Pass-The-Hash (PtH)
You dumped an NTLM hash (via LSASS, Mimikatz, Responder).
Category: Active Directory · Kerberos & NTLM 🎯 Trench — You dumped an NTLM hash (via LSASS, Mimikatz, Responder). You don’t need to crack it: you present it to the server as if it were the password. 🔗 Kill chain — Prerequisite: any valid NTLM hash. Next: lateral movement via SMB/WinRM, escalation to Domain Admin if hash belongs to a privileged account. 📡 Defensive footprint — Event ID 4624 withLogon Type 9
(NewCredentials) on the DC. Mimikatz touches LSASS → instant
critical alert in 99% of modern EDRs.
⚠️ False friend — Running Mimikatz as downloaded. Static
signature is flagged by all AVs. Recompile, obfuscate or use
in-memory variants (reflective Invoke-Mimikatz).
🛡️ Remediation — Credential Guard, Protected Users group, LAPS
for local accounts, admin tier separation (Tier 0/1/2).
← Back to the full glossary Last updated: 2026-06-11