During the 2024 RockYou2024 credential dump analysis, researchers found that millions of cracked hashes came from NTLM passwords under 10 characters — most falling within minutes on modern GPUs. Hashcat is the tool behind most of that work. This guide shows you how to set it up and use it effectively.
Installing Hashcat and Verifying GPU Access
Hashcat is an open-source, GPU-accelerated password recovery tool. It supports over 300 hash types and runs significantly faster on a GPU than a CPU — often 100x or more for common hash types like NTLM or MD5.
On a Debian-based system, install it alongside the OpenCL runtime:
sudo apt update && sudo apt install hashcat ocl-icd-opencl-dev -y
hashcat -I
The -I flag lists every compute device Hashcat can see. Your output should look something like this:
OpenCL Info:
Platform ID #1
Vendor : NVIDIA Corporation
Name : NVIDIA CUDA
Version : OpenCL 3.0 CUDA 12.4
Backend Device ID #1
Name : NVIDIA RTX 4070
Processors : 36
Clock : 2505 MHz
Memory.Total : 12282 MB
Memory.Free : 11900 MB
If you see your GPU listed, you are ready. If only a CPU appears, your OpenCL or CUDA driver is missing. On NVIDIA hardware, install the proprietary driver and nvidia-opencl-icd package first.
Run a quick benchmark to see what you are working with:
hashcat -b -m 1000
Mode 1000 is NTLM — the hash type you will encounter most often in Windows environments. On an RTX 4070, expect roughly 80 GH/s. That means 80 billion NTLM hash comparisons per second. An 8-character lowercase password has 208 billion combinations — crackable in under three seconds at that speed.
Dictionary Attack Against a Real Hash
Say you have pulled NTLM hashes from a domain controller during an authorized red team engagement on dc01.corp.internal (192.0.2.10). You used Secretsdump and extracted a hash for the user jmartin:
jmartin:1104:aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c:::
The relevant part is the NT hash: 8846f7eaee8fb117ad06bdd830b7586c. Save it to a file:
echo "8846f7eaee8fb117ad06bdd830b7586c" > hashes.txt
Now run a dictionary attack using the classic rockyou.txt wordlist:
hashcat -m 1000 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt -o cracked.txt --outfmt 2
Breaking that command down: -m 1000 sets the hash type to NTLM, -a 0 is straight dictionary mode, and -o cracked.txt writes results to a file. Within seconds you should see:
8846f7eaee8fb117ad06bdd830b7586c:Password1
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 1000 (NTLM)
Time.Started.....: Mon Oct 06 09:14:22 2026
Time.Estimated...: Cracked
Speed.#1.........: 81,204 MH/s
Recovered........: 1/1 (100.00%)
That hash is the well-known NTLM value for Password1. In a real engagement, a cracked domain account password opens a direct path to lateral movement — especially if jmartin reused it elsewhere or is a local admin on other boxes. Document it, pivot, and report it as a critical finding.
Rule-Based Attack: Going Beyond the Wordlist
Most users do not pick raw dictionary words — they mangle them. Password1 becomes P@ssw0rd1!. Hashcat rules automate this mangling at GPU speed.
Suppose jmartin changed their password and the new hash is 3b72a6d3958fd5d81f77e4438e4b1f50. A straight dictionary attack misses it. Add Hashcat’s best64 rule set:
hashcat -m 1000 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt \
-r /usr/share/hashcat/rules/best64.rule -o cracked.txt
Each rule transforms every word before comparing it to the hash. The rule $1 $! appends 1!, turning password into password1!. With best64 applied to rockyou.txt, you get roughly 900 million candidate passwords — still processed in seconds on a modern GPU.
3b72a6d3958fd5d81f77e4438e4b1f50:P@ssword1!
Status...........: Cracked
Speed.#1.........: 78,901 MH/s
Recovered........: 1/1 (100.00%)
This output confirms the user chose a predictable mangled password. For defenders, this is exactly why password complexity requirements alone fail — users follow predictable patterns, and rule engines exploit those patterns systematically.
For attackers: chain multiple rule files with repeated -r flags or use OneRuleToRuleThemAll.rule from GitHub for broader coverage on stubborn hashes.
What To Do Now
Pull your own Active Directory NTLM hashes in a lab environment using Impacket’s secretsdump.py against a test DC, run them through Hashcat with rockyou.txt plus best64.rule, and record how many crack within 60 seconds. That single exercise will immediately show you how weak your current password policy really is — and give you the evidence you need to push for longer minimum lengths or passphrases.
