Skip to content
payloadreport
Saturday, October 10, 2026Cybersecurity news without the noise70 reports
Threat Intelligence

Stop Pass-the-Hash Attacks: Practical Prevention and Detection

Disabling NTLM alone fails because modern protocols like Kerberos and SMB can still carry credential material, requiring layered identity controls.

Stop Pass-the-Hash Attacks: Practical Prevention and Detection
Illustration: Payload Report
Quick answer

Restrict NTLM usage and enforce mutual authentication to block credential replay. Implement credential guard to isolate secrets from memory. Monitor for unusual lateral movement patterns. These steps reduce the attack surface without relying on perimeter defences that attackers already bypass.

The Mechanics of Credential Replay

Pass-the-hash attacks exploit the way operating systems handle authentication. When a user logs on, the system hashes their password. This cryptographic hash is stored locally and sent to domain controllers for verification. Attackers do not need the plaintext password. They only need this hash. If they extract it from memory or a local security account manager database, they can present it to other servers as proof of identity. The server accepts the hash, believing it is the legitimate user.

This works because the authentication protocol trusts the hash as a valid credential. It does not verify that the hash was generated in the current session. This allows an attacker to move laterally across a network. They jump from one compromised machine to another, using the same stolen credential material. The attack leaves minimal traces in standard logs, making detection difficult.

Infographic: Stop Pass-the-Hash Attacks: Practical Prevention and Detection. NTLM restrictions stop the most common replay vector but require careful tuning to avoid breaking legacy applications. Virtualisation-based isolation prevents attackers from extracting hashes from running processes, even wi
Infographic: Stop Pass-the-Hash Attacks: Practical Prevention and Detection. Free to share with a link to Payload Report.

Why NTLM Restrictions Are Not Enough

Many teams assume that disabling NTLM (New Technology LAN Manager) stops these attacks. This is a dangerous misconception. NTLM is an older authentication protocol that is indeed vulnerable to replay attacks. Disabling it forces systems to use more secure methods. However, attackers adapt. They use other protocols that also transmit credential material.

Kerberos is the standard for modern Windows environments. It is more secure than NTLM, but it is not immune to credential theft. Attackers can steal Kerberos tickets or use techniques like pass-the-ticket. Furthermore, SMB (Server Message Block) traffic can carry authentication data. If you only block NTLM, you leave the door open for these alternative vectors. You must restrict NTLM, but you cannot rely on it as the sole defence.

Virtualisation-Based Isolation

The most effective technical control is to prevent the hash from being accessible in the first place. Credential Guard uses virtualisation-based security to isolate sensitive authentication material. It moves the credentials into a secure, isolated container called the Virtual Secure Mode. The main operating system cannot access this container. Even if an attacker gains local administrator privileges, they cannot read the memory where the hashes are stored.

This breaks the chain of the pass-the-hash attack. Without access to the hash or the plaintext password, the attacker cannot replay credentials to other systems. This measure addresses the root cause: the exposure of secrets in user-mode memory. It requires hardware virtualisation support, which is standard on modern servers and workstations. The trade-off is a slight increase in boot time and resource usage. For most environments, this cost is negligible compared to the risk of lateral movement.

Network Segmentation and Zero Trust

If an attacker does obtain a hash, you must limit where they can use it. Network segmentation divides your infrastructure into smaller zones. Each zone has strict access controls. A user in the finance zone cannot access servers in the engineering zone, even if they have valid credentials. This is the core principle of zero trust architecture.

This approach reduces the value of a stolen credential. The attacker is trapped in a small segment. They cannot move laterally to high-value targets. You must define strict rules for which services can communicate with each other. Default deny policies are essential here. Allow only the traffic that is necessary for business operations. This requires careful mapping of application dependencies. It is a significant effort, but it drastically reduces the blast radius of any breach.

Detecting Lateral Movement

Prevention is ideal, but detection is necessary. You must monitor for signs of lateral movement. Look for unusual authentication patterns. A server that never initiates outbound connections suddenly authenticating to multiple other systems is a red flag. Monitor for failed logon attempts followed by success. This pattern often indicates an attacker testing stolen credentials.

