logo

Reliably Detecting Pass the Hash Through Event Log Analysis

ID: f4ea75ca-fb70-51a4-89e3-056a776b3031

STIX ID: report--f4ea75ca-fb70-51a4-89e3-056a776b3031

Feed Name: Binary Defense Blog

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This blog post from Binary Defense explains how to detect Pass-the-Hash (PtH) activity by analyzing Windows security event logs, focusing on Event ID 4624 with Logon Type 3, Logon Process NtLmSsp, a session Key Length of 0, and filtering for local accounts to reduce false positives; it includes practical notes on GPO settings, common false positives (e.g., OWA), and investigative tips such as using source IP and hostname to track the origin of PtH attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.