NTLM relay & pass-the-hash

intermediateInternal & Active Directory

TL;DR

NTLM authentication can be relayed (passed straight to another service to log in as the victim) or replayed with pass-the-hash (the hash is as good as the password). Both come down to NTLM being weak. The defences are SMB signing, reducing NTLM, LAPS and admin tiering.

What it is

NTLM is the older Windows authentication protocol, and it has two long-standing problems an attacker leans on: the authentication can be forwarded to a different server, and the password hash can be used directly without ever cracking it.

How it works

How to detect it

How to defend

Reference: MITRE ATT&CK T1550.002.

← Back to Internal & Active Directory