Hashcat (-m) & John the Ripper Hash Identifier & Command Builder (2026)

Identify 50+ password hash formats by regex, bit length, and modular crypt prefix ($2y$, $argon2id$, $6$, $krb5tgs$, NetNTLMv2, DCC2), retrieve exact Hashcat -m modes and John --format flags, and generate GPU cracking CLI commands.

Hashcat (-m) & John the Ripper Hash Identifier & Command Builder — Interactive Console
Runs locally in your browser • Instant output
One-Click Sample Hash Presets (8 Formats):
bcrypt (Blowfish Adaptive KDF)99% Match
Strong KDF
Hashcat Mode (-m)-m 3200
John the Ripper--format=bcrypt
RTX 5090 Crack Rate~215,000 H/s (at cost=10) / ~53,000 H/s (at cost=12)

Contains 128-bit Base64 salt and exponential work factor (2^cost rounds).

Hashcat Dictionary + Rule CLI
hashcat -m 3200 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt -r rules/best64.rule -w 3 -O
John the Ripper CLI
john --format=bcrypt --wordlist=/usr/share/wordlists/rockyou.txt --rules=Best64 hashes.txt
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Hashcat (-m) & John the Ripper Hash Identifier & Command Builder](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/hashcat-john-hash-type-identifier/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/hashcat-john-hash-type-identifier/">Hashcat (-m) & John the Ripper Hash Identifier & Command Builder — ZerosUniverse</a>

2026 Hashcat (-m) & John the Ripper (--format) Hash Signature Table

2026 Verified Reference
Quick Answer & 2026 Technical Summary (hashcat hash identifier mode finder)Updated 2026 Standard

Identify cryptographic hashes by inspecting their prefix (`$2b$`, `$6$`, `$argon2id$`), character length (32 hex = MD5/NTLM, 40 hex = SHA1, 64 hex = SHA-256), and delimiter structure, then map directly to Hashcat `-m` mode IDs and John the Ripper `--format` flags.

hashcat -m <MODE_ID> -a 0 hashes.txt rockyou.txt -O -w 3 | john --format=<FORMAT> --wordlist=rockyou.txt hashes.txt
32 Hex Characters: MD5 (-m 0) or Windows NTLM (-m 1000)
60 Chars ($2a$/$2b$): bcrypt Blowfish (-m 3200)
Active Directory Kerberos: AS-REP (-m 18200) / TGS (-m 13100)
Hash Algorithm / StandardLength & Prefix SignatureHashcat Mode (-m)John the Ripper (--format)
MD5 / Raw-MD532 Hex chars (e.g., 5d41402abc4b2a76...)-m 0--format=raw-md5
Windows NTLM (SAM / NTDS.dit)32 Hex chars (No salt; case-insensitive hex)-m 1000--format=nt
SHA-256 / Raw-SHA25664 Hex chars (256-bit digest)-m 1400--format=raw-sha256
bcrypt (Blowfish Cost Factor)60 chars starting with $2a$, $2b$, or $2y$-m 3200--format=bcrypt
NetNTLMv2 (SMB Responder)user::DOMAIN:ServerChallenge:NTProofStr:Blob-m 5600--format=netntlmv2
WPA2 / WPA3 PMKID + EAPOLWPA*01* or WPA*02* (hc22000 hashline)-m 22000--format=wpapsk-opencl
In-Depth ZerosUniverse Tutorial

CEH Module 06: System Hacking & Password Cracking Guide

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Hashcat (-m) & John the Ripper Hash Identifier & Command Builder

01

Paste a Raw or Salted Hash String (or Load a Red-Team Sample)

Paste your target hash into the analyzer input—or click a one-click sample preset (NTLM, bcrypt $2y$12$, NetNTLMv2, Kerberoast $krb5tgs$23$, SHA-512 $6$, or Argon2id).

02

Review Ranked Candidate Algorithms & Confidence Scores

Inspect the matched hash types ordered by structural specificity, complete with bit length, salt location, cost factor extraction, and Hashcat -m / John --format IDs.

03

Configure Attack Mode, Wordlist, Rules & Mask Pattern

Select Straight Dictionary (-a 0), Brute-Force Mask (-a 3), or Hybrid Wordlist+Mask (-a 6), then customize your mask charset (?u, ?l, ?d, ?s) and GPU workload profile (-w 3).

04

Copy Ready-to-Run Hashcat & John CLI Commands

Copy the generated terminal command lines and review the estimated keyspace size and GPU cracking duration.

Key Capabilities & Technical Architecture

Multi-Signature Regex & Modular Crypt Prefix Classifier

Distinguish raw hex digests (32/40/64/128 chars) from structured MCF strings ($2a$/$2y$ bcrypt, $argon2id$, $6$ sha512crypt, $krb5tgs$23$, $krb5asrep$, Domain Cached Credentials DCC2, and NetNTLMv2).

Exact Hashcat (-m) & John the Ripper (--format) Cross-Reference

Map every candidate hash algorithm to its exact Hashcat numeric mode (-m 1000, -m 3200, -m 13100, -m 5600) and John Jumbo format string (--format=NT, --format=krb5tgs).

Interactive Attack Mode (-a 0 / -a 3 / -a 6) CLI Command Builder

Generate copy-ready Hashcat and John commands with custom wordlists (rockyou.txt), rules (best64.rule, OneRuleToRuleThemAll), charset masks (?u?l?l?l?d?d?d?s), and optimized kernel flags (-O -w 3).

RTX 4090 / 5090 Hashrate & Keyspace Exhaustion Estimator

Compare cracking velocity across unsalted fast hashes (MD5/NTLM at 100+ GH/s) vs memory-hard KDFs (bcrypt cost 12, Argon2id, PBKDF2-HMAC-SHA256) and calculate time-to-crack.

Practical Use Cases

CEH v12 & OSCP / Penetration Test Hash Triage

Quickly classify extracted hashes from /etc/shadow, SAM/NTDS.dit dumps, Responder SMB captures, or Rubeus/Impacket Kerberoasting output during engagements.

Eliminating Hashcat Mode Lookup Errors & Token Exceptions

Prevent 'Token length exception' and 'Separator unmatched' errors by validating exact salt delimiters and modular crypt prefixes before launching GPU rigs.

Password Storage Architecture Security Auditing

Demonstrate the 7-order-of-magnitude GPU cracking speed gap between legacy SHA-256/NTLM hashes and OWASP-recommended Argon2id (m=65536, t=3, p=4).

Frequently Asked Questions (FAQs)

Why can a 32-character hexadecimal string be either MD5 (-m 0) or NTLM (-m 1000)?+

Both MD5 and Microsoft NTLM (which is MD4 of the UTF-16LE encoded password) output an unsalted 128-bit digest represented as 32 hexadecimal characters. Because cryptographic hashes are pseudorandom, a raw 32-hex string has no structural header—you determine whether to run -m 0 or -m 1000 based on whether the hash came from a web database or a Windows SAM/NTDS.dit dump.

What is the difference between NetNTLMv2 (-m 5600) and local NTLM (-m 1000) hashes?+

A local NTLM hash (-m 1000) is a direct unsalted MD4 digest stored in the SAM or Active Directory NTDS.dit database and can be used directly for Pass-the-Hash (PtH). A NetNTLMv2 hash (-m 5600) is a network challenge-response HMAC-MD5 blob captured over SMB/HTTP via tools like Responder; it cannot be used for Pass-the-Hash and must be cracked offline.

How do I read the parts of a bcrypt ($2y$12$...) hash?+

A standard 60-character bcrypt string starts with the version identifier ($2a$, $2b$, or $2y$), followed by the base-2 logarithmic cost factor ($12$ = 2^12 = 4,096 Blowfish key expansion rounds), followed by a 22-character Radix-64 encoded 128-bit salt, and finally a 31-character Radix-64 ciphertext digest.

What does the -O (--optimized-kernel-enable) flag do in Hashcat?+

Passing -O enables hand-tuned assembly/OpenCL/CUDA kernels that run up to 2x faster on GPUs by restricting the maximum password candidate length (typically to 31 characters for raw hashes or 15 characters for certain salted modes). Omit -O if you are testing long passphrases.

Are pasted hashes logged or sent to an external cracking lookup API?+

No. All regex parsing, prefix decoding, and CLI command generation run 100% locally in your browser's JavaScript engine.