Detailedlikelihood: Mediumseverity: HighStable
CAPEC-644Use of Captured Hashes (Pass The Hash)
Abstraction
Detailed
Status
Stable
Likelihood
Medium
Severity
High
Description
An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols.
Metadata: detailed CAPEC pattern, status stable, likelihood medium, severity high. Underlying weaknesses: CWE-522, CWE-836, CWE-308, CWE-294, CWE-308. Mapped ATT&CK technique: [object Object]. Related CAPEC patterns: [object Object], [object Object], [object Object], [object Object] (and 1 more).
Related weaknesses· 5
MITRE ATT&CK crosswalk· 1
Related attack patterns· 5
Exploits4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Insufficiently Protected Credentialscwe-522 | 100% | live |
| Weakness | Use of Password Hash Instead of Password for Authenticationcwe-836 | 100% | live |
| Weakness | Authentication Bypass by Capture-replaycwe-294 | 100% | live |
| Weakness | Use of Single-factor Authenticationcwe-308 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Pass the Hasht1550.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.