NTLMv2 Password Cracking
Siege T.V.

Pass-The-Hash (PtH) Attack

A Pass-The-Hash (PtH) attack is a sophisticated cybersecurity threat that targets Windows-based networks and exploits weaknesses in the authentication process. Here’s a summary of a Pass-The-Hash attack on a Windows Domain:

  1. Objective: The primary goal of a Pass-The-Hash attack is to gain unauthorised access to a Windows Domain by using hashed credentials (password hashes) rather than the actual plaintext passwords. This attack is particularly dangerous because it doesn’t require knowledge of the actual passwords.
  2. Authentication Process: In a typical Windows Domain environment, when a user logs in, their password is hashed and compared to the stored password hash in the security database (like the NTDS.dit file on a domain controller). If the hashes match, the user gains access.
  3. Attacker’s Method: To perform a PtH attack, an attacker first needs to obtain the password hash of a legitimate user. This can be achieved through various means, including malware, phishing, or exploiting vulnerabilities on a compromised system.
  4. Pass-the-Hash Attack Steps:
    • Hash Extraction: The attacker extracts the password hash (NTLM hash) of a user from a compromised system or network.
    • Hash Injection: The attacker uses the stolen hash to authenticate themselves to other systems or services within the Windows Domain. They “pass” the stolen hash instead of the actual password. 
    • Lateral Movement: Once authenticated on one system, the attacker can move laterally through the network, leveraging the compromised account’s privileges to access more sensitive resources.
  5. Avoiding Detection: PtH attacks can be challenging to detect because they don’t involve the transmission of plaintext passwords, making them less visible in network traffic. Traditional intrusion detection systems may struggle to identify these attacks.
  6. Mitigation and Prevention: To defend against Pass-The-Hash attacks, organisations should implement several security measures:
    • Strong Authentication: Enforce the use of strong authentication mechanisms, such as multi-factor authentication (MFA), to make it more difficult for attackers to gain access even if they have hash values.
    • Regular Patching: Keep systems and software up to date to minimise vulnerabilities that attackers might exploit to gain access.
    • Least Privilege: Implement the principle of least privilege, ensuring users only have access to the resources necessary for their job roles.
    • Monitoring and Detection: Employ advanced threat detection systems that can identify unusual activity, including multiple logins from different locations or the use of compromised credentials.
    • Education and Training: Train users and IT staff about the risks and detection of PtH attacks and promote strong password practices.

In conclusion, Pass-The-Hash attacks pose a serious threat to Windows Domains, allowing attackers to move laterally through a network with stolen password hashes. Preventing these attacks requires a combination of technical measures, strong authentication practices, and ongoing security awareness.

How to detect it

Pass-the-hash is difficult to catch by looking for a single event, because the authentication itself is valid. Detection comes from context rather than from the logon.

  • Look for Event ID 4624 logon type 3 with NTLM authentication where you would expect Kerberos. Lateral movement between domain-joined systems that authenticates over NTLM is unusual in a healthy environment.
  • Alert on administrative accounts logging on to workstations. There is rarely a legitimate reason for a domain administrator to authenticate to an ordinary desktop, and that pattern is what the technique depends on.
  • Watch for an account authenticating to many hosts in a short period, particularly outside its normal working pattern.
  • Monitor access to LSASS memory. Credential material has to be obtained before it can be reused, and endpoint detection tooling can flag processes reading that memory.

How to prevent it

The technique exploits a design property of Windows authentication rather than a bug, so the defences are architectural.

Tier your administrative accounts. This is the most important control. Administrators who manage servers should not use the same accounts to log on to workstations, and domain administrators should authenticate only to domain controllers. Tiering means a harvested credential is confined to the tier it came from.

Enable Credential Guard on supported systems, which isolates credential material so it cannot be read from memory in the usual way.

Use the protected users group for privileged accounts, which prevents credential caching and restricts weaker authentication methods.

Deny network logon for local accounts and ensure local administrator passwords are unique per machine, managed by a solution such as Windows LAPS. A shared local administrator password across a fleet turns one compromised machine into all of them.

Reduce standing privilege. Just-in-time administration means there are fewer privileged credentials in memory at any moment, which is the raw material the technique needs.

Worth noting for incident response: because the attacker holds the hash rather than the password, a password reset is what invalidates it. Resetting twice is the traditional advice for accounts such as the domain krbtgt account, where the previous value remains usable.

Siege Cyber is a CREST-accredited provider of penetration testing across Australia. Get a Fixed-Price Quote.