NTLM Hash Generator
Generate the Windows NTLM (NT) hash of a string.
NTLM (NT hash) · 128 bits
Result will appear here...
NTLM Hash Generator
Compute the NTLM (NT) hash of a string the same way Windows derives it. The value is calculated in your browser and shown as 32 hexadecimal characters. The input is converted to UTF-16LE automatically, so the result matches the NT hash format used by Windows account databases and by security tools that work with them.
What is the NT hash?
The NT hash (commonly called the NTLM hash) is defined as MD4 of the UTF-16LE encoded input. It replaced the weak LM hash and is the value stored for local and domain accounts on modern Windows. Because it is unsalted and fast, two accounts with the same password have identical NT hashes — a property that makes it useful for auditing but also means it should be handled carefully.
For example, the NT hash of an empty string is 31d6cfe0d16ae931b73c59d7e0c089c0.
Common uses
- Security auditing and testing – reproducing NT hashes to compare against values recovered from a system you administer, or to confirm that accounts do not share weak or blank credentials.
- Interoperability – tools such as Hashcat (mode 1000) and John the Ripper use this exact format, so generating a known value here helps verify a lab or test setup.
- Learning – understanding how Windows derives account hashes from the MD4 building block.
Features
- Automatic UTF-16LE encoding of the input
- File input for hashing raw bytes when needed
- Hex, uppercase, or Base64 output
- Compare with a known hash to check a value in one step
Related tools
The NT hash is built on MD4 — see the MD4 Hash Generator for the underlying algorithm. For strong general-purpose hashing use the SHA256 Hash Generator, and for password storage a slow algorithm such as bcrypt is appropriate; see the WordPress Password Hash Generator.
Frequently Asked Questions
How is an NTLM hash calculated?
The input is encoded as UTF-16 little-endian (two bytes per character) and the MD4 digest of those bytes is taken. There is no salt, so the same input always produces the same 32-character hexadecimal value.
What is the NTLM hash of an empty string?
31d6cfe0d16ae931b73c59d7e0c089c0. Administrators sometimes use this well-known value to spot blank credentials during a security audit.
Is the NTLM hash the same as the LM hash?
No. The much older LM hash uppercases the input, splits it into two 7-character halves, and uses DES. The NT hash produced here is based on MD4 and is the value modern Windows systems store; LM storage is disabled by default on current Windows versions.
Why does my NTLM value differ from a plain MD4 hash?
NTLM hashes the UTF-16LE encoding, while a plain MD4 tool usually hashes UTF-8 bytes. That different byte layout produces a different digest even for the same characters.