Skip to main content
All Cyber Labs
Password Cracking

Hashcat LabGPU-accelerated password recovery in a browser lab.

Practice Hashcat online in a real cyber lab — run dictionary, mask, hybrid, and rule-based attacks against NTLM, bcrypt, WPA2, and 300+ hash modes. Browser-based Kali, no install.

Overview

What is Hashcat?

Hashcat is the world's fastest open-source password recovery tool. It supports 300+ hash modes — including NTLM, bcrypt, scrypt, WPA/WPA2, KeePass, Office, and PDF — and offers six attack modes (straight, combination, mask, hybrid, rule-based) for offline credential cracking.

Inside the lab

Practising Hashcat in a real cyber lab

Hashcat is pre-installed in DeepTech Kali labs with optimised kernels and standard wordlists (rockyou, SecLists). You point it at hash files dumped from lab targets and explore attack-mode trade-offs — dictionary vs mask vs hybrid — without managing drivers, kernels, or hardware locally.

Hands-on

What you'll practice

Hands-on exercises that build job-ready Hashcat skills.

  • Run dictionary attacks with rule mutations against NTLM hashes
  • Build mask attacks for known password policies
  • Crack WPA2 4-way handshake captures from the Aircrack-ng lab
  • Pipe Hashcat through hybrid attacks (dictionary + mask)
  • Compare cracking strategy efficiency across hash modes

Available in: Tier 2 — Kali VM.

Questions, answered

Hashcat lab FAQ

Is the lab GPU-accelerated?

Labs run on shared CPU instances, with cracking exercises sized to complete in a session. For curriculum needs that require sustained GPU cracking, contact us about dedicated GPU lab tiers.

Which hash modes are practised?

The standard cracking curriculum covers NTLM, NetNTLMv2, bcrypt, MD5/SHA-family, WPA2-PSK, KeePass, and Office. The full 300+ mode set is available — exercises pick representative samples per learning objective.

How does Hashcat differ from John the Ripper in the labs?

Both run side-by-side on the same Kali image. John is workflow-friendly for mixed-format cracking; Hashcat shines on raw throughput and mask/rule expressiveness. The cracking curriculum uses both intentionally.

Start your Hashcat lab now

Spin up a real, isolated environment in your browser and practice Hashcat hands-on — no install, pay only for active time.