NTLM Hash Generator

Generate the Windows NTLM (NT) hash of a string.

0 chars
Encoded as UTF-16LE
NTLM (NT hash) · 128 bits

Result will appear here...

NTLM Hash Generator

Compute the NTLM (NT) hash of a string the same way Windows derives it. The value is calculated in your browser and shown as 32 hexadecimal characters. The input is converted to UTF-16LE automatically, so the result matches the NT hash format used by Windows account databases and by security tools that work with them.

What is the NT hash?

The NT hash (commonly called the NTLM hash) is defined as MD4 of the UTF-16LE encoded input. It replaced the weak LM hash and is the value stored for local and domain accounts on modern Windows. Because it is unsalted and fast, two accounts with the same password have identical NT hashes — a property that makes it useful for auditing but also means it should be handled carefully.

For example, the NT hash of an empty string is 31d6cfe0d16ae931b73c59d7e0c089c0.

Common uses

  • Security auditing and testing – reproducing NT hashes to compare against values recovered from a system you administer, or to confirm that accounts do not share weak or blank credentials.
  • Interoperability – tools such as Hashcat (mode 1000) and John the Ripper use this exact format, so generating a known value here helps verify a lab or test setup.
  • Learning – understanding how Windows derives account hashes from the MD4 building block.

Features

  • Automatic UTF-16LE encoding of the input
  • File input for hashing raw bytes when needed
  • Hex, uppercase, or Base64 output
  • Compare with a known hash to check a value in one step

The NT hash is built on MD4 — see the MD4 Hash Generator for the underlying algorithm. For strong general-purpose hashing use the SHA256 Hash Generator, and for password storage a slow algorithm such as bcrypt is appropriate; see the WordPress Password Hash Generator.

Frequently Asked Questions

The input is encoded as UTF-16 little-endian (two bytes per character) and the MD4 digest of those bytes is taken. There is no salt, so the same input always produces the same 32-character hexadecimal value.

31d6cfe0d16ae931b73c59d7e0c089c0. Administrators sometimes use this well-known value to spot blank credentials during a security audit.

No. The much older LM hash uppercases the input, splits it into two 7-character halves, and uses DES. The NT hash produced here is based on MD4 and is the value modern Windows systems store; LM storage is disabled by default on current Windows versions.

NTLM hashes the UTF-16LE encoding, while a plain MD4 tool usually hashes UTF-8 bytes. That different byte layout produces a different digest even for the same characters.