Skip to main content
AD Academy
Attacks on AD
Intermediate17 minLast updated: Topic 2 of 7

Pass-the-Hash and Pass-the-Ticket

Attacks that use stolen Hashes or Tickets.

Not read

What you will learn here

  • How to log in with a hash, no password
  • PtH vs PtT
  • Which defenses stop it

Worth reading first:Kerberoasting

In certain protocols, such as , you don't always need the password itself — its Hash is enough. allows using a stolen Hash for authentication. is a similar attack, but with tickets.

תוקף עם הרשאות DS-Replication פונה ל־Domain Controller. שלב 1: בקשת GetNCChanges כאילו מדובר ב־DC אחר. שלב 2: ה־DC מחזיר Hashes מתוך NTDS.dit, כולל krbtgt ו־Domain Admins. שלב 3: יצירת Golden Ticket לשליטה מתמשכת. הגנה: ניטור אירוע 4662 והגבלת הרשאות רפליקציה.

How to defend

  • Enable and LSA Protection.
  • Restrict the use of Privileged Accounts.
  • Monitor unusual authentication and Lateral Movement in the network.
  • Disable where possible and move to .
Architecture and Theory — Under the Hood

does not send the password but proves knowledge of the hash. Therefore, the hash itself is the secret — whoever holds it connects without knowing the password. This is not a bug but a feature of the protocol.

  • LSASS holds hashes and tickets of everyone logged in, in memory.
  • Local Admin with the same password on all workstations = immediate lateral movement.
  • — the same concept with tickets.
Practical Configuration (PowerShell / GUI)
# LAPS — Unique and rotating local admin password on every computer
Get-LapsADPassword -Identity PC-01 -AsPlainText

# Blocking local accounts from network access (GPO / Registry)
New-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" `
  -Name LocalAccountTokenFilterPolicy -Value 0 -PropertyType DWord -Force

# Credential Guard (requires UEFI + Secure Boot)
# Computer Config > Admin Templates > System > Device Guard > Turn On Virtualization Based Security
powershell
Real-world Scenarios in the Organization
  • Tiering: Tier0 (DC) / Tier1 (Servers) / Tier2 (Workstations) — an account from one tier does not access another tier.
  • Protected Users Group — Blocks and delegation for group members.
  • PAW — Dedicated management workstation for admins only.
Troubleshooting
  • Event 4624 with Logon Type 3 + against a server expected to use = red flag.
  • The same local account connecting to dozens of computers = lateral movement.
  • Check LSASS access: Sysmon Event ID 10 with TargetImage lsass.exe.
Glossary and Quick Command Line
  • PtH — .
  • LSASS — A process that holds secrets in memory.
  • — Local Admin Password Solution.
  • Logon Type 3 = Network, 10 = RDP.

Check yourself

What does the Pass-the-Hash attack use?

Was this page helpful?