NOTES
Hashcat is a password-recovery engine, not a substitute for understanding the captured material. Before running it, I identify the protocol or file format, confirm the hash mode against an official example, and document why recovery is authorized.
A successful recovery demonstrates password weakness in context. A failed wordlist run does not prove that a password is strong.
WORKFLOW
- Normalize and deduplicate input without altering required separators or metadata.
- Verify the mode against Hashcat example hashes.
- Start with organization-specific candidates and defensible rules before giant generic attacks.
- Use status and restore files so long runs remain observable and recoverable.
- Record mode, attack type, source wordlist, rules, runtime, recovered count, and hardware context.
- Handle potfiles and recovered plaintext as sensitive data.
COMMANDS
hashcat -m MODE hashes.txt wordlist.txt
hashcat -m MODE hashes.txt wordlist.txt -r rules/best64.rule
hashcat -m MODE hashes.txt -a 3 MASK --increment
hashcat --show -m MODE hashes.txt
GOTCHAS
- Token-length or encoding errors usually mean the mode or input format is wrong.
- Do not edit the only copy of original capture material.
- Masks should reflect an evidence-based password pattern.
- Set workload and temperature behavior appropriate to the hardware.
- Report the password-control weakness without unnecessarily reproducing plaintext credentials.