Audit credentials. Recover passwords.
At GPU Speed.
Test password strength, audit credentials for your organization or your clients, and recover passwords you're authorized to access.
No tools to install. No GPUs to manage.
- Built for ethical security testing
- Free Basic Search
- Custom options
For data you own, or are authorized to test.
- Enterprises & Fortune 500
- Cybersecurity firms
- Penetration testers
- Law enforcement & DFIR
- Managed service providers
Submit a hash or a file
Basic Search is free either way. You'll create a free account before the search runs.
Uploaded files are deleted once their hash is extracted. Privacy policy.
Submit a hash or upload a file
Submit an authorized hash, or let us extract it from a supported file.
Hash or file
Prefer to keep your file local? Extract the hash yourself and submit only that.
Files deleted after extraction
Uploads are deleted as soon as the hash has been extracted.
Authorized use only
Built for responsible cybersecurity work. Every submission requires confirmation that you own the data or have permission to test it. Trust Center
- NTLM
- Kerberos
- bcrypt
- MD5 & SHA
- WPA/WPA2
- MS Office
- ZIP, RAR, 7z
- Crypto wallets
- See all 220 algorithms supported →
Put cloud GPUs to work
Start with a free Basic Search. For deeper testing, choose a paid job and review its price before it runs.
| Capability | Your own setup | OnlineHashCrack |
|---|---|---|
| Hash support | Install and configure your testing tools | 220 supported hashcat modes |
| Encrypted files | Set up extraction tools for your formats | Hash extraction from supported uploads |
| GPU hardware | Manage local hardware or cloud instances | Cloud GPUs managed for you |
| Search options | Configure and run your searches | Wordlists, rules, masks and targeted brute-force searches |
| While it runs | Allocate and monitor your compute resources | Keep your own resources available for other work |
| Getting started | Provide the hardware or pay for cloud compute | Free Basic Search; optional paid searches |
| Automation | Build and maintain your integration | Integrate through REST API + MCP |
Measured on our current GPU infrastructure, for an alphanum NTLM:
- 9 characters
- Under 30 minutes
- 10 characters
- Under 24 hours
Averages over searches that returned a result, on those character sets.
Recover access. Act on exposed passwords.
Restore access to your own data or turn audit findings into concrete security improvements.
If it's your own password
- Regain access to your document, archive, wallet or Wi-Fi network.
- Then change it. If we recovered it, it was not strong enough to keep.
- See for free whether it was found; unlock it only if it was.
If you're auditing credentials
- Identify recoverable passwords and investigate reuse across your authorized audit scope.
- Reset exposed credentials and address gaps in your password policy.
- Present recovery counts and test scope to your board or risk committee.
- Retest updated credentials after remediation.
- Give clients and internal reviewers documented evidence of the test and its findings.
Audit report available on request. Discuss your audit
Use the findings to support your security assessment and remediation planning. Document password testing as part of your review of authentication and access-control requirements under applicable frameworks:
- NIST SP 800-63B
- ISO/IEC 27001
- NIS2 EU
- DORA EU
- PCI DSS 4.0
- Cyber Essentials UK
- Essential Eight Australia
- MAS TRM Singapore
- APPI Japan
Use the documented scope, findings and remediation actions as evidence for applicable controls. The relevant requirements depend on your organization and assessment scope; a password audit alone does not establish compliance.
Does an unrecovered password mean it is secure?
No. It means the search did not recover it within the selected options and processing time. Use the findings alongside your password policy and other security checks.
Can you guarantee recovery or a completion time?
No. The typical times shown elsewhere on this site are results on our current infrastructure, not a guarantee for your case. Results depend on the password, the algorithm and the search options. A stronger password or a slower algorithm can require more processing without producing a result.
What is included in the free search?
Basic Search is free and tries common passwords and short candidate sets first, with no payment to start. If it recovers your password, unlocking the result is a separate, confirmed charge. If it does not, you can run a paid custom job with different wordlists, rules or a targeted bruteforce range. Review pricing before continuing.
Can I recover a file password instead of submitting hashes?
Yes. File password recovery is a separate starting point for encrypted documents, archives and Wi-Fi captures. Check the supported formats before preparing a file.
Try a free Basic Search
Create a free account to submit your data and start Basic Search at no charge.