PolycryptZero is a desktop hash-cracking tool. It combines a Python/CPU hashing path, an optional hashcat/GPU backend, a SQLite-backed rainbow table store, and a small ONNX transformer for generating password candidates.
gui
The application is presented as a compact desktop interface with separate views for the main cracking workflow and its supporting controls.
hash algorithm support
Two tiers are used depending on the algorithm and available backend.
native
MD5, MD4, SHA-1, SHA-224/256/384/512, SHA3-256/384/512, BLAKE2b, BLAKE2s, RIPEMD160, Whirlpool, SHAKE128-256, SHAKE256-512, and bcrypt.
hashcat-only
NTLM, LM, md5crypt, sha256crypt/sha512crypt, phpass, database formats, Django hashes, Kerberos, WPA-PBKDF2/PMKID, 7-Zip, RAR, ZIP, PDF, 1Password, macOS hashes, and other hashcat modes.
Hash identification tries prefix detection first, then hashcat --identify,
then a length-based fallback. The final fallback is heuristic and is not guaranteed
to uniquely identify an algorithm.
attack modes
| mode | description | backend |
|---|---|---|
| wordlist | Streams a file line-by-line and checks each candidate. | CPU / hashcat |
| brute-force | Exhaustive itertools.product over a selected charset and length range. | CPU / hashcat |
| rule-based | Transforms base words using prefixes, suffixes, case changes, numbers, symbols, and leet substitutions. | CPU / hashcat |
| probabilistic (AI) | Uses an ONNX transformer to generate password candidates token-by-token. | CPU / hashcat |
| rainbow table | Looks up hashes against locally stored precomputed tables. | SQLite |
bcrypt is deliberately kept on the native bcrypt path rather than routed
through hashcat.
rainbow tables
The rainbow table engine uses a small layered cache hierarchy:
- SQLite with WAL mode, page caching, and memory-mapped I/O
- Configurable Bloom filter to avoid unnecessary disk hits
- In-memory hot lookup cache
- Batched inserts
- Successful cracks feed back into the table automatically
probabilistic / AI mode
This mode runs a GPT-2-style autoregressive transformer exported to ONNX and samples candidates token-by-token rather than enumerating a combinatorial keyspace.
A seed keyword can prime generation. The generator runs in a bounded loop with periodic heartbeat updates so a slow model does not appear frozen.
gpu / hashcat backend
When hashcat is available, wordlist, brute-force, and rule-based attacks can be routed to it. Device selection can target a specific CUDA, OpenCL, HIP, or Metal device.
gpu
Forces hashcat and can warn when only an integrated GPU is detected.
cpu
Forces the native Python hashing path.
installation
option 1 — windows executable
Download the latest v2.0 release,
extract p0-Release-v2.0.7z, and run p0.exe.
The release includes the hashcat backend and the gpt2-passwordmodel directory.
option 2 — source
git clone https://github.com/serptail/p0-Password-Cracking-Tool.git
cd p0-Password-Cracking-Tool
pip install -r requirements.txt
python src/main.py
For source installs, hashcat must be installed separately and either placed in a folder
named hashcat beside the main script or available on PATH.
Python 3.11+
customtkinter
pycryptodome
numpy
onnxruntime
transformers
usage
- Paste the target hash and let p0 identify it, or select the algorithm manually.
- Choose an attack mode and configure its parameters.
- Select a backend: GPU or CPU.
- Start the job and monitor rate / ETA from the logs.
wordlists
The project release includes hashmob2025-medium.txt.
rockyou.txt is also supported.
probabilistic model
Point p0 at an exported ONNX model directory. The bundled gpt2-passwordmodel
works as-is. Custom causal-LM checkpoints can be exported with export_to_onnx.py.
roadmap
- better model architecture for the probabilistic engine
- linux release
- cuda-specific tuning for probabilistic mode
- less ambiguous hash-type detection
legal notice
PolycryptZero is intended for educational and personal use. Do not use it against accounts or systems without explicit permission. You are responsible for how you use it.
PolycryptZero™ and its logo are not covered by the open-source license and may not be reused in derivative projects or forks without permission.