Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0409 — Detection Strategy for T1550.002 - Pass the Hash (Windows)
DET0409

Detection Strategy for T1550.002 - Pass the Hash (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1144 Analytic 1144
Windows

Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Security EventCode=4768 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=1
[TimeWindow] Allows tuning the correlation timeframe between authentication, session creation, and process/network activity.
[SourceAccountAnomalyThreshold] Supports tuning detection sensitivity based on deviations from normal user login patterns or usage context.
[LogonTypeFilter] Allows focusing detection on specific logon types (e.g., LogonType 3 for network logon, Type 10 for RDP).

Detected Techniques

1

Lateral Movement (1)

Details

MITRE ID
DET0409
STIX ID
x-mitre-detection-strategy--5692084b-878d-44f7-8b38-a3d125894845
Analytics
1
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.