Sub-technique of T1550 Use Alternate Authentication Material.View on attack.mitre.org
Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls. Pass the hash (PtH) is a method of authenticating as a user without having access to the user's cleartext password. This method bypasses standard authentication steps that require a cleartext password, moving directly into the portion of the authentication that uses the password hash.
When performing PtH, valid password hashes for the account being used are captured using a Credential Access technique. Captured hashes are used with PtH to authenticate as that user. Once authenticated, PtH may be used to perform actions on local or remote systems.
Adversaries may also use stolen password hashes to "overpass the hash." Similar to PtH, this involves using a password hash to authenticate as a user but also uses the password hash to create a valid Kerberos ticket. This ticket can then be used to perform Pass the Ticket attacks.
Rules on DetectionCode tagged with T1550.002.
| Rule | Level | Log source |
|---|---|---|
| Hacktool Ruler | high | windows / NULL |
| Successful Overpass the Hash Attempt | high | windows / NULL |
| NTLMv1 Logon Between Client and Server | medium | windows / NULL |
| Pass the Hash Activity 2 | medium | windows / NULL |
| NTLM Logon | low | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect Activity Related to Pass the Hash Attacks | Hunting | NULL | Windows Event Log Security 4624 |
| Used by | Procedure example |
|---|---|
| GroupAPT1 | The APT1 group is known to have used pass the hash. |
| GroupAPT28 | APT28 has used pass the hash for lateral movement. |
| GroupAPT32 | APT32 has used pass the hash for lateral movement. |
| GroupAPT41 | APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes. |
| GroupAquatic Panda | Aquatic Panda used a registry edit to enable a Windows feature called |
| GroupChimera | Chimera has dumped password hashes for use in pass the hash authentication attacks. |
| GroupEmber Bear | Ember Bear has used pass-the-hash techniques for lateral movement in victim environments. |
| GroupFIN13 | FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment. |
| Used by | Procedure example |
|---|---|
| MalwareBADHATCH | BADHATCH can perform pass the hash on compromised machines with x64 versions. |
| MalwareCobalt Strike | Cobalt Strike can perform pass the hash. |
| ToolCrackMapExec | CrackMapExec can pass the hash to authenticate via SMB. |
| ToolEmpire | Empire can perform pass the hash attacks. |
| MalwareHOPLIGHT | HOPLIGHT has been observed loading several APIs associated with Pass the Hash. |
| ToolMimikatz | Mimikatz's |
| ToolPass-The-Hash Toolkit | Pass-The-Hash Toolkit can perform pass the hash. |
| ToolPoshC2 | PoshC2 has a number of modules that leverage pass the hash for lateral movement. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to reuse password hash values to gain access to other systems. |
| CampaignNight Dragon | During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.