Offline password auditing tests candidate passwords against copied hash data rather than a live login service. This hands-on course teaches you to prepare that data, build focused candidate lists, choose the correct cracking format, and interpret recovered results with John the Ripper and Hashcat.
You will generate patterned words with Crunch, collect contextual vocabulary from a local practice site with Cewl, and refine the combined list. You will then exercise John’s single and dictionary modes, Hashcat’s straight and rule-based attacks, and potfile reporting. A final challenge combines an NTLM hash, a company-derived wordlist, and a custom year-appending rule.
What You Will Learn
- Generate a constrained pattern-based wordlist with Crunch
- Extract target-relevant words from a local website with Cewl and deduplicate combined dictionaries
- Prepare Linux account data for John the Ripper with
unshadow - Run John’s single-crack and dictionary modes and report recovered credentials with
--show - Find Hashcat module codes and run a straight dictionary attack against prepared MD5 hashes
- Use John and Hashcat potfiles to retrieve previous results without repeating work
- Preview built-in Hashcat mutations and write a custom rule for a known password pattern
- Combine contextual vocabulary, NTLM mode selection, and rule-based guessing in an independent recovery challenge
Who This Course Is For
This intermediate course is for cybersecurity learners, penetration testers, incident responders, and administrators who need a practical introduction to authorized offline password auditing. It emphasizes candidate strategy, input preparation, and reproducible reporting rather than raw benchmark performance.
Prerequisites: Comfort with a Linux terminal, files, pipes, output redirection, and basic hash concepts. Familiarity with wordlists and common password habits is helpful; prior John the Ripper or Hashcat experience is not required.
Learning environment: An interactive Ubuntu 22.04 terminal with prepared synthetic hashes and account files, John the Ripper, Hashcat, Crunch, Cewl, and a local practice website. The intentionally small datasets run on the lab CPU without dedicated GPU hardware.
Frequently Asked Questions
Does this course attack live login pages or online accounts?
No. Every recovery attempt is offline against copied, synthetic hash files supplied in the isolated lab. The local website is used only to generate contextual words; there are no authentication requests, lockout tests, or MFA bypasses.
Do I need a powerful GPU?
No. The exercises use small MD5, NTLM, and Linux password-hash samples designed to complete on the lab CPU. The course explains Hashcat’s hardware-oriented workflow but does not benchmark or perform large-scale cracking.
Which attack strategies are practiced?
You use pattern-based and context-derived wordlists, John’s heuristic single mode, straight dictionary attacks, and Hashcat mutation rules. Broad brute-force keyspaces, mask attacks, distributed cracking, and cloud GPU operations are outside the scope.
Can these techniques be used on real credential data?
Only when you own the data or have explicit authorization to audit it. The course uses synthetic credentials in an isolated environment and presents the workflow for defensive assessment and approved penetration testing.





