Glossary
Pass-the-hash
Pass-the-Hash is a technique that authenticates using a stolen NTLM password hash directly, without ever knowing the plaintext password.
Pass-the-Hash (PtH) exploits how NTLM authentication works: the protocol only requires proof of knowledge of a password's hash, not the password itself, to complete a challenge-response exchange. An attacker who extracts NTLM hashes from a compromised machine's memory or SAM database can replay that hash against other systems to authenticate as the associated user, entirely bypassing the need to crack or know the actual password.
This matters because it lets a single compromised endpoint, especially one where a privileged account has logged on, become a springboard for lateral movement across the network, often reaching many other hosts and eventually domain controllers. Mitigations include restricting NTLM in favor of Kerberos, enabling Credential Guard, applying tiered administration so high-privilege credentials never touch lower-tier machines, and using unique local administrator passwords (e.g., LAPS) to prevent hash reuse across hosts.