Avatier

SSO, IdP, or federation compromise

Pass-the-hash

Pass-the-hash is an attack that signs in to Windows systems using a stolen password hash instead of the password itself. Older Windows authentication, such as NTLM, accepts the hash as proof of identity, so an attacker who dumps hashes from one machine can move to others as that user without ever cracking the password.

How it works

After compromising a computer, the attacker extracts NTLM hashes from memory or local credential stores using tools such as Mimikatz. They then present a hash to other servers over protocols like SMB. If the same local admin password is reused across machines, or a domain admin has signed in, one hash can unlock much of the network.

A real example

A September 2024 advisory from the FBI, CISA, NSA and partners said Russian GRU Unit 29155 cyber actors used Pass-the-Hash to authenticate via SMB.

Source: Russian Military Cyber Actors Target US and Global Critical Infrastructure (AA24-249A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-09-05

How to stop it

Use unique local admin passwords on every machine, restrict where privileged accounts can sign in, disable NTLM where possible, and protect credential memory on endpoints.

Related terms

Sources

  1. Russian Military Cyber Actors Target US and Global Critical Infrastructure (AA24-249A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-09-05

Last reviewed Oct 2, 2026