- Probabilistic Context-Free Grammar (PCFG) password generator - Pure Go Edition
- pcfg-go is a Pure Go rewrite of the Python3 pcfg_cracker
- The goal of this Go implementation is to provide a substantial performance improvement for both trainer and guesser over the original Python3 version, while also adding features such as supporting
$HEX[]input and multi-byte character support — which is not implemented in the Pure C pcfg_guesser - Credits for the original python3 pcfg_cracker belong to the author @lakiw
- Rules trained by
pcfg_trainerare compatible with hashcat's new PCFG-a 4attack mode. See the hashcat PCFG implementation commit for details.
pcfg_trainer:
go install -ldflags="-s -w" github.com/cyclone-github/pcfg-go/cmd/pcfg_trainer@mainpcfg_guesser:
go install -ldflags="-s -w" github.com/cyclone-github/pcfg-go/cmd/pcfg_guesser@main- Performance — ~53.94× faster
pcfg_trainerand ~12.16× fasterpcfg_guesservs Python 3 (see Benchmarks below) - $HEX[] input — Trainer accepts
$HEX[...]encoded passwords in the training wordlist (multi-byte support) - Ctrl+C handling — Pressing Ctrl+C auto-saves the session in
pcfg_guesser - Multi-keyboard layouts — QWERTY, AZERTY, QWERTZ, Dvorak, JCUKEN (Russian Cyrillic)
- Expanded TLD list — Legacy TLDs, ccTLDs, gTLDs (
.info,.xyz,.app,.dev, etc.), and short TLDs (.co,.io,.ai,.me,.gg); improves both website and email detection - Improved website detection — Broader URL/prefix detection (
http://,https://,www., etc.) and host extraction - Multi-threaded architecture —
pcfg_guesseris multi-threaded for increased performance - Compiled binary — No fuss; pcfg-go uses compiled binaries for speed and easy deployment
Python3 trainer: 13m21s (801s)Go pcfg_trainer: 14.85s- Speedup: ~53.94×
Python3 pcfg_guesser: 195.5sGo pcfg_guesser: 16.08s- Speedup: ~12.16×
Train a new ruleset from wordlist:
pcfg_trainer -r rule_name -t wordlist.txtGenerate guesses from a trained ruleset:
pcfg_guesser -r rule_nameSession save/restore:
pcfg_guesser -r rule_name -s my_session # save to my_session.sav on exit
pcfg_guesser -r rule_name -s my_session -l # load and resumePress Ctrl+C to save session and exit.
pcfg_guesser -r rule_name -s my_session | hashcat -m 0 hashes.txt...hashcat -m 0 -a 4 hashes.txt path_to_pcfg_rule_dir ...pcfg_trainer
pcfg-go vs pcfg-python3 flags
| Go | Python3 | Description |
|---|---|---|
| -r | --rule | Ruleset name |
| -t | --training | Training wordlist (required) |
| -e | --encoding | File encoding |
| -C | --comments | Config comments |
| -S | --save_sensitive | Save emails, URLs |
| -p | --prefixcount | Lines prefixed with count |
| -n | --ngram | OMEN ngram size (2-5) |
| -a | --alphabet | Alphabet size for Markov |
| -c | --coverage | PCFG vs OMEN coverage |
| -m | --multiword | Pre-train multiword file |
| -h | --help | Help |
| -version | --version | Version info |
pcfg_guesser
pcfg-go vs pcfg-python3 flags
| Go | Python3 | Description |
|---|---|---|
| -r | --rule | Ruleset name |
| -s | --session | Session name |
| -l | --load | Load previous session |
| -n | --limit | Max guesses |
| -b | --skip_brute | Skip OMEN/Markov |
| -a | --all_lower | No case mangling |
| -d | --debug | Debug output |
| -h | --help | Help |
| -version | --version | Version info |
Requires Go and Git.
git clone https://github.com/cyclone-github/pcfg-go.git
cd pcfg-go
go mod tidy
mkdir -p bin
go build -ldflags="-s -w" -o bin/pcfg_trainer ./cmd/pcfg_trainer
go build -ldflags="-s -w" -o bin/pcfg_guesser ./cmd/pcfg_guesserInstall to $GOPATH/bin:
go install -ldflags="-s -w" ./cmd/pcfg_trainer
go install -ldflags="-s -w" ./cmd/pcfg_guesser