Glossary

PASS THE HASH
defined.

An authentication-relay technique where an attacker uses an NTLM hash (rather than the plaintext password) to authenticate to other systems.

A–Z

What is Pass the Hash?

Pass-the-Hash is core lateral-movement tradecraft. Mitigation is layered: Credential Guard / LSA protection in Windows, no local-admin password reuse (LAPS), and disabling NTLM where possible.

Where this shows up.

See our web application penetration testing, API security testing, network penetration testing, and cloud security audit services for how we test for and defend against this class of issue.

Test for this in your stack

BOOK A FREE
scoping call.

30-minute call with an OSCP-certified engineer. Tailored proposal in 24 hours.