Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-644 — Use of Captured Hashes (Pass The Hash)
CAPEC-644

Use of Captured Hashes (Pass The Hash)

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols.

Mitigation

Prevent the use of Lan Man and NT Lan Man authentication on severs and apply patch KB2871997 to Windows 7 and higher systems. | Leverage multi-factor authentication for all authentication services and prior to granting an entity access to the domain network. | Monitor system and domain logs for abnormal credential access. | Create a strong password policy and ensure that your system enforces this policy. | Leverage system penetration testing and other defense in depth methods to determine vulnerable systems within a domain.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.