Skip to content

Hashcat

World's fastest password recovery tool. Recover lost passwords from hash files using CPU and GPU.

Self-hostedNot yet verified
Report issueDemo online
MIT★ 20000

Open the official app on hashcat.net

This tool is hosted by its maintainers. Click below to open hashcat.net in a new tab — it's their official demo.

Browse security tools →

What's next with Hashcat?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Hashcat?

Hashcat is an open-source password recovery tool designed to crack cryptographic hashes by leveraging computational power from CPUs, GPUs, and other hardware. Its primary purpose is to recover lost or forgotten passwords by testing vast numbers of potential candidates against hashed data. Cybersecurity professionals, penetration testers, and developers use Hashcat to assess system security, identify weak password practices, and mitigate risks from compromised credentials. It solves the problem of recovering passwords from encrypted storage, such as hashed user databases, by utilizing distributed computing and advanced algorithms to accelerate the cracking process.

How it works

Hashcat is a powerful password recovery utility that supports multiple hash types and cryptographic algorithms. It is particularly effective for cracking hashes generated by protocols like MD5, SHA-1, and bcrypt, among others. The tool is essential for security audits, where it helps identify vulnerabilities in password storage mechanisms. Its ability to handle large datasets makes it a critical tool for both offensive and defensive cybersecurity operations. Hashcat supports multi-hash cracking, allowing users to process multiple hash types simultaneously. It also utilizes GPU acceleration via OpenCL, significantly speeding up brute-force attacks. Features like distributed cracking networks and session management enable efficient resource allocation and resume capabilities after interruptions.

How to use it

  1. 1Install Hashcat on your system, ensuring compatibility with your OpenCL-enabled hardware. 2. Verify GPU drivers are correctly installed, such as AMD Adrenalin Edition or NVIDIA CUDA Toolkit. 3. Run a benchmark test with 'hashcat -b' to assess cracking speeds. 4. Use the benchmark results to configure a cracking session with 'hashcat -O' for optimized kernel code. Practical tips include using the '--force' flag to bypass device compatibility warnings and leveraging the '--session' option for managing ongoing attacks. Always ensure legal compliance when using Hashcat for password recovery.

What it can do

  • password hash cracking

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/hashcat/hashcat
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Requires high-performance hardware for complex hash types
  • Cracking time increases exponentially with password complexity
  • Legal restrictions may limit its use in unauthorized environments
  • Consumes significant system resources during operation

Understanding the result

World's fastest password recovery tool. Recover lost passwords from hash files using CPU and GPU.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(hashcat/hashcat)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with hashcat/hashcat. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Hashcat used for?

Hashcat is primarily used for password recovery by cracking cryptographic hashes. It helps cybersecurity professionals assess password security, recover lost credentials, and test the resilience of password storage mechanisms against brute-force attacks.

How does Hashcat utilize OpenCL?

Hashcat leverages OpenCL (Open Computing Language) to offload computational tasks to GPUs and other accelerators. This allows parallel processing of hash calculations, drastically reducing cracking time compared to CPU-only methods. Support for AMD, NVIDIA, and Intel OpenCL runtimes ensures compatibility across diverse hardware.

How do I run a benchmark test with Hashcat?

To run a benchmark test, use the command 'hashcat -b'. This mode evaluates the performance of your hardware by testing all supported hash types. The output provides estimated cracking speeds, helping users configure optimal settings for their specific use case.

How does Hashcat compare to alternatives like John the Ripper?

Hashcat outperforms John the Ripper in GPU-accelerated cracking due to its native OpenCL support and multi-device capabilities. John the Ripper, while effective for CPU-based attacks, lacks Hashcat's scalability for distributed networks and advanced hash types like bcrypt. Hashcat's flexibility makes it more suited for modern, resource-intensive cracking scenarios.

How do I resolve 'Device #1: Not a native Intel OpenCL runtime' errors?

This error occurs when Hashcat detects a non-Intel OpenCL runtime, such as ROCm or CUDA. To resolve it, ensure your system meets the required drivers (e.g., AMD Adrenalin Edition for ROCm or NVIDIA CUDA Toolkit). Use the '--force' flag to bypass the check, but note that performance may degrade without compatible hardware.

Spotted something wrong with Hashcat, or want to maintain it? See how to help.