Overpass-the-Hash is a credential misuse technique that bridges Pass-the-Hash and Pass-the-Ticket attacks. It allows attackers to leverage an NTLM hash to request a Kerberos Ticket-Granting Ticket (TGT) from the Key Distribution Center (KDC) in an Active Directory environment, effectively converting NTLM credentials into Kerberos credentials without needing the plaintext password.

MITRE ATT&CK ID: T1550.002


1- Understanding the Attack


2- Steps of an Overpass-the-Hash Attack

a. Initial Access and Hash Extraction

b. Converting NTLM Hash to a Kerberos Ticket

c. Verifying and Using the Kerberos Ticket


3- Key Tools