Pass the Hash Guidance Logo

Pass the Hash Guidance

0
Free
2 saves
Updated 11 March 2025
Visit Website

This project hosts scripts for aiding administrators in implementing Pass the Hash mitigations as outlined in the Reducing the Effectiveness of Pass the Hash paper. The PtHTools module contains the main commands for helping with implementing PtH mitigations: - Find-PotentialPtHEvents - Invoke-DenyNetworkAccess - Edit-AllLocalAccountPasswords - Get-LocalAccountSummaryOnDomain - Invoke-SmartcardHashRefresh - Find-OldSmartcardHash See the PtHTools readme file for more information on how to use them. Guidance: Reducing the Effectiveness of Pass the Hash Long-Lived Hashes for AD Smartcard Required Accounts Limit Workstation-to-Workstation Communication Microsoft guidance: https://aka.ms/pth - Microsoft's Pass-the-Hash general resource page. Mitigating Pass-the-Hash and Other Credential Theft v1 Mitigating Pass-the-Hash and Other Credential Theft v2 How Pass-the-Hash works Local Administrator Password Solution - LAPS is a Microsoft supported tool that ensures local administrator accounts do not all have the same password. It is an alternative to the Edit-AllLocalAccountPasswords command found in PtHTools. krbtgt refresh script - Resets the krbtgt account password twice to invalidate the hash.

FEATURES

SIMILAR TOOLS

Free cyber security training and resources for career development.

A detailed manual for cybersecurity professionals focusing on red team, OSINT, and blue team strategies.

A collection of lab scripts and files for learning about containers and container internals.

Free online class for web security and hacking

Free and open-source cybersecurity training classes with multi-class learning paths for high-skill, high-pay job skills.

Cybrary is an online learning platform that provides accessible and affordable training in cybersecurity skills.

FARA is a repository of purposefully erroneous Yara rules for training security analysts.

A repository aiming to archive all Android security presentations and whitepapers from conferences.

A comprehensive and immersive 13-week course by NYU Tandon's OSIRIS Lab introducing students to offensive security with practical applications and research projects.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved