CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard

A tester has a curated wordlist of common passwords and wants hashcat to apply common human mutation patterns, such as appending digits or capitalizing the first letter, to each word without generating a new wordlist manually. Which hashcat configuration accomplishes this?

  1. AHybrid wordlist + mask attack (mode 6)
  2. BStraight attack (mode 0) with a rule file (-r)
  3. CCombinator attack (mode 1)
  4. DBrute-force mask attack (mode 3)
Show answer & explanation

Correct answer: B. Straight attack (mode 0) with a rule file (-r)

A straight attack (mode 0) combined with a rule file (-r) applies predefined mutation rules, such as appending numbers or capitalizing letters, to each word in the wordlist, exactly matching the described requirement.

Why the other options are wrong

  • A. Hybrid mode appends a mask to wordlist entries but doesn't apply general rule-based mutations.
  • C. Combinator attack concatenates two wordlists together, not apply mutation rules.
  • D. Mask attack brute-forces character positions, not existing wordlist mutation.

Hashcat Rule-Based Attack

A straight attack (mode 0) enhanced with a rules file (-r) that applies mutation patterns like case changes, appends, and character substitutions to wordlist entries.

  • Common rule files include best64.rule and rockyou-30000.rule
  • Greatly expands wordlist coverage without new files
  • Rules are plaintext scripts defining mutation functions

Memory trick: 'Straight Combines Brute Hybrids' = 0,1,3,6/7

More Vulnerability Discovery and Analysis questions