NTLM Hash Generator

See how Windows turns a password into an NT hash: MD4 of the password encoded as UTF-16LE. Use it with test passwords to understand the format, check a lab setup or verify your own tooling, and read below why this legacy format needs strong protection.

What is an NTLM hash?

What most people call the “NTLM hash” is properly the NT hash: the value Windows derives from a user’s password and stores instead of the password itself. It is defined very simply. The password is encoded as UTF-16 little-endian (two bytes per character for most text) and then hashed with MD4, producing 128 bits, usually shown as 32 uppercase hex characters. There is no salt and no iteration count.

Test passwordNT hash
(empty)31D6CFE0D16AE931B73C59D7E0C089C0
password8846F7EAEE8FB117AD06BDD830B7586C

These values appear in Microsoft documentation and security training, and the tool reproduces them. The empty-password hash in particular is worth recognizing, because seeing it in an audit means an account has no password.

How to use this tool

  1. Type a test password. The NT hash appears immediately, together with the number of UTF-16LE bytes that were hashed.
  2. Choose uppercase hex (the usual Windows style) or lowercase.
  3. Paste a value into the compare box to check that your own script, lab environment or migration tool produces the same result.

Everything runs locally in your browser. Even so, as a general habit, never type a real, in-use password into any website. For other algorithms, including MD4 on arbitrary text and files, use the full hash generator.

Where Windows uses the NT hash

Local accounts keep their NT hashes in the Security Account Manager (SAM) database, and Active Directory domain controllers keep them for every domain account. The NTLM family of authentication protocols (NTLMv1 and NTLMv2) uses the NT hash as the secret key in a challenge–response exchange, so a client proves it knows the hash rather than sending the password. Modern domains prefer Kerberos, and NTLM remains mainly as a fallback for older systems, workgroup machines and applications that were never updated. Microsoft has announced that NTLM is deprecated and is removing the oldest version, NTLMv1, from new Windows releases.

An even older format, the LAN Manager (LM) hash, uppercased passwords and split them into 7-character halves. It has been disabled by default since Windows Vista and Windows Server 2008. If you still see LM hashes stored anywhere, that is a finding to fix.

Why the NT hash is weak

How to protect Windows accounts

If you administer Windows systems, these widely recommended measures reduce the risk from NT hashes:

Don’t use NT hashes in new designs

If you are building an application, never store passwords as NT hashes, MD5 or SHA-256. Use a slow, salted password hash such as Argon2id or bcrypt; you can experiment with bcrypt in the bcrypt generator. The only reason to compute an NT hash today is compatibility with existing Windows systems: testing, migrations, lab work and learning how the format works.

Common questions about the encoding

The NT hash is computed over UTF-16LE bytes, not UTF-8, so the same password gives a different hash here than in an ordinary MD4 tool that hashes UTF-8. Passwords are case-sensitive, and every character counts, including trailing spaces. Characters outside the Basic Multilingual Plane, such as many emoji, take four bytes in UTF-16 (a surrogate pair), and the tool encodes them the same way Windows does.

Frequently asked questions

How is an NTLM hash calculated?

The NT hash, often called the NTLM hash, is MD4 applied to the password encoded as UTF-16 little-endian. There is no salt and no iteration, and the result is usually written as 32 uppercase hex characters.

Why is NTLM considered insecure?

The NT hash is unsalted and very fast to compute, so weak passwords are easy to recover if hashes leak, and the hash itself can be used to authenticate over NTLM. Microsoft has deprecated NTLM in favor of Kerberos.

Is the NTLM hash the same as MD4?

It is MD4, but of the UTF-16LE form of the password. An MD4 tool that hashes UTF-8 text will give a different result for the same password.

Is it safe to type a password here?

The hash is calculated in your browser and nothing is sent anywhere. Still, as a habit, use test passwords rather than real ones on any website.

What is the difference between LM and NT hashes?

The LM hash is an older, much weaker format that uppercases the password and splits it into 7-character halves. It has been disabled by default since Windows Vista. The NT hash replaced it.

Should I use NTLM hashes to store passwords in my app?

No. Use a slow, salted password hash such as Argon2id or bcrypt. NT hashes are only useful for compatibility with existing Windows systems.