# NotSoSecure/password_cracking_rules

One rule to crack all passwords. or atleast we hope so.

Repository: https://github.com/NotSoSecure/password_cracking_rules
Canonical: https://ross.abutalabs.com/products/password_cracking_rules
License: MIT
License Family: permissive
Last push: 2021-12-09T03:33:52+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3380, "days_push": 1728, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1629, forks 295 (observed 2026-08-28T04:05:13.833924+00:00)

## What it is
A consolidated password cracking rules file for hashcat and John the Ripper, aggregating rules from sources like Hob0Rules, KoreLogic, NSAKEY, and hashcat. It is a supporting artifact for NotSoSecure's 'One Rule to Rule Them All' blog post on rule-based password attacks.

## Use cases
- crack password hashes with hashcat using a comprehensive rule set
- run rule-based dictionary attacks in penetration tests
- audit password strength of an organization
- recover forgotten passwords from hashes
- combine best-known cracking rules into one file

## When to choose
- you want a single well-tested rules file instead of assembling rules from multiple sources
- you are doing an authorized password audit or CTF and need broad rule coverage
- you want a good starting point for hashcat rule-based attacks

## When to avoid
- you need highly optimized, minimal rules for time-constrained attacks
- you need actively maintained rules with recent updates
- you are looking for a cracking tool itself rather than a rules file

## Facets
- artifact type: dataset
- maturity: maintenance
- function: security, penetration-testing
- domain: security, penetration-testing
- platform: cli, cross-platform
- tags: password-cracking, hashcat, rule-based-attacks, wordlist-rules, john-the-ripper

## Member repositories
- NotSoSecure/password_cracking_rules (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:13.833924+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:48:16.124189+00:00, confidence not recorded.
  - readme: https://github.com/NotSoSecure/password_cracking_rules (fetched 2026-08-28T04:05:13.833924+00:00, sha 35e5c6c401d4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
