{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/security-tooling/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["credential-access","tool","windows","security-tooling"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eHashcat is a widely used advanced password recovery tool that supports various hashing algorithms. In offensive operations, adversaries utilize Hashcat to crack password hashes extracted from compromised systems, such as SAM database exports or NTDS.dit files. Defenders must monitor for the execution of hashcat.exe, particularly when used in conjunction with command-line arguments specifying attack modes (-a), hash types (-m), or rule-based cracking files (-r). While legitimate security assessments and authorized penetration tests employ this tool, its presence on endpoints often signals active credential access or post-exploitation activity where an attacker has already successfully bypassed system-level protections to obtain credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful execution of Hashcat by unauthorized actors leads to the recovery of plaintext passwords, facilitating lateral movement, privilege escalation, and persistent access to the organization's network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect unauthorized Hashcat process creation events.\u003c/li\u003e\n\u003cli\u003eInvestigate any detected execution of hashcat.exe to determine if it aligns with authorized penetration testing or security assessment activity.\u003c/li\u003e\n\u003cli\u003eProactively secure sensitive credential stores such as the SAM registry hive and NTDS.dit file by implementing strict access control lists and monitoring for unauthorized file access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T11:06:25Z","date_published":"2026-09-01T11:06:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hashcat-execution/","summary":"Detection engineering brief regarding the use of the Hashcat password recovery tool in Windows environments, which is frequently used by adversaries for credential access via offline hash cracking.","title":"Detection of Hashcat Password Cracker Execution","url":"https://feed.craftedsignal.io/briefs/2026-09-hashcat-execution/"}],"language":"en","title":"CraftedSignal Threat Feed - Security-Tooling","version":"https://jsonfeed.org/version/1.1"}