Clever pentesters don't run the raw 100GB file. Instead, they use the passwords from RockYou2021 combined with hashcat rules ( best64.rule or rockyou-30000.rule ). This expands coverage to 95% of user passwords while keeping compute time manageable.

: See which "hashed" passwords can be cracked quickly with consumer-grade hardware like an RTX 3080.