What is pass-the-hash?¶
Pass-the-hash is authentication using a captured password-derived hash without knowing or entering the original password. Where the protocol accepts that representation, stealing the hash can support lateral movement.
Connect credential access to authentication¶
Establish which account the hash represented, where it could have been extracted, the source device, target service and authentication protocol. Memory or credential-store access, suspicious tooling and source-side processes may show acquisition; target authentication and remote-service records may show use.
Hash-based access can resemble ordinary account authentication. A login result alone is therefore insufficient. Protocol details and the surrounding credential-access and source-system activity are needed, sometimes with specialist interpretation.
Limit the conclusion¶
Not every login by the account is pass-the-hash, and successful access does not mean the password was disclosed or typed. The account holder may be unaware of both extraction and use.
A supported event can establish account misuse and movement to a target, but it does not identify who extracted or replayed the hash. State limitations where logs do not expose the authentication mechanism directly.
Key takeaway
Prove pass-the-hash by linking hash acquisition, protocol-specific authentication and target activity - not from a successful account login alone.