Maximum-throughput PKZIP password recovery for a dedicated NVIDIA GeForce RTX 2080 Ti.
PKZIP Overdrive is a focused Python launcher for Hashcat. It validates the GPU, isolates CUDA to one RTX 2080 Ti, selects a supported PKZIP mode, applies maximum-performance workload settings, maintains resumable sessions, and shows Hashcat's aggregate speed and progress counter every 10 seconds.
Use this software only with archives you own or are explicitly authorized to recover.
- CUDA-only execution on one 11 GB RTX 2080 Ti
- Hashcat workload profile 4 with automatic kernel tuning
- No CPU/OpenCL hashing, leaving Windows responsive
- Aggregate speed, progress, temperature, utilization, and ETA updates
- Interactive maximum-length prompt capped at 10; every run starts at length 1
- Interactive ZIP path/directory prompt with automatic
zip2johnhash extraction and mode selection - Resumable sessions and a shared potfile
- 88°C emergency temperature cutoff
- Two-stage keyboard stop: press
Esctwice to stop cleanly - Prominent recovered-password display with an Enter prompt before closing
- PKZIP modes 17200, 17210, 17220, 17225, and 17230
Test system:
- NVIDIA GeForce RTX 2080 Ti, 11,264 MiB
- NVIDIA driver 591.86
- CUDA Toolkit 13.1
- Hashcat 7.1.2
| Hashcat mode | Workload | Measured speed | Candidates/minute |
|---|---|---|---|
| 17220, PKZIP compressed multi-file | Synthetic benchmark | 11.1402 GH/s | 668.412 billion |
Actual speed varies with PKZIP mode, member size, compression method, thermals, and attack shape. Benchmark results are not a guarantee for every archive.
Ensure Hashcat and zip2john are on PATH, then run from PowerShell:
python .\pkzip_overdrive.pyRunning without arguments starts the complete guided flow. The launcher first finds valid saved checkpoints and lets you resume one or start a new attack. New attacks prompt for a checkpoint name; pressing Enter uses a Windows-safe timestamp such as pkzip_2026-07-16_14-30-00. It then asks for the ZIP path, attack method, and wordlist or maximum length. You can also paste a directory: its only ZIP is selected automatically, or the launcher displays a numbered choice when several ZIPs are present. Surrounding quotes and paths containing spaces or parentheses are accepted.
Custom checkpoint names may use letters, digits, dots, underscores, and dashes.
Names that Windows reserves for devices, such as CON, NUL, COM1, and
LPT1, are rejected, including when they have an extension.
The startup checkpoint manager supports:
- Enter a checkpoint number to resume it.
- Enter
P, then its number, to preview the ZIP/source path, attack type, latest attempted/total count and percentage, speed, attempts per minute, ETA, queue, mask, and checkpoint location. - Enter
D, then its number, to delete its.restorecheckpoint after typingDELETE. Other session logs and results are retained, and deletion is blocked while Hashcat is running. - Enter
0or press Enter to start a new attack.
New sessions save their source and latest status in session-info.json after every Hashcat status update. Checkpoints created by older launcher versions can still expose their attack mode, current mask, and restore-position percentage, but their original ZIP path displays as not recorded.
The launcher reads ZIP metadata, selects a compact encrypted member, creates the PKZIP hash with zip2john, infers mode 17200 or 17210, and asks you to choose a dictionary or brute-force attack.
| Attack | Interactive flow |
|---|---|
| Dictionary | Paste a wordlist file/directory; a directory with multiple wordlists displays a numbered choice |
| Brute force | Select a maximum length from 1 through 10; every length from 1 through that selection is tested |
For automation, provide both values explicitly:
python .\pkzip_overdrive.py start "C:\path with spaces\archive.zip" --attack brute --max-length 7python .\pkzip_overdrive.py start "C:\path with spaces\archive.zip" --attack dictionary --wordlist "C:\wordlists\rockyou.txt"Use --hashcat C:\path\to\hashcat.exe when Hashcat is not on PATH. Session data defaults to %LOCALAPPDATA%\hashcat-rtx2080ti on Windows.
The launcher prints the generated session name at startup. Do not run multiple Hashcat processes against the same GPU; they contend for compute and VRAM and normally reduce total throughput.
