NTLM relay & pass-the-hash
TL;DR
NTLM authentication can be relayed (passed straight to another service to log in as the victim) or replayed with pass-the-hash (the hash is as good as the password). Both come down to NTLM being weak. The defences are SMB signing, reducing NTLM, LAPS and admin tiering.
What it is
NTLM is the older Windows authentication protocol, and it has two long-standing problems an attacker leans on: the authentication can be forwarded to a different server, and the password hash can be used directly without ever cracking it.
How it works
- Relay: the attacker gets a victim to authenticate to them (often via poisoning), then passes that authentication to another service where the victim has access — logging in as them, without ever seeing the password.
- Pass-the-hash: with an account’s NTLM hash, the attacker authenticates as that account directly. The hash is the credential.
How to detect it
- Logons from unexpected hosts, the same account active in two places, and authentication that doesn’t match normal patterns.
How to defend
- Enforce SMB signing to break relaying, and reduce or disable NTLM in favour of Kerberos.
- LAPS for unique local admin passwords, and an admin tiering model so a stolen hash doesn’t unlock everything.
Reference: MITRE ATT&CK T1550.002.