{"id":"T1550.002","name":"Pass the Hash","url":"https://attack.mitre.org/techniques/T1550/002","tactics":["lateral-movement"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0409","stix_id":"x-mitre-detection-strategy--5692084b-878d-44f7-8b38-a3d125894845","name":"Detection Strategy for T1550.002 - Pass the Hash (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0409","analytics":[{"id":"AN1144","stix_id":"x-mitre-analytic--d1bcc6a4-e84a-4251-b86b-e8fe2ecc0dd1","name":"Analytic 1144","description":"Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement.","url":"https://attack.mitre.org/detectionstrategies/DET0409#AN1144","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4768","data_component":"DC0084","data_component_name":"Active Directory Credential Request","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Allows tuning the correlation timeframe between authentication, session creation, and process/network activity."},{"field":"SourceAccountAnomalyThreshold","description":"Supports tuning detection sensitivity based on deviations from normal user login patterns or usage context."},{"field":"LogonTypeFilter","description":"Allows focusing detection on specific logon types (e.g., LogonType 3 for network logon, Type 10 for RDP)."}],"live":true,"detection_strategies":["DET0409"],"techniques":["T1550.002"]}],"live":true,"version":"1.0","techniques":["T1550.002"]}],"sigma_rules":[{"id":"192a0330-c20b-4356-90b6-7b7049ae0b87","title":"Successful Overpass the Hash Attempt","author":"Roberto Rodriguez (source), Dominik Schaudel (rule)","status":"test","level":"high","date":"2018-02-12","modified":"2021-11-27","description":"Detects successful logon with logon type 9 (NewCredentials) which matches the Overpass the Hash behavior of e.g Mimikatz's sekurlsa::pth module.","references":["https://web.archive.org/web/20220419045003/https://cyberwardog.blogspot.com/2017/04/chronicles-of-threat-hunter-hunting-for.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.s0002","attack.t1550.002"],"path":"rules/windows/builtin/security/account_management/win_security_overpass_the_hash.yml","techniques":["T1550.002"],"cves":[]},{"id":"24549159-ac1b-479c-8175-d42aea947cae","title":"Hacktool Ruler","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-31","modified":"2022-10-09","description":"This events that are generated when using the hacktool Ruler by Sensepost","references":["https://github.com/sensepost/ruler","https://github.com/sensepost/ruler/issues/47","https://github.com/staaldraad/go-ntlm/blob/cd032d41aa8ce5751c07cb7945400c0f5c81e2eb/ntlm/ntlmv1.go#L427","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4776","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4624"],"logsource":{"product":"windows","service":"security"},"tags":["attack.discovery","attack.execution","attack.collection","attack.lateral-movement","attack.t1087","attack.t1114","attack.t1059","attack.t1550.002"],"path":"rules/windows/builtin/security/win_security_alert_ruler.yml","techniques":["T1087","T1114","T1059","T1550.002"],"cves":[]},{"id":"8eef149c-bd26-49f2-9e5a-9b00e3af499b","title":"Pass the Hash Activity 2","author":"Dave Kennedy, Jeff Warren (method) / David Vassallo (rule)","status":"stable","level":"medium","date":"2019-06-14","modified":"2022-10-05","description":"Detects the attack technique pass the hash which is used to move laterally inside the network","references":["https://github.com/iadgov/Event-Forwarding-Guidance/tree/master/Events","https://web.archive.org/web/20170909091934/https://blog.binarydefense.com/reliably-detecting-pass-the-hash-through-event-log-analysis","https://blog.stealthbits.com/how-to-detect-pass-the-hash-attacks/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.t1550.002"],"path":"rules/windows/builtin/security/account_management/win_security_pass_the_hash_2.yml","techniques":["T1550.002"],"cves":[]},{"id":"98c3bcf1-56f2-49dc-9d8d-c66cf190238b","title":"NTLM Logon","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2018-06-08","modified":"2024-07-22","description":"Detects logons using NTLM, which could be caused by a legacy source or attackers","references":["https://twitter.com/JohnLaTwC/status/1004895028995477505"],"logsource":{"product":"windows","service":"ntlm"},"tags":["attack.lateral-movement","attack.t1550.002"],"path":"rules/windows/builtin/ntlm/win_susp_ntlm_auth.yml","techniques":["T1550.002"],"cves":[]},{"id":"e9d4ab66-a532-4ef7-a502-66a9e4a34f5d","title":"NTLMv1 Logon Between Client and Server","author":"Tim Shelton, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-04-26","modified":"2023-06-06","description":"Detects the reporting of NTLMv1 being used between a client and server. NTLMv1 is insecure as the underlying encryption algorithms can be brute-forced by modern hardware.","references":["https://github.com/nasbench/EVTX-ETW-Resources/blob/f1b010ce0ee1b71e3024180de1a3e67f99701fe4/ETWProvidersManifests/Windows10/22H2/W10_22H2_Pro_20230321_19045.2728/WEPExplorer/LsaSrv.xml"],"logsource":{"product":"windows","service":"system"},"tags":["attack.lateral-movement","attack.t1550.002"],"path":"rules/windows/builtin/system/lsasrv/win_system_lsasrv_ntlmv1.yml","techniques":["T1550.002"],"cves":[]},{"id":"f8d98d6c-7a07-4d74-b064-dd4a3c244528","title":"Potential Pass the Hash Activity","author":"Ilias el Matani (rule), The Information Assurance Directorate at the NSA (method)","status":"test","level":"medium","date":"2017-03-08","modified":"2023-12-15","description":"Detects the attack technique pass the hash which is used to move laterally inside the network","references":["https://github.com/nsacyber/Event-Forwarding-Guidance/tree/6e92d622fa33da911f79e7633da4263d632f9624/Events"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.t1550.002","car.2016-04-004"],"path":"rules-placeholder/windows/builtin/security/win_security_potential_pass_the_hash.yml","techniques":["T1550.002"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-13161","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-13160","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-13159","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-23397","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}