Hashcat NTLMv2 Cracking

Crack NTLMv2 (NetNTLMv2) challenge-response hashes captured from Responder or relay attacks

Tool
hashcat
Category
Credential Attacks / Hash Cracking
Platform
linux

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

hashcat -m 5600 '<hash_file>' /usr/share/wordlists/rockyou.txt

Credential variants

The same attack using a different authentication material.

With Rules

hashcat -m 5600 '<hash_file>' /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule

With Mask (8+ chars)

hashcat -m 5600 '<hash_file>' -a 3 '?a?a?a?a?a?a?a?a'

Examples

hashcat -m 5600 ntlmv2.hashes /usr/share/wordlists/rockyou.txt

Tags

hashcat ntlmv2 hash-cracking responder offline