Open cardosec

Case D4ED00 · Identity & AD · L2 Practitioner

Pass-the-Hash

Practise as: Explain it · Interview

Interview questionWhy can an attacker log in with a password hash without ever cracking it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. NTLM computes its challenge response from the NT hash alone (no password needed), so the hash is password-equivalent
  2. Hashes are harvested from LSASS memory or the SAM/NTDS.dit, e.g. with Mimikatz sekurlsa::logonpasswords
  3. Lateral movement via SMB/PsExec, WMI or WinRM using tools like Impacket or CrackMapExec with the hash
  4. Detect: 4624 Type 3 NTLM from odd sources; Mimikatz sekurlsa::pth (PtH or overpass) leaves 4624 Type 9 seclogo on the source
  5. Mitigate: LAPS for unique local admin passwords, Credential Guard, Protected Users, restrict NTLM, tiered admin

If the interviewer pushes back

  • How does overpass-the-hash differ, and why does it produce Kerberos rather than NTLM traffic?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.