shooter_hashcat is a Windows-focused version of hashcat 7.1.2. It keeps the
normal hashcat commands and features, then adds faster handling of very large
hash and rule lists, better multi-GPU behavior, more ways to build password
candidates, multibyte masks and rules on Windows, additional hash types, and a
ready-to-run release. If an error occurs, it also creates one support file that
can be reviewed and sent with a bug report.
It was developed for a Windows machine with 12 NVIDIA GeForce RTX 4090 GPUs, but most of its additions also work on other hardware.
Use this software only on passwords and systems you own or are explicitly authorized to audit.
This public inventory lists changes maintained by Shooter relative to the official upstream hashcat commit merged into this branch. Features inherited from official hashcat are intentionally excluded. Every item links to a plain-language explanation.
- Huge hash lists parse across CPU cores — less time waiting at
Parsing Hashes. - Huge unsalted hash lists sort across CPU cores — preprocessing finishes sooner.
- The 12-GPU system skips unnecessary backend scans — short jobs begin faster.
- Multiple GPUs start and stop concurrently — devices no longer wait on one-at-a-time setup.
- The 12-GPU system uses much less host memory — measured staging fell from about 97.7 GB to 36.7 GB.
- RTX 4090 tuning is saved and reused — matching jobs can skip repeated tuning.
- Blowfish kernels can be reused — supported Blowfish modes avoid needless recompilation.
- Large cracked-result sets write much faster — outfile and potfile results are batched safely.
- Attack mode 1 joins three or more wordlists — no fixed three-to-six-file attack modes are needed.
- Multi-GPU combination attacks seek directly to each GPU's work — later GPUs do not replay earlier combinations.
- Rules can modify the complete candidate — supported in attack modes 1, 3, 6, and 7; mode 13 instead applies rules at their ordered pipeline position.
--stdoutrule generation uses multiple CPU cores — up to 64 workers retain deterministic order.--stdoutjobs can pause, checkpoint, and restore — file output resumes at the exact byte boundary.- Multibyte masks work on Windows — literals such as
№survive the command line. - Multibyte rules work on Windows — rule files and inline rules accept UTF-8 literals.
- A running time limit can be extended or shortened — adjust
--runtimewithout restarting. - Multi-GPU checkpoints keep every GPU coordinated — checkpoint cancellation safely resumes all devices.
- CUDA startup failures retry without dropping GPUs — a failed device cannot silently produce a partial-GPU run.
- Temporarily locked output files are retried — brief Windows locks do not immediately lose results.
[i]gnore outfilestops directory checking — stop checking--outfile-check-dirfor the current run without changing the directory.- Outfile-check-only cracks are labeled clearly — the final status identifies where the result came from.
- Loopback induction files clean up safely on Windows — consumed files are not rediscovered forever.
- Quit shows shutdown progress — the console explains what hashcat is still finishing.
- The final summary shows total run time —
Total Run Timeis calculated from start and stop timestamps. - Combination status shows the correct wordlist paths — ruled mode-1 jobs no longer show
(null). - Pure Kernel selection is highlighted — interactive status displays the line in yellow.
- The complete mdxfind
e1-e1001namespace is available — 999 standalone algorithms plus two documented special entries. - mdxfind names appear consistently throughout hashcat — help, status, benchmarks, and logs show public
eNnames. - mdxfind
e987accepts Magento Argon2 input — original Magento lines remain intact in output and potfiles. - Modes 29950 and 29951 handle phpBB3 legacy rehashes — the complete two-stage hashes run on the GPU.
- Mode 29980 adds the supported gost-yescrypt profile — handles libxcrypt-style
$gy$j9T$hashes. - Mode 67000 restores legacy yescrypt numbering — old jobs use the maintained mode-36100 implementation.
- One
.7zcontains both source and a ready-to-run build — download one file to run or rebuild Shooter. - Release contents can be verified locally — an included script checks the complete SHA-256 manifest.
- Windows builds bootstrap with one command — the compiler toolchain stays inside the repository.
- Fresh clones build from any drive — no machine-specific absolute paths are required.
- Release versions are reproducible — tags, packages, rebuilds, and
--versionstay identical. - Huge rule files load across CPU cores — all rule-capable algorithms spend less time waiting at
Loading rules. Restore.Substatus lines are optional — they stay hidden unless--status-restore-subis requested.- Prebuilt releases run on standard x64 CPUs — release binaries do not inherit the GitHub runner's CPU-only instructions.
--showand--leftfinish faster on huge lists — large potfiles use narrower lookups, and-ojobs skip a redundant full-result copy and sort.- Shooter's mdxfind bridge builds on Linux — the added bridge links in both static and shared Linux builds.
- Errors are saved in one support file — the file records recent warnings, every normal error, later warnings, and the details needed to investigate the problem.
