CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

After compromising a workstation, a tester uses Mimikatz to extract an NTLM hash from memory and then uses that hash directly with a tool like psexec to authenticate to another server on the network, without ever needing to know or crack the plaintext password. Which attack technique does this describe?

  1. AGolden ticket attack
  2. BPass-the-hash
  3. CLLMNR poisoning
  4. DKerberoasting
Show answer & explanation

Correct answer: B. Pass-the-hash

Pass-the-hash allows an attacker to authenticate to systems using a captured NTLM hash directly, bypassing the need to know or crack the underlying plaintext password, exploiting how NTLM authentication accepts the hash itself.

Why the other options are wrong

  • A. A golden ticket attack forges Kerberos TGTs using the krbtgt hash, a different mechanism.
  • C. LLMNR poisoning captures credentials via name resolution spoofing, not hash reuse for lateral movement.
  • D. Kerberoasting targets Kerberos service tickets for offline cracking, not direct hash reuse.

Pass-the-Hash

A lateral movement technique where a captured NTLM hash is used directly to authenticate to other systems without needing the plaintext password.

  • Exploits NTLM's acceptance of the hash itself as a credential
  • Commonly performed with tools like Mimikatz and psexec/impacket
  • Mitigated by disabling NTLM and enabling Credential Guard

Memory trick: Pass the hash like passing a keycard — no need to know the code.

More Attacks and Exploits questions