Compare software

John the Ripper vs hashcat: catalog facts
John the Ripperhashcat

Best for: Auditing passwords, especially in hash formats that other tools do not support

Best for: Auditing how quickly the password hashes in your own systems can be recovered

Free

Free and open source under the GPL, with some components under a relaxed variant.

Free

Free and open source under the MIT licence.

Windows, macOS, Linux, Command line Windows, macOS, Linux, Command line
  • The jumbo build supports hundreds of hash and cipher types, including many obscure ones
  • Runs on a very wide range of platforms including old and unusual ones
All 4 strengths for John the Ripper
  • The jumbo build supports hundreds of hash and cipher types, including many obscure ones
  • Runs on a very wide range of platforms including old and unusual ones
  • Strong rule-based and incremental attack modes, not just dictionaries
  • Packaged by every major distribution plus Homebrew, Flathub and Snap
  • Over 590 hash modes and ten attack modes, including masks and rule-based mutation
  • CUDA, HIP, Metal and OpenCL backends, with mixed device types in one system
All 4 strengths for hashcat
  • Over 590 hash modes and ten attack modes, including masks and rule-based mutation
  • CUDA, HIP, Metal and OpenCL backends, with mixed device types in one system
  • Named sessions with restore after interruption, and a thermal watchdog
  • Keyboard layout mapping for disk encryption passwords typed on a non-US keyboard
  • The project states jumbo has low quality requirements and that bugs are to be expected
  • GPU support is weaker than hashcat's for the common hash types
All 4 limitations for John the Ripper
  • The project states jumbo has low quality requirements and that bugs are to be expected
  • GPU support is weaker than hashcat's for the common hash types
  • Command line only, with a substantial learning curve
  • Only legitimate against systems you are authorised to test
  • Only legitimate against hashes you are authorised to test
  • Needs a capable GPU to be useful; CPU-only cracking is slow
All 4 limitations for hashcat
  • Only legitimate against hashes you are authorised to test
  • Needs a capable GPU to be useful; CPU-only cracking is slow
  • Command line with a large option surface and a real learning curve
  • Driver and backend setup is frequently the hardest part
Downloadable app Downloadable app
Open source Open source
License: GPL-2.0 License: MIT
No account needed No account needed
Offline features available Offline features available
Sources for John the Ripper

Catalog checked September 21, 2026

Sources for hashcat

Catalog checked September 21, 2026

“Not stated” means we have not confirmed it. Features can vary by device and plan.