat -a 0 -m 0 hash.txt rockyou.txt<\/code><\/td>\n<td>Performs a dictionary attack (mode 0) on MD5 hashes (type 0) using the <code>rockyou.txt<\/code> wordlist.<\/td>\n<\/tr>\n<tr>\n<td><code>hashcat -a 3 -m 0 hash.txt ?a?a?a?a?a?a<\/code><\/td>\n<td>Executes a brute-force attack (mode 3) on MD5 hashes, testing all possible six-character combinations.<\/td>\n<\/tr>\n<tr>\n<td><code>hashcat -a 6 -m 0 hash.txt rockyou.txt ?d?d?d<\/code><\/td>\n<td>Performs a hybrid attack (mode 6) by appending three digits to each dictionary word, simulating passwords like <code>admin123<\/code>.<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/figure>\n\n\n<p>Every option has its logic. The <strong>-a<\/strong> defines the <strong>attack mode<\/strong> (0 for dictionary, 3 for brute force, 6 for hybrid), the <strong>-m<\/strong> specifies the <strong>hash type<\/strong> (MD5, SHA1, bcrypt\u2026), and the rest configure the files to use.<\/p>\n\n\n<h4 class=\"wp-block-heading\" id=\"concrete-examples-of-usage\">Concrete Examples of Usage<\/h4>\n\n\n<p>Let&#8217;s consider a typical case. You retrieve a file containing <strong>MD5 hashes<\/strong> extracted from a <a href=\"https:\/\/liora.io\/en\/database-what-is-it\">database<\/a> during an audit. You want to check if weak passwords have been used.<\/p>\n\n\n<p>You run the following command:<\/p>\n\n\n<p><strong>Dictionary attack on MD5 hashes<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code>hashcat -a 0 -m 0 hash.txt rockyou.txt<\/code><\/pre>\n\n\n<p>Hashcat will then compare each hash with the words in the <strong>rockyou.txt<\/strong> file. If a match is found, you will obtain the password in clear text. This is a simple way to demonstrate that a <strong>lenient password policy<\/strong> can jeopardize an entire system.<\/p>\n\n\n<p>Another example: you suspect that users add their birth year to their passwords. You can test:<\/p>\n\n\n<p><strong>Hybrid attack ,  dictionary + year suffix<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code>hashcat -a 6 -m 0 hash.txt rockyou.txt ?d?d?d?d<\/code><\/pre>\n\n\n<p>This hybrid attack is particularly effective in professional environments where practices are predictable.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"optimizing-performance-with-gpu\">Optimizing Performance with GPU<\/h3>\n\n\n<p>To gain speed, GPU optimization is essential. First step: ensure that <strong>your graphics card is properly recognized<\/strong> by Hashcat. To check, use the command <strong>hashcat -I<\/strong> (uppercase), which displays the available devices.<\/p>\n\n\n<p>You can also adjust the workload using the <strong>-w<\/strong> option. For example, the command:<\/p>\n\n\n<p><strong>High-intensity GPU attack<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><code>hashcat -w 3 -a 0 -m 0 hash.txt rockyou.txt<\/code><\/pre>\n\n\n<p>instructs Hashcat to operate at a <strong>high intensity<\/strong>, ideal for use on a dedicated attack machine. The higher the value of -w (from 1 to 4), the more the performance is pushed, but this can also impact the stability of your machine if it&#8217;s multitasking.<\/p>\n\n\n<p>Lastly, monitor the <strong>temperature of your graphics card<\/strong>. Overheating could slow down or even interrupt your session. Use tools like <code>nvidia-smi<\/code> or <code>watch sensors<\/code> to keep an eye on the hardware.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"what-are-the-alternatives-to-hashcat\">What Are the Alternatives to Hashcat?<\/h2>\n\n\n<p>While <strong>Hashcat<\/strong> is a benchmark in password cracking, it is not the only tool available. Other efficient solutions warrant your attention, especially in specific scenarios or under technical constraints. Among these, <strong>John the Ripper<\/strong> and THC Hydra are significant contenders.