You are investigating logon events on a domain controller. A compromised workstation authenticates as a domain user using NTLMv2 network logons. The user has no interactive logon events on that workstation, yet several successful remote authentications occur. What authentication behavior is most likely occurring?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: you don't need the actual key if you have a perfect copy of the lock's internal mechanism. Pass-the-hash lets an attacker use a captured NTLM hash to prove identity without ever cracking it to plaintext. If you see NTLMv2 auths from a machine where the user never logged in interactively, that's your red flag.
Full Explanation
Pass-the-hash (PtH) is a lateral movement technique where an attacker uses a captured NTLM hash to authenticate to remote systems without needing the plaintext password. In Windows authentication logs, PtH appears as NTLMv2 network authentication from a source host where the same user has no interactive logon, showing credential reuse from a captured hash rather than a locally entered password. It is commonly seen after credential dumping, when the attacker already has the hash in memory. Kerberos ticket replay involves replaying Kerberos tickets and would appear as Kerberos authentication traffic, not NTLM challenge/response events. Brute-force password guessing attempts would show repeated failed network logons followed by a successful authentication derived from a plaintext attempt, not the artifact of reused NTLM hashes. Golden Ticket privilege escalation forges Kerberos ticket-granting tickets, producing Kerberos-based activity rather than NTLM authentication. Exam caveat: Do not confuse pass-the-hash with pass-the-ticket; pass-the-hash depends on NTLM hashes, while pass-the-ticket depends on Kerberos tickets. Operational check: Filter authentication logs for NTLMv2 successes from systems lacking corresponding interactive logons for the same user account.