- Parser bugs are hunted automatically — scheduled sanitizer and coverage-guided fuzz tests retain crash inputs.
- Pipeline time and peak RAM can be measured — opt-in human and JSON reports show where a run spent its time.
- Releases include an SBOM and signed attestations — verify archive contents, provenance, and the software inventory.
- Existing outfile results are removed before cracking starts — if every hash is already in
--outfile-check-dir, the expensive attack-specific GPU and host-memory allocation is skipped. - Huge wordlists index and feed faster — first-use line counting uses the CPU cores and ordinary candidates reach the GPUs with less per-word overhead.
- Remaining hashes and recovery rates are always visible — every normal status display includes
RemainingandRecovered/Time, even for small hash lists, with live minute values from the first status update. - Attacks can explain where their time went — opt-in
--task-time-breakdownoutput separates preparation, cracking, and cleanup, then itemizes hash loading, sorting, potfile/outfile checks, rules, GPU setup, self-test, and autotune. - Full status appears at both ends of an attack — the same human-readable page as interactive
sprints once before cracking workers start and again when the attack completes. - Attack mode 13 runs an ordered component pipeline — any number of wordlists, masks, and rule stages run left-to-right in the exact order entered.
- All-rejected optimized input retries with the pure kernel — when
-Oparser limits reject every supplied hash, the complete session is rebuilt once without-O. - PCFG candidates run through a native deterministic feed — train a probability-ordered grammar, then run it as
-a 8 pcfg MODELwith keyspace, rules, restore, and multi-GPU distribution. - Final candidates can require character classes — independent, default-off upper/lower/digit/symbol minimums are checked after supported rules and complete mode-13 pipelines.
- Multibyte candidates display correctly on Windows — valid UTF-8 previews use the Unicode console without changing candidate bytes or redirected output.
- A running attack can seek forward — press
g; values through 100 mean percentage and larger values mean an exact one-based line/base position.
Download the single shooter_hashcat-<version>-windows-x64-complete.7z asset from the
latest release
and extract it. The archive contains the complete tagged source and the
already-built Windows x64 program.
Verify the package and check the version:
.\verify-windows-package.ps1
.\hashcat.exe --versionIf a run reports an error, look for Error report saved to: in the console.
Review that text file and send it with a short description of the problem; see
Automatic error reports for privacy details and
limitations.
Rebuild everything from the included source:
.\build-windows.ps1 -Action RebuildThe first rebuild downloads a checksum-pinned MSYS2 compiler toolchain into
the local .build-tools directory. Allow internet access and at least 5 GB of
free disk space. Nothing is installed system-wide, and the system or user
PATH is not changed. GPU vendor drivers remain an external requirement.
Tagged Windows releases are rebuilt on a clean GitHub runner. The release is published only after the executable version, archive layout, source manifest, and package-integrity checks pass. Separate CI jobs exercise static and shared Windows and Linux builds, Rust crates, and the sanitizer-backed parser fuzzer.
| Topic | Documentation |
|---|---|
| Complete Shooter feature inventory | docs/shooter-enhancements.md |
| Startup, memory, parsing, and sorting | docs/startup-optimization.md |
| Large-wordlist indexing and feed speed | wordlist I/O optimization |
Existing --outfile-check-dir results before cracking |
outfile-check startup |
| RTX 4090 autotune cache | RTX_4090_AUTOTUNE_CACHE.md |
| Multi-file combinations and complete-candidate rules | docs/multi-file-combination.md and docs/whole-candidate-rules.md |
| Ordered component pipeline: attack mode 13 | docs/multi-hybrid-mode13.md |
| Native PCFG training and attack feed | docs/pcfg-attack.md |
| Final-candidate class requirements | docs/candidate-requirements.md |
| Candidate methods 1-6 and implementation status | docs/candidate-generation-roadmap.md |
| Runtime and checkpoint controls | docs/runtime-controls.md and docs/checkpoint-control.md |
| Live forward seek by percentage or line | docs/live-goto.md |
| Interactive status output | consistent remaining and recovery-rate lines |
| Resumable candidate output | docs/stdout-sessions.md |
| mdxfind modes | docs/mdxfind-modules.md and the complete JSON registry |
| Windows builds | how_to_compile.txt |
| Linux builds | BUILD.md |
| Error reports and privacy | docs/error-reports.md |
| Stage timing and peak memory | docs/stage-profile.md |
| Sanitizers and parser fuzzing | docs/security-testing.md |
| SBOM and signed release attestations | docs/release-security.md |
| Every release and verification result | CHANGELOG.md |
| Source comparison | Feature origins and the complete Shooter delta from the merged upstream baseline |
General hashcat help is available from the Hashcat Wiki,
--help, the
Hashcat Forum, and
Discord.
hashcat and the Shooter modifications are licensed under the MIT license. See docs/license.txt.