offensive-tools/cracking/john/SKILL.md
Auth/lab ref: CPU-based password cracker supporting hundreds of hash formats with wordlist, rules, and incremental modes.
npx skillsauth add aeondave/malskill johnInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
CPU password cracker — hundreds of hash formats, wordlist + rules + incremental.
# Auto-detect format and crack
john hashes.txt --wordlist=/usr/share/wordlists/rockyou.txt
# Show cracked passwords
john hashes.txt --show
# Single crack mode (fast, username-based)
john hashes.txt --single
# Incremental (brute-force)
john hashes.txt --incremental
| Flag | Purpose |
|------|---------|
| --wordlist=FILE | Dictionary attack |
| --rules[=RULE] | Apply mangling rules |
| --format=TYPE | Force hash format |
| --single | Single crack (username hints) |
| --incremental | Brute-force |
| --show | Display cracked passwords |
| --pot=FILE | Custom pot file |
| --fork=N | Parallel processes |
| --list=formats | List all formats |
NTLM with rules:
john ntlm.txt --format=NT --wordlist=rockyou.txt --rules=best64
SSH private key:
ssh2john id_rsa > id_rsa.hash
john id_rsa.hash --wordlist=rockyou.txt
Zip archive:
zip2john archive.zip > zip.hash
john zip.hash --wordlist=rockyou.txt
PDF:
pdf2john document.pdf > pdf.hash
john pdf.hash --wordlist=rockyou.txt
KeePass database:
keepass2john database.kdbx > kp.hash
john kp.hash --wordlist=rockyou.txt
Office documents (docx/xlsx):
office2john document.docx > office.hash
john office.hash --wordlist=rockyou.txt
7-Zip:
7z2john archive.7z > 7z.hash
john 7z.hash --wordlist=rockyou.txt
# Named session
john hashes.txt --wordlist=rockyou.txt --session=mysession
# Resume
john --restore=mysession
# Check status of running session (send USR1 signal or press 'q')
john --status=mysession
# Fork N processes (uses all CPU cores)
john hashes.txt --wordlist=rockyou.txt --fork=4
[List.Rules:MyRules]
# Append year variants
Az"[0-9][0-9][0-9][0-9]"
# Capitalize first + append !
c Az"!"
# l33t substitutions
sa@ se3 si1 so0
john hashes.txt --wordlist=rockyou.txt --rules=MyRules
| File | When to load |
|------|--------------|
| references/formats-and-rules.md | Supported format names, *2john tool list, rule syntax reference |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.