logo

Holy Shuck! Weaponizing NTLM Hashes as a Wordlist

ID: d75d662a-9b10-556c-974b-f71b74af7ed7

STIX ID: report--d75d662a-9b10-556c-974b-f71b74af7ed7

Feed Name: TrustedSec blog

Date Published: 2025-12-09

Date Updated: 2026-05-01

...
...

This report explains "hash shucking," a technique that leverages NTLM (NT) hashes as high-speed candidates in Hashcat to detect password reuse across NT-derived authentication artifacts (NTLMv1/v2, Kerberos etype 23, DCC/DCC2) without recovering plaintext. It details relevant Hashcat modes, demonstrates two offensive scenarios using DCSync/Kerberoast and LSA/DCC2 extraction to prove cross-domain reuse, quantifies speed advantages of attacking NT hashes versus slower formats, and recommends mitigations such as eliminating RC4/etype 23, enforcing AES-only Kerberos, using managed service accounts and LAPS, and reducing password reuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.