logo

Active Directory Attacks Demystified: Pass-the-Hash (PtH), Pass-the-Ticket (PtT), and Beyond

ID: d62ae2da-74eb-59aa-b1d7-812e461c45dd

STIX ID: report--d62ae2da-74eb-59aa-b1d7-812e461c45dd

Feed Name: Qualys Blog

Date Published: 2026-02-12

Date Updated: 2026-04-28

Author: Prashant Sheshnaryan Pawar

...
...

This report outlines identity-centric threats in Active Directory, focusing on Pass-the-Hash and Pass-the-Ticket techniques, related privilege-escalation paths (e.g., WriteDACL, DCSync), common tools, impacts, and mitigation best practices (NTLM restriction, Kerberos hardening, least privilege, and monitoring). It uses lab-based walkthroughs to illustrate lateral movement and domain takeover, and explains how Qualys ETM Identity maps attack paths, detects toxic privileges, and monitors identity configurations to proactively reduce domain-compromise risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.