[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYC1hFu_3uIk_prUedX-6bKthdTfpHezJ0TWI384GlP4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},727,"How does mimikatz's Pass-the-Hash differ from its Pass-the-Ticket approach?","Mimikatz's Pass-the-Hash (`sekurlsa::pth`) requires local administrator privileges because it injects into the `lsass.exe` process to overwrite credentials. In contrast, Pass-the-Ticket uses the external tool `kekeo` to request a TGT with just the user's NT hash, then imports that ticket via `kerberos::ptt`—all without admin rights. This makes Pass-the-Ticket a viable alternative when administrator privileges are unavailable. For more on related techniques, refer to [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode).","\u003Cp>Mimikatz&#39;s Pass-the-Hash (`sekurlsa::pth`) requires local administrator privileges because it injects into the `lsass.exe` process to overwrite credentials. In contrast, Pass-the-Ticket uses the external tool `kekeo` to request a TGT with just the user&#39;s NT hash, then imports that ticket via `kerberos::ptt`—all without admin rights. This makes Pass-the-Ticket a viable alternative when administrator privileges are unavailable. For more on related techniques, refer to [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-implementation-of-pass-the-hash\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-mimikatzs-pass-the-hash-differ-from-its-pass-the-ticket-approach-1777482230652","mimikatz, Pass the Hash, Pass the Ticket, kekeo, administrator privileges, TGT",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},179,"Domain Penetration - Implementation of Pass The Hash","domain-penetration-implementation-of-pass-the-hash","Learn Pass The Hash implementation for domain penetration: principles, tools like mimikatz, wmiexec, and Invoke-TheHash, with practical examples for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article 'Domain Penetration - Pass The Hash &amp; Pass The Key', the impact of kb2871997 on Pass The Hash was introduced. This article will approach from another perspective, introducing the relevant implementations of Pass The Hash\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Principles of Pass The Hash\u003C\u002Fli>\u003Cli>Common Tools\u003C\u002Fli>\u003Cli>Pass The Hash in mimikatz\u003C\u002Fli>\u003Cli>Pass The Ticket in mimikatz\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Principles of Pass The Hash\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to the introduction on Wikipedia, available at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPass_the_hash\u003C\u002Fp>\u003Cp>Extract key information:\u003C\u002Fp>\u003Cul>\u003Cli>In Windows systems, NTLM authentication is typically used.\u003C\u002Fli>\u003Cli>NTLM authentication does not use plaintext passwords but instead uses hash values generated from encrypted passwords, created by system APIs (e.g., LsaLogonUser).\u003C\u002Fli>\u003Cli>Hashes are divided into LM hash and NT hash. If the password length exceeds 15 characters, LM hash cannot be generated. Starting from Windows Vista and Windows Server 2008, Microsoft disabled LM hash by default.\u003C\u002Fli>\u003Cli>If an attacker obtains the hash, they can impersonate the user during authentication (i.e., bypass the process of calling the API to generate the hash).\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>mimikatz supports extracting LM hash from memory, but only if the Windows system supports LM hash.\u003C\u002Fp>\u003Cp>Method to enable LM hash on Windows Server 2008:\u003C\u002Fp>\u003Cp>gpedit.msc → Computer Configuration → Windows Settings → Security Settings → Local Policies → Security Options\u003C\u002Fp>\u003Cp>Find 'Network security: Do not store LAN Manager hash value on next password change' and select 'Disabled'.\u003C\u002Fp>\u003Cp>After the system changes the password next time, LM hash can be extracted.\u003C\u002Fp>\u003Ch2>0x03 Common Tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When we obtain a user's password hash and are limited to not cracking the plaintext password, what tools can be used for Pass The Hash?\u003C\u002Fp>\u003Ch3>1. Tools in Kali\u003C\u002Fh3>\u003Ch4>(1) meterpreter\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fwindows\u002Fsmb\u002Fpsexec_psh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Toolkit\u003C\u002Fh4>\u003Cp>Located under Password Attacks - Passing the Hash, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017241362_0_93944484a6.jpeg\">\u003C\u002Fp>\u003Cp>Includes various exploitation tools\u003C\u002Fp>\u003Ch3>2、Tools for Windows systems\u003C\u002Fh3>\u003Ch4>(1) python\u003C\u002Fh4>\u003Cp>\u003Cstrong>wmiexec:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCoreSecurity\u002Fimpacket\u002Fblob\u002Fmaster\u002Fexamples\u002Fwmiexec.py\u003C\u002Fp>\u003Cp>EXE version download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmaaaaz\u002Fimpacket-examples-windows\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The comment in wmiexec.py indicates \"Main advantage here is it runs under the user (has to be Admin) account\", but actual testing shows that regular user permissions are sufficient\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmiexec -hashes 00000000000000000000000000000000:7ECFFFF0C3548187607A14BAD0F88BB1 TEST\u002Ftest1@192.168.1.1 \"whoami\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The hash parameter format for wmiexec.py is LMHASH:NTHASH. Since this hash comes from Server 2008, which does not support LM hash by default, the LM hash can be set to any value.