Integrate your monitoring tools to correlate events across the network. A single failed logon is noise. A burst of failures from one source, followed by successful logons to different targets, is a signal. Use this data to trigger alerts. Do not rely on perimeter firewalls for this detection. The traffic originates from inside your network. You need internal visibility.

See also: Defense Evasion Explained: How Attackers Hide in Plain Sight · Advanced Persistent Threats: Definition, Mechanics and Detection

Measures That Fail

Some common recommendations do not work against pass-the-hash attacks. Changing passwords regularly does not help. The attacker has the hash, not the password. They do not need to know the new password to use the old hash. The hash remains valid until the password is changed and the system is restarted or the cache is cleared.

Blocking outbound internet traffic is also ineffective. These attacks occur entirely within your internal network. The attacker does not need to exfiltrate data to move laterally. They simply authenticate to the next server. Focusing on perimeter controls gives a false sense of security. You must look inward.

MeasureEffortWhat it stops
Credential GuardMediumExtraction of hashes from memory
NTLM RestrictionsHighReplay attacks via legacy protocols
Network SegmentationHighLateral movement between zones
Password RotationLowNothing against existing hashes
Outbound BlockingLowNothing against internal movement

Integration with Broader Defences

These controls work best when combined with other security practices. For instance, understanding defence evasion techniques helps you tune your detection rules. Attackers often try to hide their activity by clearing logs or using legitimate tools. Your monitoring must account for this.

Similarly, Windows event log monitoring is critical for spotting the authentication anomalies described above. Without high-fidelity logs, you cannot detect the subtle signs of lateral movement. You should also consider purple teaming exercises to test your defences. These exercises simulate real attacks, allowing you to verify that your controls work as intended.

Immediate Action Plan

You do not need to overhaul your entire infrastructure today. Start with the measures that provide the highest return on investment. Enable virtualisation-based security on critical servers. This stops the most direct extraction method. Then, review your NTLM settings. Identify and restrict unnecessary usage. This closes a major vector for replay attacks.

Finally, map your network segments. Identify high-value assets and ensure they are isolated from general user workstations. This limits the damage if a credential is stolen. These steps create a layered defence. No single measure is perfect, but together they significantly raise the bar for attackers.

  • Enable Credential Guard on domain controllers and critical servers
  • Audit and restrict NTLM usage to essential legacy applications
  • Define network segments for high-value assets and enforce strict access controls

Key takeaways

  • NTLM restrictions stop the most common replay vector but require careful tuning to avoid breaking legacy applications.
  • Virtualisation-based isolation prevents attackers from extracting hashes from running processes, even with local admin rights.
  • Network segmentation limits the blast radius if a credential is stolen, reducing the value of the stolen hash.
Bottom line

Isolating credentials in memory prevents their theft, while network segmentation limits their utility. Start by enabling virtualisation-based security on your most critical systems today.

Frequently asked questions

Does multi-factor authentication stop pass-the-hash attacks?

Yes, if implemented correctly. MFA adds a second factor that the attacker cannot replay with a stolen hash. However, many legacy protocols do not support MFA, leaving gaps.

Can I use pass-the-hash on Linux systems?

Linux uses different authentication mechanisms, such as PAM and SSH keys. While similar attacks exist, they do not use NTLM hashes. The techniques and tools differ significantly.

How do I know if Credential Guard is enabled?

You can check the system status through the operating system's security settings or command-line tools. Look for indicators that virtualisation-based security is active and running.

Does disabling SMBv1 help?

Yes, SMBv1 has known vulnerabilities that can lead to credential theft. Disabling it reduces the attack surface, but it does not stop pass-the-hash on SMBv2 or SMBv3.

How this guide was produced: written by the Payload Report editorial team with AI assistance, checked against the public references listed below, and reviewed when the facts change. See our editorial policy or report an error.

Further reading

  1. CISA Cybersecurity Advisories
  2. FIRST: Forum of Incident Response and Security Teams
  3. MITRE ATT&CK
pass-the-hash attackspass-the-hashidentity securitylateral movement

Related stories

Login Alerts: Why They Fail and How to Make Them Work

Login alerts provide a false sense of security by reporting events after the damage is often done, requiring specific configuration to be useful.