Files
Anthropic-Cybersecurity-Skills/skills/performing-hash-cracking-with-hashcat/SKILL.md
T
Mahipal 2fb6a9faff Rewrite 548 skill descriptions to the activation rubric
Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
2026-08-02 09:32:13 -07:00

3.5 KiB

name, description, domain, subdomain, tags, version, author, license, nist_csf, mitre_attack
name description domain subdomain tags version author license nist_csf mitre_attack
performing-hash-cracking-with-hashcat Cracks password hashes with Hashcat, covering hash-type identification, dictionary/brute-force/rule-based attack modes, custom rule creation, GPU benchmarking, and password-strength/compliance reporting. Use for authorized penetration testing or security audits that need to evaluate password strength or crack captured hashes. cybersecurity cryptography
cryptography
hash-cracking
password-security
hashcat
penetration-testing
1.0 mahipal Apache-2.0
PR.DS-01
PR.DS-02
PR.DS-10
T1600
T1573
T1553

Performing Hash Cracking with Hashcat

Overview

Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types with GPU acceleration. This skill covers using hashcat for authorized password auditing, understanding attack modes, creating effective rule sets, and generating hash analysis reports. This is strictly for authorized penetration testing and password policy assessment.

When to Use

  • When conducting security assessments that involve performing hash cracking with hashcat
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Familiarity with cryptography concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Identify hash types from captured hashes
  • Execute dictionary, brute-force, and rule-based attacks
  • Create custom hashcat rules for targeted cracking
  • Analyze password strength from cracking results
  • Generate compliance reports on password policy effectiveness
  • Benchmark GPU performance for hash cracking

Key Concepts

Hashcat Attack Modes

Mode Flag Description Use Case
Dictionary -a 0 Wordlist attack Known password patterns
Combination -a 1 Combine two wordlists Compound passwords
Brute-force -a 3 Mask-based enumeration Short passwords
Rule-based -a 0 -r Dictionary + transformation rules Complex variations
Hybrid -a 6/7 Wordlist + mask Passwords with appended numbers

Common Hash Types

Hash Mode Type Example Use
0 MD5 Legacy web apps
100 SHA-1 Legacy systems
1000 NTLM Windows credentials
1800 sha512crypt Linux /etc/shadow
3200 bcrypt Modern web apps
13100 Kerberos TGS-REP Active Directory

Security Considerations

  • Only perform hash cracking with explicit written authorization
  • Secure all captured hash data in transit and at rest
  • Report all cracked passwords immediately to asset owners
  • Use results to improve password policies, not exploit users
  • Destroy cracked password data after engagement concludes
  • Follow rules of engagement for penetration test scope

Validation Criteria

  • Hash type identification is correct
  • Dictionary attack cracks weak passwords
  • Rule-based attack cracks policy-compliant passwords
  • Mask attack cracks short passwords
  • Results report shows password strength distribution
  • All operations performed within authorized scope