<\/p>\n\n\n<h4 class=\"wp-block-heading\" id=\"hashcat-vs-alternatives\">Hashcat vs Alternatives<\/h4>\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table>\n<thead>\n<tr>\n<th>Criteria<\/th>\n<th>Hashcat<\/th>\n<th>John the Ripper<\/th>\n<th>THC Hydra<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Attack type<\/td>\n<td>Mainly offline<\/td>\n<td>Offline<\/td>\n<td>Online<\/td>\n<\/tr>\n<tr>\n<td>GPU support<\/td>\n<td>Extensive<\/td>\n<td>Limited<\/td>\n<td>Not applicable<\/td>\n<\/tr>\n<tr>\n<td>Hash formats<\/td>\n<td>Wide range<\/td>\n<td>Wide range<\/td>\n<td>Various network protocols<\/td>\n<\/tr>\n<tr>\n<td>Ease of use<\/td>\n<td>Command-line interface, requires a learning curve<\/td>\n<td>Command-line interface, requires a learning curve<\/td>\n<td>Command-line interface, requires understanding of network protocols<\/td>\n<\/tr>\n<tr>\n<td>Use cases<\/td>\n<td>Cracking recovered hashes<\/td>\n<td>Password auditing on various systems<\/td>\n<td>Penetration testing on active network services<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/figure>\n\n\n<figure class=\"wp-block-image size-full\" style=\"margin-top:32px;margin-bottom:32px\"><img alt=\"Comparison of Hashcat alternatives including John the Ripper and THC Hydra password cracking tools\" decoding=\"async\" height=\"1024\" loading=\"lazy\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2025\/05\/ChatGPT-Image-8-avr.-2025-17_37_56.png\" style=\"width:100%;height:auto\" width=\"1536\"\/><\/figure>\n\n\n<p><strong>Become a Cybersecurity Expert<\/strong> Master the tools and techniques of ethical hacking with Liora&#8217;s dedicated training programmes.<\/p>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex is-content-justification-center wp-container-core-buttons-is-layout-5ee10de4\" style=\"margin-top:32px;margin-bottom:32px\"><div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/liora.io\/en\/courses\">Become a cybersecurity expert<\/a><\/div><\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"conclusion\">Conclusion<\/h2>\n\n\n<p>Whether you wish to analyze a local hash file, audit passwords on different systems, or engage in penetration testing in a real environment, ensure you use these tools within a legal, ethical, and professional context, with the explicit permission of the target organization. The aim is never to harm but to protect by identifying vulnerabilities before a malicious third party does.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"frequently-asked-questions\">Frequently Asked Questions<\/h2>\n\n\n<h3 class=\"wp-block-heading\" id=\"what-is-the-most-effective-hashcat-attack-mode-for-real-world-passwords\">What is the most effective hashcat attack mode for real-world passwords?<\/h3>\n\n\n<p>Mode 0 (dictionary) combined with rules (<code>-r best64.rule<\/code>) is the highest-yield combination. It covers the vast majority of passwords humans choose. Only escalate to brute-force or hybrid modes after dictionary + rules is exhausted.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"what-s-the-difference-between-hashcat-attack-modes-6-and-7\">What&#8217;s the difference between hashcat attack modes 6 and 7?<\/h3>\n\n\n<p>Mode 6 appends a mask to each wordlist word (<code>word + ?d?d?d?d<\/code>). Mode 7 prepends a mask (<code>?d?d?d?d + word<\/code>). Use mode 6 for passwords like <code>admin2024<\/code>, mode 7 for passwords like <code>2024admin<\/code>.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"how-do-i-crack-a-wpa2-wi-fi-password-with-hashcat\">How do I crack a WPA2 Wi-Fi password with hashcat?<\/h3>\n\n\n<p>Capture the handshake or PMKID to a <code>.pcapng<\/code> file, convert it with <code>hcxpcapngtool -o hash.hc22000 capture.pcapng<\/code>, then run <code>hashcat -m 22000 -a 0 hash.hc22000 rockyou.txt<\/code>. Only do this on networks you own or have explicit written permission to test.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"why-is-hashcat-so-slow-on-bcrypt\">Why is hashcat so slow on bcrypt?<\/h3>\n\n\n<p>bcrypt is deliberately slow by design. The cost factor controls how many iterations are performed. At cost 10, an RTX 4090 manages ~3,000 bcrypt hashes per second versus ~68 billion MD5 hashes per second ,  a 22-million-times speed difference.