Detecting Pass-the-Hash Attack in a Microsoft Active Directory Environment using an Open-Source Approach

Jacques Gerald Vivian Felicite, Vanessa Ayala-Rivera, A. Omar Portillo‐Dominguez · 2024

The pervasiveness of Pass-the-Hash (PtH) attacks within Microsoft Active Directory environments poses a high security risk to organizations globally. This paper proposes an open-source based system for detecting PtH attacks. We systematically dissect the attack vector, which capitalizes on the vulnerability inherent in the Windows New Technology LAN Manager authentication protocol. The paper highlights the steps that attackers would use to conduct the PtH attack including acquiring the hash through system exploitation or credential theft, using the hash for impersonation without requiring the plaintext password, and achieving lateral movement to escalate privileges within the network. Furthermore, it outlines the discreet nature of PtH attacks that evade traditional security measures, emphasizing the significance of a robust and layered defense strategy. Our results demonstrate that it is possible to leverage these affordable technologies to improve the detection of malicious activities in an organisation's network, improving its security posture.

Read the paper · More papers on PaperTik