Hashcat NTLMv2 Cracking
Crack NTLMv2 (NetNTLMv2) challenge-response hashes captured from Responder or relay attacks
- Tool
- hashcat
- Category
- Credential Attacks / Hash Cracking
- Platform
- linux
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
hashcat -m 5600 '<hash_file>' /usr/share/wordlists/rockyou.txt
Credential variants
The same attack using a different authentication material.
With Rules
hashcat -m 5600 '<hash_file>' /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
With Mask (8+ chars)
hashcat -m 5600 '<hash_file>' -a 3 '?a?a?a?a?a?a?a?a'
Examples
hashcat -m 5600 ntlmv2.hashes /usr/share/wordlists/rockyou.txt
Tags
Related commands
- NetExec SMB Auth Test Test SMB authentication with various credential types
- Evil-WinRM Shell Windows Remote Management shell connection
- Hashcat AS-REP Roasting Cracking Crack AS-REP roasting hashes obtained from accounts without Kerberos pre-auth
- Hashcat Kerberoast Crack Crack Kerberoasting hashes
- Hashcat MSCacheV2 (DCC2) Cracking Crack MSCacheV2 (Domain Cached Credentials v2 / DCC2) hashes extracted from registry
- Hashcat NTLM Crack Crack NTLM hashes using wordlist attack