Password attacks are a fundamental part of penetration testing, red teaming, Active Directory assessments, and CTFs. Whether you’re solving Hack The Box machines, tackling ProLabs, or performing real-world engagements, credentials are often the fastest path to deeper access.
Finding usernames or password hashes is only the beginning. The next challenge is figuring out the most effective way to turn them into valid credentials.
Depending on the target environment, you may need to answer questions like:
- What type of hash is this?
- Which Hashcat mode should I use?
- Should I use Hashcat or John the Ripper?
- Is password spraying a better option than brute forcing?
- How do I safely spray passwords without locking accounts?
- Can I generate a target-specific wordlist?
- What are the common default credentials?
- Which services should I test for credential reuse?
- How do I enumerate valid domain users?
- Which wordlists should I start with?
That’s why the Practical Hacking Cheatsheet Series includes a dedicated:
Password Attacks Cheat Sheet
This cheatsheet is designed as a clean, practical reference for the password attack techniques most commonly encountered during HTB machines, CTFs, ProLabs, Active Directory labs, and penetration tests. Rather than collecting random commands from different sources, it brings together the tools and workflows you’ll use most when attacking credentials.
The full Password Attacks Cheat Sheet covers topics like:
- Hash identification
- Common Hashcat modes
- Hashcat attacks and rules
- John the Ripper
- Password cracking workflows
- Hydra brute forcing
- NetExec password spraying
- Kerbrute user enumeration
- Kerbrute password spraying
- Wordlist generation with CeWL
- Crunch pattern-based wordlists
- CUPP custom wordlists
- Username generation
- Hashcat rule files
- Common default credentials
- Useful SecLists wordlists
- Credential reuse methodology
- Online and offline password attacks
This cheatsheet is especially useful when you’ve discovered usernames, password hashes, or exposed authentication services and need a structured approach to recovering valid credentials.
For example:
- What hash type am I looking at?
- Which Hashcat mode should I use?
- How do I crack NTLM or bcrypt hashes?
- When should I use John the Ripper instead of Hashcat?
- How do I spray passwords against Active Directory?
- How do I enumerate valid users?
- How do I build a custom wordlist for a target?
- Which default credentials should I try first?
- How do I test for credential reuse across services?
- Which wordlists are worth using before brute forcing?
The main idea is simple: successful password attacks rely far more on good methodology than blindly throwing massive wordlists at a target. In many real-world environments, weak passwords, password reuse, default credentials, poor naming conventions, and targeted wordlists are far more effective than noisy brute-force attacks. This cheatsheet brings together the commands, tools, and techniques you need into a single practical reference.
Full Cheatsheet Series
This is the complete Practical Hacking Cheatsheet Series:
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →| Cheatsheet | Focus |
|---|---|
| Active Directory | AD attack methodology and commands |
| Web Application | Web exploitation techniques and payloads |
| Linux Privilege Escalation | Linux privilege escalation vectors |
| Windows Privilege Escalation | Windows privilege escalation vectors |
| Reverse Shells | Reverse shell one-liners and shell upgrades |
| File Transfers | Methods to transfer files between machines |
| Pivoting | SSH tunneling, Chisel, Ligolo, SOCKS |
| Password Attacks | Cracking, spraying, and brute-forcing techniques |
| Linux Enumeration | Post-exploitation Linux enumeration |
| Windows Enumeration | Post-exploitation Windows enumeration |
Each cheatsheet is designed to be practical, concise, and easy to reference while solving machines, conducting penetration tests, or preparing for certifications like OSCP, CPTS, PNPT, and CRTO.
Who This Is For
This cheatsheet series is made for:
- Hack The Box players
- CTF enthusiasts
- ProLab students
- Beginner and intermediate penetration testers
- Red team operators
- OSCP, CPTS, PNPT, and CRTO students
- Active Directory learners
- Cybersecurity students
- Anyone building a practical offensive security knowledge base
If you’re regularly assessing systems or solving labs, this Password Attacks Cheat Sheet gives you a practical reference for identifying hashes, cracking passwords, spraying credentials, generating effective wordlists, and testing credential reuse without constantly searching for commands.
One subscription.
Every cheatsheet, forever.
Get the full Password Attacks Cheatsheet now — plus every new part of the Practical Hacking Series as it drops, and access to additional series too. No waiting. No separate purchases.









