T1550

Use Alternate Authentication Material

Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens to move laterally.

ATT&CK / Lateral Movement

Defense strategies

  • Implement Credential Guard
  • Limit credential caching
  • Monitor Kerberos ticket requests
  • Use Protected Users group

Detection methods

  • Detect pass-the-hash activity
  • Monitor for anomalous Kerberos requests
  • Track NTLM authentication patterns

T1550 on MITRE ATT&CK ↗