CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A tester has a wordlist of common passwords but wants to automatically generate mutated variations, such as appending '123', capitalizing the first letter, and substituting 'a' with '@', without manually typing every possible combination. Which hashcat attack mode should the tester use?

  1. ARule-based attack (-r)
  2. BMask attack (-a 3)
  3. CBrute-force attack (-a 3 with full charset)
  4. DCombinator attack (-a 1)
Show answer & explanation

Correct answer: A. Rule-based attack (-r)

A rule-based attack applies transformation rules (append, prepend, capitalize, character substitution) defined in a rule file to a base wordlist, dramatically expanding coverage without manually enumerating every variation.

Why the other options are wrong

  • B. A mask attack defines a fixed character pattern per position, not wordlist mutation.
  • C. A full brute-force attack tries every possible character combination and does not use a wordlist.
  • D. A combinator attack concatenates two wordlists together, not applying transformation rules.

Hashcat Rule-Based Attack

A hashcat attack mode (-r) that applies a set of transformation rules to each word in a wordlist to generate mutated password candidates.

  • Rules can append, prepend, capitalize, and substitute characters
  • Greatly expands wordlist coverage without a larger dictionary
  • Common rule files include best64.rule and rockyou-30000.rule

Memory trick: Rules reshape the words like clay into new forms.

More Attacks and Exploits questions