Use of Captured Hashes (Pass The Hash)
CAPEC-644 · Detailed · Stable
An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols.
likelihood: Medium
severity: High