Skip to content

Latest commit

 

History

11,198 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

shooter_hashcat

shooter_hashcat is a Windows-focused version of hashcat 7.1.2. It keeps the normal hashcat commands and features, then adds faster handling of very large hash and rule lists, better multi-GPU behavior, more ways to build password candidates, multibyte masks and rules on Windows, additional hash types, and a ready-to-run release. If an error occurs, it also creates one support file that can be reviewed and sent with a bug report.

It was developed for a Windows machine with 12 NVIDIA GeForce RTX 4090 GPUs, but most of its additions also work on other hardware.

Use this software only on passwords and systems you own or are explicitly authorized to audit.

Shooter-specific enhancements

This public inventory lists changes maintained by Shooter relative to the official upstream hashcat commit merged into this branch. Features inherited from official hashcat are intentionally excluded. Every item links to a plain-language explanation.

  1. Huge hash lists parse across CPU cores — less time waiting at Parsing Hashes.
  2. Huge unsalted hash lists sort across CPU cores — preprocessing finishes sooner.
  3. The 12-GPU system skips unnecessary backend scans — short jobs begin faster.
  4. Multiple GPUs start and stop concurrently — devices no longer wait on one-at-a-time setup.
  5. The 12-GPU system uses much less host memory — measured staging fell from about 97.7 GB to 36.7 GB.
  6. RTX 4090 tuning is saved and reused — matching jobs can skip repeated tuning.
  7. Blowfish kernels can be reused — supported Blowfish modes avoid needless recompilation.
  8. Large cracked-result sets write much faster — outfile and potfile results are batched safely.
  9. Attack mode 1 joins three or more wordlists — no fixed three-to-six-file attack modes are needed.
  10. Multi-GPU combination attacks seek directly to each GPU's work — later GPUs do not replay earlier combinations.
  11. Rules can modify the complete candidate — supported in attack modes 1, 3, 6, and 7; mode 13 instead applies rules at their ordered pipeline position.
  12. --stdout rule generation uses multiple CPU cores — up to 64 workers retain deterministic order.
  13. --stdout jobs can pause, checkpoint, and restore — file output resumes at the exact byte boundary.
  14. Multibyte masks work on Windows — literals such as № survive the command line.
  15. Multibyte rules work on Windows — rule files and inline rules accept UTF-8 literals.
  16. A running time limit can be extended or shortened — adjust --runtime without restarting.
  17. Multi-GPU checkpoints keep every GPU coordinated — checkpoint cancellation safely resumes all devices.
  18. CUDA startup failures retry without dropping GPUs — a failed device cannot silently produce a partial-GPU run.
  19. Temporarily locked output files are retried — brief Windows locks do not immediately lose results.
  20. [i]gnore outfile stops directory checking — stop checking --outfile-check-dir for the current run without changing the directory.
  21. Outfile-check-only cracks are labeled clearly — the final status identifies where the result came from.
  22. Loopback induction files clean up safely on Windows — consumed files are not rediscovered forever.
  23. Quit shows shutdown progress — the console explains what hashcat is still finishing.
  24. The final summary shows total run time — Total Run Time is calculated from start and stop timestamps.
  25. Combination status shows the correct wordlist paths — ruled mode-1 jobs no longer show (null).
  26. Pure Kernel selection is highlighted — interactive status displays the line in yellow.
  27. The complete mdxfind e1-e1001 namespace is available — 999 standalone algorithms plus two documented special entries.
  28. mdxfind names appear consistently throughout hashcat — help, status, benchmarks, and logs show public eN names.
  29. mdxfind e987 accepts Magento Argon2 input — original Magento lines remain intact in output and potfiles.
  30. Modes 29950 and 29951 handle phpBB3 legacy rehashes — the complete two-stage hashes run on the GPU.
  31. Mode 29980 adds the supported gost-yescrypt profile — handles libxcrypt-style $gy$j9T$ hashes.
  32. Mode 67000 restores legacy yescrypt numbering — old jobs use the maintained mode-36100 implementation.
  33. One .7z contains both source and a ready-to-run build — download one file to run or rebuild Shooter.
  34. Release contents can be verified locally — an included script checks the complete SHA-256 manifest.
  35. Windows builds bootstrap with one command — the compiler toolchain stays inside the repository.
  36. Fresh clones build from any drive — no machine-specific absolute paths are required.
  37. Release versions are reproducible — tags, packages, rebuilds, and --version stay identical.
  38. Huge rule files load across CPU cores — all rule-capable algorithms spend less time waiting at Loading rules.
  39. Restore.Sub status lines are optional — they stay hidden unless --status-restore-sub is requested.
  40. Prebuilt releases run on standard x64 CPUs — release binaries do not inherit the GitHub runner's CPU-only instructions.
  41. --show and --left finish faster on huge lists — large potfiles use narrower lookups, and -o jobs skip a redundant full-result copy and sort.
  42. Shooter's mdxfind bridge builds on Linux — the added bridge links in both static and shared Linux builds.
  43. Errors are saved in one support file — the file records recent warnings, every normal error, later warnings, and the details needed to investigate the problem.
  44. Parser bugs are hunted automatically — scheduled sanitizer and coverage-guided fuzz tests retain crash inputs.
  45. Pipeline time and peak RAM can be measured — opt-in human and JSON reports show where a run spent its time.
  46. Releases include an SBOM and signed attestations — verify archive contents, provenance, and the software inventory.
  47. Existing outfile results are removed before cracking starts — if every hash is already in --outfile-check-dir, the expensive attack-specific GPU and host-memory allocation is skipped.
  48. Huge wordlists index and feed faster — first-use line counting uses the CPU cores and ordinary candidates reach the GPUs with less per-word overhead.
  49. Remaining hashes and recovery rates are always visible — every normal status display includes Remaining and Recovered/Time, even for small hash lists, with live minute values from the first status update.
  50. Attacks can explain where their time went — opt-in --task-time-breakdown output separates preparation, cracking, and cleanup, then itemizes hash loading, sorting, potfile/outfile checks, rules, GPU setup, self-test, and autotune.
  51. Full status appears at both ends of an attack — the same human-readable page as interactive s prints once before cracking workers start and again when the attack completes.
  52. Attack mode 13 runs an ordered component pipeline — any number of wordlists, masks, and rule stages run left-to-right in the exact order entered.
  53. All-rejected optimized input retries with the pure kernel — when -O parser limits reject every supplied hash, the complete session is rebuilt once without -O.
  54. PCFG candidates run through a native deterministic feed — train a probability-ordered grammar, then run it as -a 8 pcfg MODEL with keyspace, rules, restore, and multi-GPU distribution.
  55. Final candidates can require character classes — independent, default-off upper/lower/digit/symbol minimums are checked after supported rules and complete mode-13 pipelines.
  56. Multibyte candidates display correctly on Windows — valid UTF-8 previews use the Unicode console without changing candidate bytes or redirected output.
  57. A running attack can seek forward — press g; values through 100 mean percentage and larger values mean an exact one-based line/base position.

