Skip to main content

Pass-The-Hash (PtH)

You dumped an NTLM hash (via LSASS, Mimikatz, Responder).

Category: Active Directory · Kerberos & NTLM 🎯 Trench — You dumped an NTLM hash (via LSASS, Mimikatz, Responder). You don’t need to crack it: you present it to the server as if it were the password. 🔗 Kill chain — Prerequisite: any valid NTLM hash. Next: lateral movement via SMB/WinRM, escalation to Domain Admin if hash belongs to a privileged account. 📡 Defensive footprint — Event ID 4624 with Logon Type 9 (NewCredentials) on the DC. Mimikatz touches LSASS → instant critical alert in 99% of modern EDRs. ⚠️ False friend — Running Mimikatz as downloaded. Static signature is flagged by all AVs. Recompile, obfuscate or use in-memory variants (reflective Invoke-Mimikatz). 🛡️ Remediation — Credential Guard, Protected Users group, LAPS for local accounts, admin tier separation (Tier 0/1/2).
Back to the full glossary Last updated: 2026-06-11