Active Directory Attacks Demystified: Pass-the-Hash (PtH), Pass-the-Ticket (PtT), and Beyond
ID: d62ae2da-74eb-59aa-b1d7-812e461c45dd
STIX ID: report--d62ae2da-74eb-59aa-b1d7-812e461c45dd
Feed Name: Qualys Blog
This report outlines identity-centric threats in Active Directory, focusing on Pass-the-Hash and Pass-the-Ticket techniques, related privilege-escalation paths (e.g., WriteDACL, DCSync), common tools, impacts, and mitigation best practices (NTLM restriction, Kerberos hardening, least privilege, and monitoring). It uses lab-based walkthroughs to illustrate lateral movement and domain takeover, and explains how Qualys ETM Identity maps attack paths, detects toxic privileges, and monitors identity configurations to proactively reduce domain-compromise risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