\u003C\u002Fp>\u003Ch4>(2) powershell\u003C\u002Fh4>\u003Cp>Reference URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FInvoke-TheHash\u002F\u003C\u002Fp>\u003Cp>Supports multiple methods\u003C\u002Fp>\u003Cp>\u003Cstrong>Invoke-WMIExec:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-WMIExec -Target 192.168.1.1 -Domain test.local -Username test1 -Hash 7ECFFFF0C3548187607A14BAD0F88BB1 -Command \"calc.exe\" -verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Similar to wmiexec.py\u003C\u002Fp>\u003Cp>\u003Cstrong>Invoke-SMBExec:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Supports SMB1, SMB2 (2.1), and SMB signing\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-SMBExec -Target 192.168.0.2 -Domain test.local -Username test1 -Hash 7ECFFFF0C3548187607A14BAD0F88BB1 -Command \"calc.exe\" -verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By creating a service on the target host to execute commands, thus the privilege is system\u003C\u002Fp>\u003Cp>\u003Cstrong>Invoke-SMBClient:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Supports SMB1, SMB2 (2.1), and SMB signing\u003C\u002Fp>\u003Cp>If only having permissions for SMB file sharing but no remote execution permissions, this script can be used\u003C\u002Fp>\u003Cp>Supported functions include listing directories, uploading files, downloading files, deleting files (specific permissions depend on the permissions of the password hash)\u003C\u002Fp>\u003Ch4>(3) mimikatz\u003C\u002Fh4>\u003Cp>\u003Cstrong>Pass-The-Hash:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Actually Overpass-the-hash\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>sekurlsa::pth \u002Fuser:test1 \u002Fdomain:test.local \u002Fntlm:c5a237b7e9d8e708d8436b6148a25fa1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The pth function of mimikatz requires local administrator privileges, which is determined by its implementation mechanism, as it needs to first obtain information from the high-privilege process lsass.exe\u003C\u002Fp>\u003Cp>For 8.1\u002F2012r2, Win 7\u002F2008r2\u002F8\u002F2012 with patch kb2871997 installed, AES keys can be used instead of NT hash\u003C\u002Fp>\u003Cp>\u003Cstrong>Pass-The-Ticket:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Considering that mimikatz's Pass-The-Hash feature requires local administrator privileges, mimikatz also provides a solution that does not require administrator privileges: Pass-The-Ticket.\u003C\u002Fp>\u003Cp>Pass-The-Ticket requires the use of another open-source tool by gentilkiwi called kekeo, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fkekeo\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>kekeo \"tgt::ask \u002Fuser:test1 \u002Fdomain:test.local \u002Fntlm:7ECFFFF0C3548187607A14BAD0F88BB1\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, the ticket TGT_test1@TEST.LOCAL_krbtgt~test.local@TEST.LOCAL.kirbi is generated.\u003C\u002Fp>\u003Cp>Next, import the ticket:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>kekeo \"kerberos::ptt TGT_test1@TEST.LOCAL_krbtgt~test.local@TEST.LOCAL.kirbi\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article lists various tools for implementing Pass The Hash; contributions are welcome.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article 'Domain Penetration - Pass The Hash &amp; Pass The Key', the impact of kb2871997 on Pass The Hash was introduced. This article will approach from another perspective, introducing the relevant implementations of Pass The Hash\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Principles of Pass The Hash\u003C\u002Fli>\u003Cli>Common Tools\u003C\u002Fli>\u003Cli>Pass The Hash in mimikatz\u003C\u002Fli>\u003Cli>Pass The Ticket in mimikatz\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Principles of Pass The Hash\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to the introduction on Wikipedia, available at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPass_the_hash\u003C\u002Fp>\u003Cp>Extract key information:\u003C\u002Fp>\u003Cul>\u003Cli>In Windows systems, NTLM authentication is typically used.\u003C\u002Fli>\u003Cli>NTLM authentication does not use plaintext passwords but instead uses hash values generated from encrypted passwords, created by system APIs (e.g., LsaLogonUser).\u003C\u002Fli>\u003Cli>Hashes are divided into LM hash and NT hash. If the password length exceeds 15 characters, LM hash cannot be generated. Starting from Windows Vista and Windows Server 2008, Microsoft disabled LM hash by default.\u003C\u002Fli>\u003Cli>If an attacker obtains the hash, they can impersonate the user during authentication (i.e., bypass the process of calling the API to generate the hash).\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>mimikatz supports extracting LM hash from memory, but only if the Windows system supports LM hash.\u003C\u002Fp>\u003Cp>Method to enable LM hash on Windows Server 2008:\u003C\u002Fp>\u003Cp>gpedit.msc → Computer Configuration → Windows Settings → Security Settings → Local Policies → Security Options\u003C\u002Fp>\u003Cp>Find 'Network security: Do not store LAN Manager hash value on next password change' and select 'Disabled'.\u003C\u002Fp>\u003Cp>After the system changes the password next time, LM hash can be extracted.