1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1550.002 Pass the Hash — Detection Rules

Detection workspace for T1550.002 Pass the Hash: 5 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

  • NTLM Logon · test · low · {"product":"windows","service":"ntlm","definition":"Requires events from Microsoft-Windows-NTLM/Operational"}
  • Successful Overpass the Hash Attempt · test · high · {"product":"windows","service":"security"}
  • Pass the Hash Activity 2 · stable · medium · {"product":"windows","service":"security","definition":"The successful use of PtH for lateral movement between workstations would trigger event ID 4624"}
  • Hacktool Ruler · test · high · {"product":"windows","service":"security"}
  • NTLMv1 Logon Between Client and Server · test · medium · {"product":"windows","service":"system"}

Atlas deterministic concepts

T1550.002 Pass the Hash

MATCH(ntlm_network_logon_pattern_without_expected_interactive_context) AND source_host NOT_IN approved_admin_hosts -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0409 Detection Strategy for T1550.002 - Pass the Hash (Windows)

AN1144 Analytic 1144

Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1550.002 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.