Holy Shuck! Weaponizing NTLM Hashes as a Wordlist
ID: d75d662a-9b10-556c-974b-f71b74af7ed7
STIX ID: report--d75d662a-9b10-556c-974b-f71b74af7ed7
Feed Name: TrustedSec blog
This report explains "hash shucking," a technique that leverages NTLM (NT) hashes as high-speed candidates in Hashcat to detect password reuse across NT-derived authentication artifacts (NTLMv1/v2, Kerberos etype 23, DCC/DCC2) without recovering plaintext. It details relevant Hashcat modes, demonstrates two offensive scenarios using DCSync/Kerberoast and LSA/DCC2 extraction to prove cross-domain reuse, quantifies speed advantages of attacking NT hashes versus slower formats, and recommends mitigations such as eliminating RC4/etype 23, enforcing AES-only Kerberos, using managed service accounts and LAPS, and reducing password reuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