\u003C\u002Fp>\u003Ch2>0x03 Common Tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When we obtain a user's password hash and are limited to not cracking the plaintext password, what tools can be used for Pass The Hash?\u003C\u002Fp>\u003Ch3>1. Tools in Kali\u003C\u002Fh3>\u003Ch4>(1) meterpreter\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fwindows\u002Fsmb\u002Fpsexec_psh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Toolkit\u003C\u002Fh4>\u003Cp>Located under Password Attacks - Passing the Hash, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017241362_0_93944484a6-1.jpeg\">\u003C\u002Fp>\u003Cp>Includes various exploitation tools\u003C\u002Fp>\u003Ch3>2、Tools for Windows systems\u003C\u002Fh3>\u003Ch4>(1) python\u003C\u002Fh4>\u003Cp>\u003Cstrong>wmiexec:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCoreSecurity\u002Fimpacket\u002Fblob\u002Fmaster\u002Fexamples\u002Fwmiexec.py\u003C\u002Fp>\u003Cp>EXE version download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmaaaaz\u002Fimpacket-examples-windows\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The comment in wmiexec.py indicates \"Main advantage here is it runs under the user (has to be Admin) account\", but actual testing shows that regular user permissions are sufficient\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmiexec -hashes 00000000000000000000000000000000:7ECFFFF0C3548187607A14BAD0F88BB1 TEST\u002Ftest1@192.168.1.1 \"whoami\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The hash parameter format for wmiexec.py is LMHASH:NTHASH. Since this hash comes from Server 2008, which does not support LM hash by default, the LM hash can be set to any value.\u003C\u002Fp>\u003Ch4>(2) powershell\u003C\u002Fh4>\u003Cp>Reference URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FInvoke-TheHash\u002F\u003C\u002Fp>\u003Cp>Supports multiple methods\u003C\u002Fp>\u003Cp>\u003Cstrong>Invoke-WMIExec:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-WMIExec -Target 192.168.1.1 -Domain test.local -Username test1 -Hash 7ECFFFF0C3548187607A14BAD0F88BB1 -Command \"calc.exe\" -verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Similar to wmiexec.py\u003C\u002Fp>\u003Cp>\u003Cstrong>Invoke-SMBExec:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Supports SMB1, SMB2 (2.1), and SMB signing\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-SMBExec -Target 192.168.0.2 -Domain test.local -Username test1 -Hash 7ECFFFF0C3548187607A14BAD0F88BB1 -Command \"calc.exe\" -verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By creating a service on the target host to execute commands, thus the privilege is system\u003C\u002Fp>\u003Cp>\u003Cstrong>Invoke-SMBClient:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Supports SMB1, SMB2 (2.1), and SMB signing\u003C\u002Fp>\u003Cp>If only having permissions for SMB file sharing but no remote execution permissions, this script can be used\u003C\u002Fp>\u003Cp>Supported functions include listing directories, uploading files, downloading files, deleting files (specific permissions depend on the permissions of the password hash)\u003C\u002Fp>\u003Ch4>(3) mimikatz\u003C\u002Fh4>\u003Cp>\u003Cstrong>Pass-The-Hash:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Actually Overpass-the-hash\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>sekurlsa::pth \u002Fuser:test1 \u002Fdomain:test.local \u002Fntlm:c5a237b7e9d8e708d8436b6148a25fa1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The pth function of mimikatz requires local administrator privileges, which is determined by its implementation mechanism, as it needs to first obtain information from the high-privilege process lsass.exe\u003C\u002Fp>\u003Cp>For 8.1\u002F2012r2, Win 7\u002F2008r2\u002F8\u002F2012 with patch kb2871997 installed, AES keys can be used instead of NT hash\u003C\u002Fp>\u003Cp>\u003Cstrong>Pass-The-Ticket:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Considering that mimikatz's Pass-The-Hash feature requires local administrator privileges, mimikatz also provides a solution that does not require administrator privileges: Pass-The-Ticket.\u003C\u002Fp>\u003Cp>Pass-The-Ticket requires the use of another open-source tool by gentilkiwi called kekeo, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fkekeo\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>kekeo \"tgt::ask \u002Fuser:test1 \u002Fdomain:test.local \u002Fntlm:7ECFFFF0C3548187607A14BAD0F88BB1\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, the ticket TGT_test1@TEST.LOCAL_krbtgt~test.local@TEST.LOCAL.kirbi is generated.\u003C\u002Fp>\u003Cp>Next, import the ticket:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>kekeo \"kerberos::ptt TGT_test1@TEST.LOCAL_krbtgt~test.local@TEST.LOCAL.kirbi\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article lists various tools for implementing Pass The Hash; contributions are welcome.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",770,"Onedaysec",3,"published","2026-02-02T07:38:21.202Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Pass The Hash Implementation: Tools & Techniques for Domain Penetration","pass the hash, domain penetration, mimikatz, NTLM authentication, hash exploitation, Windows security, penetration testing, lateral movement",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],728,726,725,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.751Z","2026-07-23T16:02:00.838Z","draft","2026-07-23T16:14:25.268Z"]