Insecure functionality - Pass the hash
Description
It is possible to use the Pass The Hash technique to access resources within the domain.
Impact
Use account hashes to access domain resources.
Recommendation
Implement monitoring policies to detect the use of lateral movement techniques such as Pass The Hash.
Threat
Attacker from internal network without authentication with domain user hashes.
Expected Remediation Time
⏱️ 60 minutes.
Requirements
266 - Disable insecure functionalities