CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester has a wordlist of common passwords but wants to automatically generate mutated variations, such as appending '123', capitalizing the first letter, and substituting 'a' with '@', without manually typing every possible combination. Which hashcat attack mode should the tester use?
- ARule-based attack (-r)
- BMask attack (-a 3)
- CBrute-force attack (-a 3 with full charset)
- DCombinator attack (-a 1)
Show answer & explanationAnswer & explanation
Correct answer: A. Rule-based attack (-r)
A rule-based attack applies transformation rules (append, prepend, capitalize, character substitution) defined in a rule file to a base wordlist, dramatically expanding coverage without manually enumerating every variation.
Why the other options are wrong
- B. A mask attack defines a fixed character pattern per position, not wordlist mutation.
- C. A full brute-force attack tries every possible character combination and does not use a wordlist.
- D. A combinator attack concatenates two wordlists together, not applying transformation rules.
Hashcat Rule-Based Attack
A hashcat attack mode (-r) that applies a set of transformation rules to each word in a wordlist to generate mutated password candidates.
- Rules can append, prepend, capitalize, and substitute characters
- Greatly expands wordlist coverage without a larger dictionary
- Common rule files include best64.rule and rockyou-30000.rule
Memory trick: Rules reshape the words like clay into new forms.