Legal Cyber Academy
ToolFreeCurrent

Hashcat and John the Ripper

hashcat project; Openwall · Hashcat 7 · 2026

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The two standard open-source password recovery tools. Hashcat is GPU-driven and supports a very wide range of hash and container formats with dictionary, rule, mask, and hybrid attacks. John the Ripper, from Openwall, has broader format coverage in its jumbo build and a large set of extraction utilities that pull hashes out of files and containers. Both remain actively developed.

Who it is for, and when

In forensics these are the tools for getting into encrypted containers, protected archives, and credential stores when lawful authority exists but the passphrase does not: BitLocker and VeraCrypt volumes, password-protected Office and PDF files, keychains, and cached credentials. John's *2john extraction scripts are usually how you get from an evidence file to a hash line at all, and Hashcat is usually where you do the actual work because of GPU throughput. Both are also used defensively to demonstrate how weak a disputed password actually was.

What it does not cover

Neither breaks properly implemented modern cryptography — success depends entirely on the password being guessable and the key derivation being weak or the iteration count low, and a strong passphrase on a current container is not recoverable in any useful time. They provide no evidence handling, no case record, and no legal authority; running them on data you are not authorised to decrypt is the problem, not the tool. Results are also easy to misstate in a report, since a recovered password says nothing about who set or knew it.

Go to the source

Open at hashcat.net (opens in a new tab)

https://hashcat.net/wiki/

Details

Type
Tool
Written for
Working examinerAdvancedWorking examiner, Advanced
Publisher
hashcat project; Openwall
Version verified
Hashcat 7
Year
2026
Topics
password-recovery, encryption, open-source, validation
Checked at source
  • A browser-based tool published by GCHQ that chains together hundreds of data operations — encodings, ciphers, compression, hashing, timestamp conversion, parsing, and extraction — into a visible recipe. It runs entirely client-side and is actively released.

  • An open-source cross-platform GUI for creating, browsing, querying, and editing SQLite and SQLCipher databases, with a spreadsheet-like table view and a full SQL editor. Point releases are infrequent but the repository remains active and nightly builds are published.

  • An open-source library and tool set for the Expert Witness Compression Format (E01/Ex01), including ewfacquire to create images, ewfverify to check their integrity hashes, ewfinfo to read the metadata, and ewfmount to expose an image as a raw device. The repository remains actively maintained.

  • Sigma

    Free

    An open, structured YAML format for describing detections in log data, plus a community rule repository and the pySigma/sigma-cli tooling that converts a rule into the query language of a particular SIEM or log platform. The rule repository is actively released by SigmaHQ.

  • The annual meeting of the American Academy of Forensic Sciences, a multidisciplinary body of over 6,500 members organised into twelve sections, one of which is Digital & Multimedia Sciences. The 79th Annual Scientific Conference is scheduled for 15-20 February 2027 at the Rosen Shingle Creek Hotel in Orlando, Florida.