Hashcat — Wordlist & Mask Attacks
Hashcat essentials: pick the hash mode with -m, run a dictionary attack, or fall back to a mask brute-force.
# -m = hash mode: 0=MD5, 100=SHA1, 1000=NTLM, 1800=sha512crypt (see -h for the list)
# straight dictionary attack (-a 0)
hashcat -m 0 -a 0 hash.txt /usr/share/wordlists/rockyou.txt
# mask / brute-force (-a 3): 8 chars, lowercase letters + 2 digits
hashcat -m 0 -a 3 hash.txt ?l?l?l?l?l?l?d?d
used in: Cheatsheet: tool overview