CAPEC 644 Use of Captured Hashes (Pass The Hash)

Stable Detailed Medium Risk
Severity High

Description

An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols.

Attack Execution Flow

5

Mitigations

5

Consequences

Indicators

5

Relationships

Related ATT&CK Techniques

1

Resources Required

1