T1550
Use Alternate Authentication Material
Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens to move laterally.
ATT&CK / Lateral Movement
Defense strategies
- Implement Credential Guard
- Limit credential caching
- Monitor Kerberos ticket requests
- Use Protected Users group
Detection methods
- Detect pass-the-hash activity
- Monitor for anomalous Kerberos requests
- Track NTLM authentication patterns
D3FEND mappings
1