Identify An Unknown Hash By Length And Format
Paste a hash string from a leaked database, a config file, or a pentest dump and this tool ranks the most likely algorithms by length, character set, and structural prefix — entirely in your browser, nothing is sent anywhere.
How the analyzer scores a hash
There is no byte inside a raw digest that records which algorithm produced it, so identification is always probabilistic. This tool combines three signals into a confidence score for each candidate algorithm.
1. Length match. After stripping whitespace, the tool counts characters. Most unsalted hashes are fixed width: MD5 and NTLM are 32 hex chars, SHA-1 is 40, SHA-224 is 56, SHA-256 is 64, SHA-384 is 96, and SHA-512 is 128. An exact length match scores the full base weight; in loose mode a length within ±0 still required but the alphabet test relaxes.
2. Character set. The tool classifies the string as hexadecimal ([0-9a-f]), Base64-ish ([A-Za-z0-9+/=]), or structured (contains $ or :). A hex-only string rules out Base64 schemes like bcrypt, and vice versa.
3. Structural prefix. Modern password hashes are self-describing using Modular Crypt Format. Prefixes such as $2a$, $2b$, $2y$ mean bcrypt, $argon2id$ means Argon2, $6$ is SHA-512-crypt, $1$ is MD5-crypt, and $y$ is yescrypt. A recognised prefix forces a near-certain match regardless of length.
The final score is computed as score = lengthHit ? base : 0, then multiplied by an alphabet factor (1.0 for a matching charset, 0.55 for a mismatch in loose mode, 0 in strict mode), and overridden to 0.99 when a known crypt prefix is detected. Candidates are sorted descending and the top N are shown as a percentage. Because many algorithms share a width — MD5, MD4, MD2, NTLM and double-MD5 are all 32 hex chars — the tool deliberately lists collisions rather than guessing one, which is the honest answer a real triage step needs.