1200KM / detection
T1550.002 Pass the Hash — Detection Rules
Detection workspace for T1550.002 Pass the Hash: 5 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- NTLM Logon · test · low · {"product":"windows","service":"ntlm","definition":"Requires events from Microsoft-Windows-NTLM/Operational"}
- Successful Overpass the Hash Attempt · test · high · {"product":"windows","service":"security"}
- Pass the Hash Activity 2 · stable · medium · {"product":"windows","service":"security","definition":"The successful use of PtH for lateral movement between workstations would trigger event ID 4624"}
- Hacktool Ruler · test · high · {"product":"windows","service":"security"}
- NTLMv1 Logon Between Client and Server · test · medium · {"product":"windows","service":"system"}
Atlas deterministic concepts
T1550.002 Pass the Hash
MATCH(ntlm_network_logon_pattern_without_expected_interactive_context) AND source_host NOT_IN approved_admin_hosts -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0409 Detection Strategy for T1550.002 - Pass the Hash (Windows)
AN1144 Analytic 1144
Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.