Hash cracking: dictionaries, rules, masks
With hashes in hand (from a DB, LSASS, a handshake), offline cracking recovers passwords. GPUs try billions of candidates per second for fast hashes.
The strategies
Dictionary + rules: start from a wordlist (rockyou) and apply transforms (best64, leetspeak, digit/year appends) — covering how people modify passwords. Masks: targeted brute-force over known patterns (?u?l?l?l?l?d?d?d?d = Uppercase+4 lowercase+4 digits). Combinator/hybrid join words.
hashcat -m 0 hashes.txt rockyou.txt -r rules/best64.rule # MD5
hashcat -m 1000 nt.txt -a 3 ?u?l?l?l?l?d?d?d?d # NTLM maskThe -m number is the hash type (0 MD5, 1000 NTLM, 1800 sha512crypt, 22000 WPA).
Defence
Slow, salted hashes (Argon2/bcrypt) make cracking economically prohibitive. Long, random passwords (password managers make them possible) beat every mask and dictionary. Per-user salt removes rainbow tables and parallel cracking.