What is an NTLM hash?
What most people call the “NTLM hash” is properly the NT hash: the value Windows derives from a user’s password and stores instead of the password itself. It is defined very simply. The password is encoded as UTF-16 little-endian (two bytes per character for most text) and then hashed with MD4, producing 128 bits, usually shown as 32 uppercase hex characters. There is no salt and no iteration count.
| Test password | NT hash |
|---|---|
| (empty) | 31D6CFE0D16AE931B73C59D7E0C089C0 |
password | 8846F7EAEE8FB117AD06BDD830B7586C |
These values appear in Microsoft documentation and security training, and the tool reproduces them. The empty-password hash in particular is worth recognizing, because seeing it in an audit means an account has no password.
How to use this tool
- Type a test password. The NT hash appears immediately, together with the number of UTF-16LE bytes that were hashed.
- Choose uppercase hex (the usual Windows style) or lowercase.
- Paste a value into the compare box to check that your own script, lab environment or migration tool produces the same result.
Everything runs locally in your browser. Even so, as a general habit, never type a real, in-use password into any website. For other algorithms, including MD4 on arbitrary text and files, use the full hash generator.
Where Windows uses the NT hash
Local accounts keep their NT hashes in the Security Account Manager (SAM) database, and Active Directory domain controllers keep them for every domain account. The NTLM family of authentication protocols (NTLMv1 and NTLMv2) uses the NT hash as the secret key in a challenge–response exchange, so a client proves it knows the hash rather than sending the password. Modern domains prefer Kerberos, and NTLM remains mainly as a fallback for older systems, workgroup machines and applications that were never updated. Microsoft has announced that NTLM is deprecated and is removing the oldest version, NTLMv1, from new Windows releases.
An even older format, the LAN Manager (LM) hash, uppercased passwords and split them into 7-character halves. It has been disabled by default since Windows Vista and Windows Server 2008. If you still see LM hashes stored anywhere, that is a finding to fix.
Why the NT hash is weak
- No salt. The same password always produces the same NT hash, on every machine and in every organization. Identical hashes reveal shared passwords, and precomputed tables work against every account at once.
- Very fast. MD4 was built for speed. Modern password storage deliberately uses slow, memory-hard functions such as Argon2id or bcrypt; the NT hash has none of that protection, so weak passwords fall quickly if the hashes leak.
- MD4 itself is broken. MD4 collisions are trivial to create. That matters less for passwords than speed and the missing salt, but it means the format has no security margin left.
- The hash works like the password. Because NTLM authentication proves knowledge of the hash, not the password, a stolen NT hash can be enough to sign in to other systems that accept NTLM. This class of attack is known as pass-the-hash, and it is why NT hashes must be protected as carefully as plain-text passwords.
How to protect Windows accounts
If you administer Windows systems, these widely recommended measures reduce the risk from NT hashes:
- Reduce and then disable NTLM. Audit where NTLM is still used, move those systems to Kerberos, and use the “Restrict NTLM” group policies to block it step by step.
- Turn on Credential Guard and other built-in credential protections so secrets are harder to extract from memory.
- Use unique local administrator passwords, for example with Windows LAPS, so one machine’s hash does not unlock every other machine.
- Separate administrative accounts and only use privileged accounts on hardened admin workstations.
- Require long passphrases and MFA, and check passwords against lists of known breached passwords.
- Enable SMB signing and extended protection to block relay attacks against NTLM authentication.
Don’t use NT hashes in new designs
If you are building an application, never store passwords as NT hashes, MD5 or SHA-256. Use a slow, salted password hash such as Argon2id or bcrypt; you can experiment with bcrypt in the bcrypt generator. The only reason to compute an NT hash today is compatibility with existing Windows systems: testing, migrations, lab work and learning how the format works.
Common questions about the encoding
The NT hash is computed over UTF-16LE bytes, not UTF-8, so the same password gives a different hash here than in an ordinary MD4 tool that hashes UTF-8. Passwords are case-sensitive, and every character counts, including trailing spaces. Characters outside the Basic Multilingual Plane, such as many emoji, take four bytes in UTF-16 (a surrogate pair), and the tool encodes them the same way Windows does.
Frequently asked questions
How is an NTLM hash calculated?
The NT hash, often called the NTLM hash, is MD4 applied to the password encoded as UTF-16 little-endian. There is no salt and no iteration, and the result is usually written as 32 uppercase hex characters.
Why is NTLM considered insecure?
The NT hash is unsalted and very fast to compute, so weak passwords are easy to recover if hashes leak, and the hash itself can be used to authenticate over NTLM. Microsoft has deprecated NTLM in favor of Kerberos.
Is the NTLM hash the same as MD4?
It is MD4, but of the UTF-16LE form of the password. An MD4 tool that hashes UTF-8 text will give a different result for the same password.
Is it safe to type a password here?
The hash is calculated in your browser and nothing is sent anywhere. Still, as a habit, use test passwords rather than real ones on any website.
What is the difference between LM and NT hashes?
The LM hash is an older, much weaker format that uppercases the password and splits it into 7-character halves. It has been disabled by default since Windows Vista. The NT hash replaced it.
Should I use NTLM hashes to store passwords in my app?
No. Use a slow, salted password hash such as Argon2id or bcrypt. NT hashes are only useful for compatibility with existing Windows systems.