performing-hash-cracking-with-hashcat
Cracks password hashes with Hashcat, covering hash-type identification, dictionary/brute-force/rule-based attack modes, custom rule creation, GPU benchmarking, and password-strength/compliance reporting. Use for authorized penetration testing or security audits that need to evaluate password strength or crack captured hashes.
DeepseekModel
官方收录技能
质量 优秀 · 90
v1.0.0
获取
https://deepseekmodel.com/api/download.php?id=mukul975-anthropic-cybersecurity-skills-skills-performing-hash-cracking-with-hashcat-skill-md&format=skill
下载 .skill
标准格式,含 system_prompt 与 model_config,导入任意 Agent 框架即可使用
.skill 文件中 system_prompt 字段的实际内容。
name performing-hash-cracking-with-hashcat description Cracks password hashes with Hashcat, covering hash-type identification, dictionary/brute-force/rule-based attack modes, custom rule creation, GPU benchmarking, and password-strength/compliance reporting. Use for authorized penetration testing or security audits that need to evaluate password strength or crack captured hashes. domain cybersecurity subdomain cryptography tags ["cryptography","hash-cracking","password-security","hashcat","penetration-testing"] version 1.0 author mahipal license Apache-2.0 nist_csf ["PR.DS-01","PR.DS-02","PR.DS-10"] mitre_attack ["T1600","T1573","T1553"] Performing Hash Cracking with Hashcat Overview Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types with GPU acceleration. This skill covers using hashcat for authorized password auditing, understanding attack modes, creating effective rule sets, and generating hash analysis reports. This is strictly for authorized penetration testing and password policy assessment. When to Use When conducting security assessments that involve performing hash cracking with hashcat When following incident response procedures for related security events When performing scheduled security testing or auditing activities When validating security controls through hands-on testing Prerequisites Familiarity with cryptography concepts and tools Access to a test or lab environment for safe execution Python 3.8+ with required dependencies installed Appropriate authorization for any testing activities Objectives Identify hash types from captured hashes Execute dictionary, brute-force, and rule-based attacks Create custom hashcat rules for targeted cracking Analyze password strength from cracking results Generate compliance reports on password policy effectiveness Benchmark GPU performance for hash cracking Key Concepts Hashcat Attack Modes Mode Flag Description Use Case Dictionary -a 0 Wordlist attack Known password patterns Combination -a 1 Combine two wordlists Compound passwords Brute-force -a 3 Mask-based enumeration Short passwords Rule-based -a 0 -r Dictionary + transformation rules Complex variations Hybrid -a 6/7 Wordlist + mask Passwords with appended numbers Common Hash Types Hash Mode Type Example Use 0 MD5 Legacy web apps 100 SHA-1 Legacy systems 1000 NTLM Windows credentials 1800 sha512crypt Linux /etc/shadow 3200 bcrypt Modern web apps 13100 Kerberos TGS-REP Active Directory Security Considerations Only perform hash cracking with explicit written authorization Secure all captured hash data in transit and at rest Report all cracked passwords immediately to asset owners Use results to improve password policies, not exploit users Destroy cracked password data after engagement concludes Follow rules of engagement for penetration test scope Validation Criteria Hash type identification is correct Dictionary attack cracks weak passwords Rule-based attack cracks policy-compliant passwords Mask attack cracks short passwords Results report shows password strength distribution All operations performed within authorized scope
Agent 识别该技能的关键词,点击任意一个即可复制。
该技能未提供触发词。
下载的 .skill 包内含以下字段。
| 字段 | 说明 |
|---|---|
| format | 格式标识(skill/v1) |
| skill_id | 技能唯一 ID |
| name | 技能名称 |
| version | 版本号 |
| description | 技能描述 |
| category | 所属分类(数组) |
| trigger_words | 触发词列表 |
| tags | 标签列表 |
| source | 来源标识 |
| source_url | 来源链接(本页地址) |
| exported_at | 导出时间(每次下载生成) |
| system_prompt | 系统提示词正文 |
| model_config | 模型参数:provider / model / temperature / max_tokens / top_p |
| examples | 示例 |
| install_guide | 各平台导入说明(Coze / Dify / Claude / 自定义框架) |