- Press
Esconce to arm termination. - Press
Escagain to stop Hashcat and preserve its restore checkpoint. - Pressing a native Hashcat command after the first
Esccancels double-Esc termination and forwards the command. - When a password is recovered, Hashcat stops, PKZIP Overdrive displays it, and the console waits for Enter before closing.
- Whenever Hashcat exits, the launcher prints the absolute
.restorecheckpoint path and an exact resume command. It also writes those details tocheckpoint-info.txtin the session directory. - The latest ZIP path and aggregate progress are persisted to
session-info.jsonfor the next startup preview.
| Key | Action |
|---|---|
s or Enter |
Show status immediately |
p / r |
Pause / resume |
b |
Bypass the current wordlist/mask and advance to the next queued attack |
c |
Toggle stopping at the next restore checkpoint |
f |
Toggle finishing the current wordlist/mask before stopping |
q |
Quit Hashcat cleanly |
Hashcat's Progress value is the total number of candidates attempted across all active device workers. Speed.#01, Speed.#02, and so on are per-device rates; Speed.#* is the combined rate.
Replace SESSION_NAME with the session printed at startup:
python .\pkzip_overdrive.py restore SESSION_NAMEpython .\pkzip_overdrive.py benchmark --mode 17220The regression suite uses only the Python standard library and exercises the launcher parsers, checkpoint metadata, protected hash extraction, exact merge, deduplication, cancellation, and failure cleanup:
python -m unittest discover -s tests -v
python .\wordlist_merger_gpu.py --self-test| Value | Hashcat mask | Contents |
|---|---|---|
ascii |
?a |
Printable ASCII |
alnum |
custom ?1 |
Lowercase, uppercase, digits |
lower |
?l |
Lowercase letters |
digits |
?d |
Decimal digits |
Large masks grow exponentially. Narrow the character set and length range whenever you know anything about the password format.
The repository also includes an interactive Windows wordlist merger. It opens %USERPROFILE%\Downloads\lists, lists the .txt files with checkboxes, and writes the selected files to a user-chosen output.
Launch it by double-clicking Launch Wordlist Merger.cmd, or from Command Prompt:
"Launch Wordlist Merger.cmd"Two merge modes are available:
| Mode | Behavior |
|---|---|
| GPU dedupe | Uses the RTX 2080 Ti CUDA helper to generate 128-bit line fingerprints, preserves first-seen order, removes duplicate lines, and optionally skips blank lines |
| Exact combine | Uses large buffered disk I/O and preserves every input line; this is the fastest path when deduplication is not needed |
Raw file copying is limited by storage throughput, so the GPU is used only for the line-hashing work it can accelerate. GPU dedupe refuses to compete with an active Hashcat process; Exact combine remains available while Hashcat is running.
The prebuilt wordlist_gpu_hash.dll targets the RTX 2080 Ti's sm_75 architecture. To rebuild it locally, install the CUDA Toolkit and Visual Studio C++ tools, then run Build Wordlist GPU Helper.cmd.
The launcher records startup and error details in wordlist_merger_crash.log. If startup fails, its console remains open and displays the same traceback. Source wordlists are never modified, and an output file is replaced only after a successful merge.
- Windows 10 or 11
- Exactly one NVIDIA GeForce RTX 2080 Ti with 11 GB VRAM
- A compatible NVIDIA driver and CUDA Toolkit
- Python 3.10 or newer
- Hashcat 7.1.2
- John the Ripper's
zip2johnexecutable for direct ZIP input (or an existing$pkzip$/$pkzip2$hash file)
See CONTRIBUTING.md for development checks, native Windows and CUDA verification, pull-request expectations, and recovery-data handling. Report vulnerabilities privately using SECURITY.md; never place real archives, hashes, wordlists, recovered passwords, or unredacted logs in a public issue.
The source and compiled project files in this repository are licensed under
GNU Affero General Public License v3.0 only
(AGPL-3.0-only). See
LICENSE for the complete terms.
For alternative licensing, custom builds, and support, visit austenjgreen.com.
Hashcat, NVIDIA CUDA, and John the Ripper/zip2john are third-party projects
governed by their respective licenses. They are not distributed as part of
this repository.