Extract high‑probability Hashcat rules by analyzing transformation patterns between base and target wordlists. Four‑phase GPU extraction, built‑in seed families (A–M), Token‑Strip pre‑pass (Phase 0), Genetic Algorithm (Phase 3), functional minimization, and a new CELF‑based greedy coverage selector — now shipped as a clean, testable Python package.
Rulest replaces naive BFS chaining with a GPU‑first four‑phase extraction engine. Given a base wordlist (source) and a target wordlist (dictionary), it reverse‑engineers the Hashcat rules that transform base words into target words — using OpenCL parallelism, a VRAM Bloom filter, four distinct extraction phases, and an optional Genetic Algorithm for deep‑chain discovery.
The result is a production‑ready .rule file, minimized via signature‑based functional deduplication. 100% compatible with Hashcat’s GPU engine (max 31 ops, no rejection rules). An optional Phase 0 Token‑Strip CPU pre‑pass reverse‑engineers exact chains from target passwords using 14 extraction modes before any GPU work begins.
v3 keeps every Stage 0–3 behavior identical to v2 in its default mode, but splits the old 210 kB single‑file engine into a proper rulest/ package and adds an optional post‑processing selector: Coverage Evaluation + Greedy CELF Selection, which orders and trims rules by real, verified marginal password recovery instead of raw GPU hit count.
--genetic) with 2× novelty bonus for new chains, 20% time reservation, stagnation guard, and tournament selection + crossover + mutation.--token-strip) with 14 extraction modes and multiprocessing. Reverse‑engineers exact rule chains from target passwords; singles → Phase 1; chains → Phase S + Phase 2.--genetic) with 2× novelty bonus, dedicated 20% time reservation (min 120s), stagnation guard, tournament selection + crossover + mutation.rulest/selection.py, new in v3)--select-mode frequency (default, identical to v2) or --select-mode greedy for CELF marginal‑coverage selection against the real target, with optional --select-budget/--select-budgets and --select-cost-alpha.Disabled with --no-builtin-seeds. These seeds run as a dedicated phase and are also forwarded to Phase 2 as scaffolding for deeper chains.
The original 210 kB single‑file rulest_v2.py engine has been split into a clean, testable Python package. Behavior of Stages 0–3 and frequency‑based output remains identical to v2 in the default selection mode.
rulest/state.pyrulest/common.pyrulest/minimize.pyrulest/token_strip.pyrulest/devices.pyrulest/kernel_source.pyrulest/gpu_engine.pyrulest/gpu_worker.pyrulest/multi_gpu.pyrulest/genetic.pyrulest/extractor.pyrulest/selection.pyrulest/cli.pyrun_rulest.pyRulest v3 integrates seamlessly with the A1131 ecosystem:
.rule file, ordered by frequency (default) or by CELF greedy coverage selection.--select-mode greedy instead of the default frequency ordering.
--list-devices, --device index/name--depth2-chains … --depth10-chains)OpenCL 1.2+ GPU (NVIDIA, AMD, Intel). CPU fallback supported but slow. Unit tests included under tests/ — install requirements-dev.txt and run pytest.
Output includes header with total candidates, minimization stats, and per‑depth rule counts. Sorted by GPU hit frequency (default) or by CELF marginal coverage (--select-mode greedy).
--select-mode {frequency,greedy}frequency (default): sort by raw GPU hit count, identical to v2 behaviour. greedy: CELF marginal‑coverage selection against the real target.--select-budget N--select-budgets LIST64,250,1500,10000,25000,50000,150000. Emits extra files <output>.<budget>.txt cut from the same ordering.--select-cost-alpha Again(r) = new_recovery / depth(r)**A. 0 = pure marginal coverage (default); >0 favours shorter/cheaper chains.--exact-recoveryv3 is a drop‑in upgrade for all users: same GPU engine, same Stages 0–3, same default output — now organized as a package, plus an optional smarter rule selector for anyone who wants tighter, more diverse rulesets.
rulest/ packagerulest_v2.py is now 15 focused modules plus a run_rulest.py entry point, with unit tests under tests/.rulest/selection.py--select-mode, --select-budget(s), --select-cost-alpha, and --exact-recovery.--select-mode frequency (default) produces the same ordering and output format as rulest_v2.py.--select-mode greedy when you want CELF marginal‑coverage ordering against the real target instead of raw frequency.run_rulest.py instead of rulest_v2.py. All existing flags (--max-depth, --target-hours, --bloom-mb, etc.) behave identically to v2.