Download and run

Download the single shooter_hashcat-<version>-windows-x64-complete.7z asset from the latest release and extract it. The archive contains the complete tagged source and the already-built Windows x64 program.

Verify the package and check the version:

.\verify-windows-package.ps1
.\hashcat.exe --version

If a run reports an error, look for Error report saved to: in the console. Review that text file and send it with a short description of the problem; see Automatic error reports for privacy details and limitations.

Rebuild everything from the included source:

.\build-windows.ps1 -Action Rebuild

The first rebuild downloads a checksum-pinned MSYS2 compiler toolchain into the local .build-tools directory. Allow internet access and at least 5 GB of free disk space. Nothing is installed system-wide, and the system or user PATH is not changed. GPU vendor drivers remain an external requirement.

Tagged Windows releases are rebuilt on a clean GitHub runner. The release is published only after the executable version, archive layout, source manifest, and package-integrity checks pass. Separate CI jobs exercise static and shared Windows and Linux builds, Rust crates, and the sanitizer-backed parser fuzzer.

Technical details

Topic Documentation
Complete Shooter feature inventory docs/shooter-enhancements.md
Startup, memory, parsing, and sorting docs/startup-optimization.md
Large-wordlist indexing and feed speed wordlist I/O optimization
Existing --outfile-check-dir results before cracking outfile-check startup
RTX 4090 autotune cache RTX_4090_AUTOTUNE_CACHE.md
Multi-file combinations and complete-candidate rules docs/multi-file-combination.md and docs/whole-candidate-rules.md
Ordered component pipeline: attack mode 13 docs/multi-hybrid-mode13.md
Native PCFG training and attack feed docs/pcfg-attack.md
Final-candidate class requirements docs/candidate-requirements.md
Candidate methods 1-6 and implementation status docs/candidate-generation-roadmap.md
Runtime and checkpoint controls docs/runtime-controls.md and docs/checkpoint-control.md
Live forward seek by percentage or line docs/live-goto.md
Interactive status output consistent remaining and recovery-rate lines
Resumable candidate output docs/stdout-sessions.md
mdxfind modes docs/mdxfind-modules.md and the complete JSON registry
Windows builds how_to_compile.txt
Linux builds BUILD.md
Error reports and privacy docs/error-reports.md
Stage timing and peak memory docs/stage-profile.md
Sanitizers and parser fuzzing docs/security-testing.md
SBOM and signed release attestations docs/release-security.md
Every release and verification result CHANGELOG.md
Source comparison Feature origins and the complete Shooter delta from the merged upstream baseline

Upstream hashcat and license

General hashcat help is available from the Hashcat Wiki, --help, the Hashcat Forum, and Discord.

hashcat and the Shooter modifications are licensed under the MIT license. See docs/license.txt.

About

Hashcat fork with large-list optimizations, multibyte rules and masks, multi-GPU improvements, and additional hash modes.

Resources

Stars

4 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages