Hashcat is an offline password-recovery tool: it tests candidate passwords by hashing them and comparing the results with hashes you already possess. This beginner course makes that process concrete in five guided, terminal-based labs using small, intentionally recoverable examples.
You will begin by installing Hashcat and measuring MD5 benchmark speed, then learn how hashes differ from passwords and why the correct hash mode matters. The practical sequence contrasts dictionary and mask attacks before showing how Hashcat records successful recoveries and separates unresolved hashes. The course is deliberately focused; it builds a sound first workflow rather than promising that every password can be recovered.
What You Will Learn
After completing the course, you will be able to:
- Install Hashcat on Ubuntu, verify its version, inspect available compute devices, and interpret an MD5 benchmark rate.
- Distinguish a plaintext password from its one-way hash and recognize the course’s MD5, SHA-1, and NTLM examples.
- Prepare target-hash and candidate files and select the appropriate Hashcat hash mode and attack mode.
- Run a straight dictionary attack, interpret statuses such as
CrackedandExhausted, and display recovered values with--show. - Build mask attacks with built-in character sets and a custom known pattern, then explain when a mask or wordlist is the better strategy.
- Inspect the Hashcat potfile, write recovered pairs to an output file, and use
--leftto isolate hashes that remain unresolved.
Who This Course Is For
This course is for cybersecurity beginners, system administrators learning password-audit concepts, and CTF or penetration-testing learners who have not used Hashcat before. It concentrates on the mechanics and interpretation of small offline recovery tasks. It does not cover online login attacks, rule-based attacks, distributed cracking, advanced performance tuning, or a comprehensive password-storage defense curriculum.
Prerequisites: No Hashcat experience is required. Basic Linux terminal and file-management skills are helpful. A conceptual understanding that hashes are not encrypted passwords will be developed in the course, so prior cryptography study is not necessary.
Learning environment: You will use a browser-accessible Ubuntu terminal with prepared MD5 and NTLM hashes, small wordlists, and known password patterns. Hashcat runs on the compute device available to the lab, which may be CPU-based; benchmark and recovery speeds will differ from dedicated GPU hardware. Use password-recovery tools only with your own data or explicit authorization.
Frequently Asked Questions
Does Hashcat try passwords against a live website or SSH service?
No. Hashcat works offline against hash values stored in files. Tools such as Hydra address online authentication services and involve a different workflow, network behavior, and risk profile.
Which hash types and attack modes are practiced?
The course introduces MD5, SHA-1, and NTLM conceptually. Hands-on attacks use MD5 with a dictionary and MD5 or NTLM examples with dictionary and mask workflows. It does not attempt to survey Hashcat’s full algorithm catalog.
Will these labs teach me to recover any password?
No. Recovery succeeds only when a tested candidate produces the target hash. Wordlist quality, pattern knowledge, password length and complexity, hash cost, and available hardware all affect feasibility. The lab examples are intentionally small so you can learn the workflow.
Do I need a GPU for this course?
No dedicated GPU is required for the provided exercises. You will inspect the available device and benchmark it, but the goal is to understand commands and results rather than achieve production cracking speed. Real hardware can produce very different rates.





