Credentials & Identity

Pass-the-Hash

A stolen password hash is used directly for authentication without recovering the plaintext.

AdvancedWindowsActive DirectorySMBNTLM
PRIMARY MAPPINGT1550.002

Defense Evasion / Lateral Movement

01
CONCEPT

What is it?

Pass-the-Hash abuses protocols that accept proof derived from an NTLM password hash. A stolen hash can authenticate to compatible remote services without cracking or knowing the original password.

ALSO KNOWN ASPtH
02
MENTAL MODEL

How it works in plain English

Use this three-part model to understand the attack without memorizing a tool name.

01 / TRUST BEING ABUSED

The system accepts a credential, token, ticket, recovery decision, or identity assertion as proof of who the requester is.

02 / ATTACKER ACTION

The attacker obtains, guesses, forges, replays, or changes that authentication material.

03 / DEFENDER VIEW

Focus on how the identity was acquired, where it was used, what device and network context changed, and what happened immediately after success.

Worked example: how the sequence may look

01 / Starting condition

An NTLM hash for a valid account.

02 / Attacker action

Present the stolen hash through an NTLM exchange.

03 / Observable evidence

4624 Logon Type 3 with NTLM and 4776 validation events.

04 / Detection decision

Baseline NTLM and investigate privileged network logons from rare sources.

05 / Possible outcome

If successful, the attacker may continue with Remote Services. This is a possibility, not a guaranteed next step.

This is a defensive learning scenario. Real incidents vary, and the listed outcome is only one possible path.

03
ATTACKER OBJECTIVE

Why do attackers use it?

  • Move laterally with credential material recovered from a host.

  • Avoid the time and cost of cracking.

  • Reuse identical privileged local-account hashes across systems.

  • Access SMB and NTLM-capable management services.

04
REQUIRED CONDITIONS

Prerequisites

  • An NTLM hash for a valid account.

  • A target service that permits NTLM.

  • Network access and account rights on the target.

  • Often, administrative access on one host to obtain the hash.

05
ATTACK CHAIN

Attack path possibilities

Attack chains are not fixed. These links show common possibilities to investigate before and after this behavior.

06
SEQUENCE

Step-by-step attack flow

01

Compromise an endpoint and obtain credential material.

02

Identify reachable systems and useful accounts.

03

Present the stolen hash through an NTLM exchange.

04

The target validates the response without plaintext.

05

Access shares, management services, or continue lateral movement.

07
FRAMEWORK

MITRE ATT&CK mapping

TECHNIQUET1550.002
NAMEPass-the-Hash
TACTICDefense Evasion / Lateral Movement
VERIFY ON MITRE ↗

ATT&CK is updated over time. Verify the live technique before operationalizing a detection.

08
EVIDENCE

Logs and artifacts

  • 4624 Logon Type 3 with NTLM and 4776 validation events.

  • Remote service creation 7045/4697, tasks, WMI, SMB, or WinRM activity.

  • Suspicious access to LSASS or local security databases on the source.

  • Privileged logons from workstations that do not normally originate them.

09
RAW TELEMETRY

Realistic log examples

REPRESENTATIVE, SANITIZED EXAMPLES

These records use realistic field names and formats but synthetic organizations, users, addresses, and identifiers. A single event is not proof; correlate time, identity, source, target, and the resulting action.

LOG SOURCEWindows Security — Event 4625

Failed authentication; useful for guessing, spraying, exposed remote services, and account targeting.

2026-07-16T14:22:31Z EventID=4625 Computer=DC01.corp.example
TargetUserName=j.singh TargetDomainName=CORP LogonType=3
AuthenticationPackageName=NTLM WorkstationName=WKSTN-442
IpAddress=203.0.113.48 IpPort=51842
Status=0xC000006D SubStatus=0xC000006A FailureReason="Unknown user name or bad password"
HOW TO INTERPRET IT FOR PASS-THE-HASH

Baseline NTLM and investigate privileged network logons from rare sources.

LOG SOURCEMicrosoft Entra — SigninLogs

Cloud sign-in context including identity, application, source, result, device, and conditional access.

2026-07-16T14:24:51Z UserPrincipalName=j.singh@corp.example
AppDisplayName="Office 365 Exchange Online" IPAddress=203.0.113.48
ResultType=50126 ResultDescription="Invalid username or password"
ClientAppUsed=Browser ConditionalAccessStatus=notApplied
DeviceDetail.operatingSystem=Windows Location=SG
HOW TO INTERPRET IT FOR PASS-THE-HASH

Correlate credential dumping on one host with NTLM logons to another.

LOG SOURCELinux auth.log / sshd

Remote authentication and PAM outcome with source address and account.

Jul 16 14:22:33 web02 sshd[24817]: Failed password for invalid user backup
from 203.0.113.48 port 51842 ssh2
Jul 16 14:22:37 web02 sshd[24817]: Failed password for deploy
from 203.0.113.48 port 51842 ssh2
HOW TO INTERPRET IT FOR PASS-THE-HASH

Detect local administrators authenticating to many hosts rapidly.

READ EACH LOG WITH FIVE QUESTIONS
  1. Who or what identity acted?
  2. From which device, process, IP, or workload?
  3. What target and operation were involved?
  4. Did it fail, succeed, or change state?
  5. What correlated event happened immediately before and after?
10
ANALYTICS

Detection logic / SIEM queries

  • Baseline NTLM and investigate privileged network logons from rare sources.

  • Correlate credential dumping on one host with NTLM logons to another.

  • Detect local administrators authenticating to many hosts rapidly.

  • Monitor administrative shares and remote services after NTLM logons.

KQLSuspicious NTLM network logon
SecurityEvent
| where EventID == 4624 and LogonType == 3
| where AuthenticationPackageName =~ "NTLM"
| summarize Targets=dcount(Computer), TargetList=make_set(Computer, 20)
    by Account, IpAddress, bin(TimeGenerated, 30m)
| where Targets >= 3
11
HARDENING

Mitigations

  • Reduce and disable NTLM where compatibility permits.

  • Use Credential Guard and protected LSASS.

  • Deploy unique local administrator passwords with Windows LAPS.

  • Restrict administrative logon paths and segment management networks.

  • Keep privileged identities off lower-trust systems.

12
IN THE WILD

Real-world examples

  • It is a common Active Directory lateral-movement technique.

  • Ransomware operators have reused local administrator hashes across Windows fleets.

  • APT1 was documented using tooling capable of Pass-the-Hash.

13
REVIEW

Common questions

01What makes Pass-the-Hash possible?

A trust assumption fails: an identity, input, component, network message, user decision, or software relationship is accepted without enough verification.

02What should a defender collect first?

Start with logs closest to the decision point, then add identity, endpoint, network, and control-plane context.

03How should I study this attack?

Learn the concept, identify prerequisites, map observable steps, write a detection hypothesis, and validate it safely in a lab.

Primary verification sources