logo

Azure Account Hijacking using mimikatz’s lsadump::setntlm

ID: 57472ab3-b372-5e0f-a444-735b6452b195

STIX ID: report--57472ab3-b372-5e0f-a444-735b6452b195

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

## Executive Summary This report details an account-hijacking technique where an attacker with AD replication privileges extracts a target's NTLM hash (DCSync), uses Mimikatz to set a temporary password/NTLM (lsadump::setntlm / lsadump::changentlm), waits for Azure AD replication to gain access to Office 365 and on-prem resources, then restores the original hash to reduce detection. The write-up includes step-by-step actions, screenshots from a lab, IoCs (Windows event IDs 4724 and 4738 and password-history entries), and mitigation guidance recommending MFA, Conditional Access, and trusted-device/network restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.