← Security+ glossary

Malware and malicious activity

Pass-the-hash

A technique in which the attacker authenticates with a stolen password hash, without needing to learn the password itself. It exploits NTLM authentication in Windows environments for lateral movement, and it is mitigated by limiting privileges, Credential Guard and disabling NTLM.

All Security+ guides →

Related terms

Get CertOwl on the App Store

Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations