2026 Hashcat (-m) & John the Ripper (--format) Hash Signature Table
2026 Verified ReferenceIdentify cryptographic hashes by inspecting their prefix (`$2b$`, `$6$`, `$argon2id$`), character length (32 hex = MD5/NTLM, 40 hex = SHA1, 64 hex = SHA-256), and delimiter structure, then map directly to Hashcat `-m` mode IDs and John the Ripper `--format` flags.
hashcat -m <MODE_ID> -a 0 hashes.txt rockyou.txt -O -w 3 | john --format=<FORMAT> --wordlist=rockyou.txt hashes.txt| Hash Algorithm / Standard | Length & Prefix Signature | Hashcat Mode (-m) | John the Ripper (--format) |
|---|---|---|---|
| MD5 / Raw-MD5 | 32 Hex chars (e.g., 5d41402abc4b2a76...) | -m 0 | --format=raw-md5 |
| Windows NTLM (SAM / NTDS.dit) | 32 Hex chars (No salt; case-insensitive hex) | -m 1000 | --format=nt |
| SHA-256 / Raw-SHA256 | 64 Hex chars (256-bit digest) | -m 1400 | --format=raw-sha256 |
| bcrypt (Blowfish Cost Factor) | 60 chars starting with $2a$, $2b$, or $2y$ | -m 3200 | --format=bcrypt |
| NetNTLMv2 (SMB Responder) | user::DOMAIN:ServerChallenge:NTProofStr:Blob | -m 5600 | --format=netntlmv2 |
| WPA2 / WPA3 PMKID + EAPOL | WPA*01* or WPA*02* (hc22000 hashline) | -m 22000 | --format=wpapsk-opencl |
