CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard
After compromising a workstation, a tester uses Mimikatz to extract an NTLM hash from memory and then uses that hash directly with a tool like psexec to authenticate to another server on the network, without ever needing to know or crack the plaintext password. Which attack technique does this describe?
- AGolden ticket attack
- BPass-the-hash
- CLLMNR poisoning
- DKerberoasting
Show answer & explanationAnswer & explanation
Correct answer: B. Pass-the-hash
Pass-the-hash allows an attacker to authenticate to systems using a captured NTLM hash directly, bypassing the need to know or crack the underlying plaintext password, exploiting how NTLM authentication accepts the hash itself.
Why the other options are wrong
- A. A golden ticket attack forges Kerberos TGTs using the krbtgt hash, a different mechanism.
- C. LLMNR poisoning captures credentials via name resolution spoofing, not hash reuse for lateral movement.
- D. Kerberoasting targets Kerberos service tickets for offline cracking, not direct hash reuse.
Pass-the-Hash
A lateral movement technique where a captured NTLM hash is used directly to authenticate to other systems without needing the plaintext password.
- Exploits NTLM's acceptance of the hash itself as a credential
- Commonly performed with tools like Mimikatz and psexec/impacket
- Mitigated by disabling NTLM and enabling Credential Guard
Memory trick: Pass the hash like passing a keycard — no need to know the code.