Module 9 · Pass-the-Hash & Pass-the-Ticket

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 27, 2026
3 min read
Read as

Last updated: April 29, 2026

100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. Pass-the-Hash was first published in 1997. Microsoft has shipped 28 years of mitigations and the technique still works on most enterprise networks. Understanding why it persists, and what actually stops it, is foundational to defending AD.

Why this module exists. Pass-the-Hash was first published in 1997. Microsoft has shipped 28 years of mitigations and the technique still works on most enterprise networks. Understanding why it persists, and what actually stops it, is foundational to defending AD.

NTLM in 30 seconds

NTLM authentication doesn’t transmit the password. The client transmits the NT hash (or a derived MAC over a challenge using the NT hash). To impersonate a user, an attacker doesn’t need the plaintext password — they need the hash.

Pass-the-Hash: take the NT hash from any source (LSASS dump, SAM database, NTDS.dit), use it as the credential in a Windows authentication call. Mimikatz, Impacket, CrackMapExec all do this.

Want this for your team?

Custom team training + practitioner advisory

Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.

Book team training call Replies in 4 working hrs · India-only · Senior consultants