During an internal penetration test, you gain access to a Windows workstation and discover that a domain user's password hash is cached in the registry. You extract the hash and want to crack it offline. Which Hashcat mode should you use to attack the cached domain credential?
MSCache v2 hashes are stored in the registry under SECURITY\Cache and are used for offline domain logon. Hashcat mode 2100 is specifically designed to crack these Domain Cached Credentials 2 hashes. Since the scenario involves a cached domain credential from a workstation, mode 2100 is the correct mode to use for offline cracking.
Why this answer
Cached domain credentials are stored as MSCache v2 hashes in the SECURITY registry hive. Hashcat mode 2100 is purpose-built to crack these hashes offline. Other modes target different hash types such as NTLM, LM, or NetNTLMv2, which are not applicable here.
Using the correct mode ensures efficient and successful cracking of the cached credential.
Exam trap
The trap here is confusing cached domain credentials with NTLM hashes stored in the SAM database, leading to the selection of an incorrect Hashcat mode.