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"what-does-token-length-exception-mean-in-hashcat\">What does &#8220;token length exception&#8221; mean in hashcat?<\/h3>\n\n\n<p>It means the hash in your input file doesn&#8217;t match the expected format for the <code>-m<\/code> mode specified. Fix: identify the correct hash type with <code>hashid<\/code> or <code>hashcat --identify<\/code>, then use the matching <code>-m<\/code> value.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"is-using-force-safe-in-hashcat\">Is using &#45;&#45;force safe in hashcat?<\/h3>\n\n\n<p>No. <code>--force<\/code> bypasses safety warnings and can produce incorrect results or hide real problems. Fix the underlying driver or configuration issue instead of relying on this flag.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"how-do-i-resume-a-hashcat-session-that-was-interrupted\">How do I resume a hashcat session that was interrupted?<\/h3>\n\n\n<p>If you started the session with <code>--session mysession<\/code>, resume it with <code>hashcat --restore --session mysession<\/code>. Always name long-running sessions to make recovery easy.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"useful-sources\">Useful Sources<\/h3>\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/hashcat.net\/wiki\/\" rel=\"noopener\" target=\"_blank\">Hashcat official wiki<\/a> ,  attack modes, example hashes, rule syntax<\/li>\n<li><a href=\"https:\/\/hashcat.net\/wiki\/doku.php?id=example_hashes\" rel=\"noopener\" target=\"_blank\">Hashcat example hashes<\/a><code>-m<\/code> values for every supported hash type<\/li>\n<li><a href=\"https:\/\/hashcat.net\/wiki\/doku.php?id=cracking_wpawpa2\" rel=\"noopener\" target=\"_blank\">Hashcat WPA\/WPA2 cracking guide<\/a> ,  official workflow for mode 22000<\/li>\n<li><a href=\"https:\/\/github.com\/ZerBea\/hcxtools\" rel=\"noopener\" target=\"_blank\">hcxtools on GitHub<\/a><code>hcxpcapngtool<\/code> for converting Wi-Fi captures<\/li>\n<li><a href=\"https:\/\/github.com\/danielmiessler\/SecLists\" rel=\"noopener\" target=\"_blank\">SecLists on GitHub<\/a> ,  curated wordlists for security testing<\/li>\n<li><a href=\"https:\/\/crackstation.net\/crackstation-wordlist-password-cracking-dictionary.htm\" rel=\"noopener\" target=\"_blank\">CrackStation wordlist<\/a> ,  1.5 billion password list<\/li>\n<li><a href=\"https:\/\/github.com\/NotSoSecure\/password_cracking_rules\" rel=\"noopener\" target=\"_blank\">OneRuleToRuleThemAll<\/a> ,  community rule file<\/li>\n<li><a href=\"https:\/\/www.blackhillsinfosec.com\/hashcat-cheatsheet\/\" rel=\"noopener\" target=\"_blank\">Black Hills InfoSec hashcat cheat sheet<\/a> ,  quick reference card<\/li>\n<\/ul>\n\n","protected":false},"excerpt":{"rendered":"<p>Are you wondering how cybersecurity experts test the strength of passwords? To understand this, you need to know what a hash is: a unique, unreadable fingerprint that protects passwords without storing them in plain text. However, when these fingerprints fall into the wrong hands, specialized software can attempt to crack them. This is where Hashcat [&hellip;]<\/p>\n","protected":false},"author":74,"featured_media":207593,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[2426],"class_list":["post-196236","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"acf":[],"_links":{"self":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/196236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/users\/74"}],"replies":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/comments?post=196236"}],"version-history":[{"count":5,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/196236\/revisions"}],"predecessor-version":[{"id":211444,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/196236\/revisions\/211444"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media\/207593"}],"wp:attachment":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media?parent=196236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/categories?post=196236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}