CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard

A tester extracted a large set of NTLM password hashes from a compromised domain controller during vulnerability validation. To efficiently crack as many hashes as possible by leveraging known corporate password patterns (e.g., 'Company2024!'), which hashcat attack configuration would be MOST effective as a first pass?

  1. AA combinator attack merging two large generic wordlists (-a 1)
  2. BA pure brute-force attack across the full character set (-a 3)
  3. CA straight dictionary attack with a rule file (-a 0 -r rules.rule)
  4. DAn association attack tied to username fields (-a 9)
Show answer & explanation

Correct answer: C. A straight dictionary attack with a rule file (-a 0 -r rules.rule)

A dictionary attack combined with rule-based mangling (-a 0 -r) efficiently generates common variations (capitalization, appended numbers/symbols) of known password patterns, making it far faster and more targeted than brute-forcing the entire keyspace. Combinator and association attacks serve different, less efficient purposes for this specific goal.

Why the other options are wrong

  • A. Combinator attacks concatenate two wordlists together, not ideal for pattern-based mutations like capitalization/appending symbols.
  • B. Brute-force across the full charset is exhaustive but extremely slow for long/complex passwords.
  • D. Association attacks link candidate passwords to specific hash metadata (e.g., usernames), not general pattern cracking.

Hashcat Attack Modes

Hashcat supports multiple attack modes (-a) that define how candidate passwords are generated to match hashes, ranging from dictionary-based to brute-force approaches.

  • -a 0: straight dictionary attack
  • -a 3: brute-force/mask attack
  • -a 0 -r applies rule files to mutate dictionary words efficiently

Memory trick: Straight beats Brute for known Patterns; Combinator combines, Association links

More Vulnerability Discovery and Analysis questions