AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Password Cracking

See below for resources related to Password Cracking! This is quite a deep rabbit hole, but more resources will be added to this page in due time. Special thanks to those who lurk in the Digital Forensics Discord Server’s Password Cracking channel for helping compile these resources!

ResourceDescription
13Cubed - Introduction to HashcatHow-to video for using Hashcat, Part 1
13Cubed - Introduction to Hashcat - Part IIHow-to video for using Hashcat, Part 2
Cracking 12 Character & Above PasswordsCombo & Hybrid Password Attacks
CrackStation's Password Cracking DictionaryCrackStation's main password cracking dictionary
HashcatHashcat Website
Hashcat WikiHashcat Wiki
Hashes.orgHashes.org is a free online hash resolving service incorporating many unparalleled techniques.
HashtopolisGUI wrapper for Hashcat
John the RipperHistorically, its primary purpose is to detect weak Unix passwords. These days, besides many Unix crypt(3) password hash types, supported in "-jumbo" versions are hundreds of additional hashes and ciphers.
Koanashi PasswordsThese wordlists have been extracted from real password leaks, and sorted by number of occurrences.
OWASP/CheatSheetSeriesCheat Sheets created by the Open Web Application Security Project (OWASP)
PDFCrackA Password Recovery Tool for PDF files
SecLists Password ListsMultiple password lists
SkullSecurity Password ListsMany leaked password lists including but not limited to rockyou.txt
WeakpassMultiple wordlists for password cracking