Case D4ED00 · Identity & AD · L2 Practitioner
Pass-the-Hash
Practise as: Explain it · Interview
Interview questionWhy can an attacker log in with a password hash without ever cracking it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- NTLM computes its challenge response from the NT hash alone (no password needed), so the hash is password-equivalent
- Hashes are harvested from LSASS memory or the SAM/NTDS.dit, e.g. with Mimikatz sekurlsa::logonpasswords
- Lateral movement via SMB/PsExec, WMI or WinRM using tools like Impacket or CrackMapExec with the hash
- Detect: 4624 Type 3 NTLM from odd sources; Mimikatz sekurlsa::pth (PtH or overpass) leaves 4624 Type 9 seclogo on the source
- Mitigate: LAPS for unique local admin passwords, Credential Guard, Protected Users, restrict NTLM, tiered admin
If the interviewer pushes back
- How does overpass-the-hash differ, and why does it produce Kerberos rather than NTLM traffic?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.