In enterprise architectures, migrating workloads to Microsoft Entra ID often leaves a substantial blind spot unresolved: legacy NTLM authentication across on-premises Active Directory networks. The Pass-the-Hash attack (PtH - MITRE ATT&CK T1550.002) remains an adversary's primary technique to pivot from local workstation compromise to full tenant administrative takeover.
Attack Anatomy: From Local Dumping to Cloud Pivot
When an attacker lands local administrative access on an endpoint, they extract NTLM hashes directly from the lsass.exe memory space using reflective API calls or specialized tooling. Because NTLM uses a challenge-response mechanism that validates the hash rather than the cleartext password, stolen hashes act as permanent authentication tokens.
In a hybrid deployment, the consequences escalate rapidly:
- Lateral Movement to Identity Connectors: The attacker executes network logons using NTLM against intermediate Tier-1 servers and targeting Microsoft Entra Connect sync engines.
- Credential Extraction: Harvesting privileged accounts such as
MSOL_instances or service agents allows an adversary to alter hybrid directory state. - Bypassing Cloud Controls: By pivoting to synchronized accounts or manipulating directory synchronization attributes, the attacker compromises cloud identities, effectively circumventing standard Conditional Access rules when compliant device requirements are not enforced.
The Native Visibility Gap
Traditional domain controller auditing sees an incoming NTLM authentication (LogonType 3, Event ID 4624) as valid and authorized. The domain controller cannot distinguish between a genuine network logon and a replayed NTLM hash. High-fidelity detection requires cross-layer correlation: joining endpoint behavioral telemetry from Defender for Endpoint (monitoring memory access to lsass.exe) with domain-level protocols parsed by Defender for Identity.
Advanced Hunting KQL Query
The following query bridges local LSASS access with rapid network logons executed over NTLM by privileged or synchronization accounts within a 30-minute window:
let timeframe = 2h;
let LsassDumps = DeviceEvents
| where Timestamp > ago(timeframe)
| where ActionType == "ProcessAccess" and FileName =~ "lsass.exe"
| where InitiatingProcessFileName !in~ ("MsMpEng.exe", "SenseCncProxy.exe")
| summarize DumpTime = min(Timestamp) by DeviceName;
IdentityLogonEvents
| where Timestamp > ago(timeframe) and LogonType == "Network"
| where Protocol has "NTLM" and AccountName matches regex @"(?i)^(adm_|svc_|msol_|sync_)"
| lookup kind=inner (
DeviceNetworkInfo | extend ClientIP = tostring(parse_json(IPAddresses)[0].IPAddress)
| project DeviceName, ClientIP
) on $left.IPAddress == $right.ClientIP
| join kind=inner (LsassDumps) on DeviceName
| where (Timestamp - DumpTime) between (0min .. 30min)
| summarize TargetCount = dcount(DestinationDeviceName), Targets = make_set(DestinationDeviceName, 5)
by bin(Timestamp, 10m), CompromisedHost = DeviceName, IPAddress, AccountUpn, ProtocolAutomated SOAR Response with Akuity SOC
Manual triage of credential dumping often leaves enough runway for the threat actor to complete lateral movement. Akuity SOC automates critical incident workflows:
- Instant AI-Powered Deobfuscation: The Akuity SOC in-app AI assistant analyzes and deobfuscates memory extraction CLI commands in under 2 seconds, eliminating the risk of external web tooling leaks.
- One-Click Response Actions: Trigger
isolateDevice()on the patient zero host and invokerevokeSessions()against impacted privileged identities directly from the evidence canvas. - Regulatory Audit Compliance: Every remediation action enforces AAL2 MFA verification and writes an immutable audit record fulfilling NIS 2 and SOC 2 Type II governance standards.
Accelerate containment with automated SOAR playbooks and stop Pass-the-Hash lateral movement across Active Directory and Microsoft Entra ID in under 60 seconds.
Start your 14-day free trial of Akuity SOC today — no credit card required →Technical Mini-FAQ
How can organizations eliminate NTLM usage safely?
Enable NTLM auditing via Group Policy Objects (NTLM Auditing: Event IDs 8001 through 8004). Identify unconstrained applications, configure Kerberos SPNs, and systematically add administrative accounts to the Protected Users security group, which programmatically denies NTLM caching.
Why is Defender for Identity mandatory to catch Pass-the-Hash?
Defender for Identity monitors raw domain controller network traffic via sensor agents. It spots reconnaissance activity (such as SAM-R queries) and anomalous NTLM authentications that bypass host-based endpoint protection visibility.