Possible Pass-the-Hash
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detection Modules
Identity Analytics
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Use Alternate Authentication Material: Pass the Hash (T1550.002)
Severity
Low
Description
An account was successfully logged on to with new credentials. This login type is rare and may be an attacker's attempt to pass-the-hash and move laterally within a network.
Attacker's Goals
An attacker is attempting to steal credentials and move laterally within a network.
Investigative actions
Audit all login events and review for discrepancies.
Look for LSASS process access, an indication of an attacker attempting to obtain password hashes.
Check for the RunAs command with the /netonly option.
Was this helpful?
