Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do stolen NTLM hashes and Kerberos tickets…
Threats, Abuse & Incident Response

Why do stolen NTLM hashes and Kerberos tickets create such high lateral movement risk in enterprise environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Threats, Abuse & Incident Response

Stolen hashes and tickets let an attacker impersonate a legitimate user without knowing the cleartext password. That matters because Windows authentication trusts those artefacts for access across systems, especially where single sign-on is common. Once a privileged token is obtained, the attacker can move from one machine to another and reach domain controllers or other sensitive servers.

Why Stolen NTLM Hashes and Kerberos Tickets Are So Dangerous

NTLM hashes and Kerberos tickets are not just “proof of login”, they are reusable authentication artefacts that often remain trusted inside the enterprise until they expire or are revoked. If an attacker captures one, they can frequently authenticate as that user on other systems without knowing the password, which turns a single compromise into a movement path across servers, workstations, and shared services.

The risk is amplified in environments built around Windows single sign-on, where access is designed to flow smoothly between systems. That convenience also means a stolen ticket or hash can be accepted in multiple places, especially when privilege is broad, segmentation is weak, or the compromised account has access to administrative tools and sensitive data.

In practice, the value of these artefacts is not the credential itself, but the trust relationship it unlocks. A reused or relayed hash can open one machine, then another, while a valid Kerberos ticket can let an attacker impersonate a legitimate session and access resources that would otherwise require interactive authentication.

How This Enables Lateral Movement Across Enterprise Windows Environments

lateral movement becomes easier because Windows authentication is often designed around delegated trust, shared domain services, and predictable access patterns. Once an attacker has a hash or ticket, they can try pass-the-hash, pass-the-ticket, token replay, or related abuse paths to reach file servers, management hosts, jump boxes, or domain controllers.

The decisive factor is usually privilege and reach, not just the captured artefact. A low-value user ticket may have limited effect, but a ticket or hash tied to local admin, service accounts, or domain privileges can quickly expand access into multiple systems and reduce the need for noisy exploitation.

That is why these compromises are so attractive to attackers: they bypass the password challenge and let malicious activity blend into ordinary authentication traffic. If the environment allows reuse across hosts, trusts too much by default, or lacks strong session boundary controls, the attacker can keep moving with minimal friction.

What Makes NTLM and Kerberos Theft a High-Value Attack Path

These artefacts are valuable because they are both authentication material and a shortcut to trust. NTLM hashes can sometimes be relayed or reused, while Kerberos tickets can grant access until expiry and may expose elevated permissions if the issuing account is privileged.

Kerberos is especially risky when attackers obtain service tickets or ticket-granting tickets, because those tokens can preserve access without repeated password checks. In a mature enterprise, this matters most where administrative tiering is weak, service accounts are overprivileged, or credential exposure is not rapidly detected and contained.

Useful background on real-world credential abuse patterns is captured in The 52 NHI Breaches Report, which shows how stolen credentials and lateral movement frequently combine into broader enterprise compromise. For a Windows-specific example, Cisco Active Directory credentials breach illustrates how password-hash exposure can become a direct enterprise access problem.

Risk and Threat Considerations

The main risk is that one stolen hash or ticket can collapse the boundary between “one compromised host” and “wider domain access”. That becomes especially dangerous when privileged accounts, service accounts, or reusable admin sessions are involved, because the artefact can be replayed faster than defenders can usually detect and respond.

Failure mechanism: Attackers steal or relay a trusted authentication artefact, then use it to authenticate to other systems where the enterprise accepts the same trust relationship without revalidating the original password or user intent.

Impact: This can lead to rapid lateral movement, privilege escalation, domain controller access, and broad data exposure before the compromised session is identified and revoked.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1003 — OS Credential DumpingStolen hashes are credential material used for lateral movement and access.
T1550 — Use Alternate Authentication MaterialPass-the-hash and pass-the-ticket rely on stolen auth artefacts.
Recommendation — Hunt for credential dumping and isolate hosts that exposed reusable authentication material. Detect and block alternate authentication material reuse across systems.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeOverprivileged accounts turn stolen hashes and tickets into wider access.
Recommendation — Reduce standing privilege so stolen authentication material cannot reach sensitive systems.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIReusable machine or service credentials become high-risk when overprivileged.
NHI-07 — Long-Lived SecretsStolen tickets and hashes remain useful while still valid or reusable.
NHI-02 — Secret LeakageStolen hashes and tickets are leaked authentication material enabling misuse.
Recommendation — Review and trim privilege on reusable credentials that can move laterally. Shorten credential lifetime and revoke exposed authentication material quickly. Detect secret leakage early and rotate any exposed authentication material.

Practitioner Guidance

What to prioritise: Treat any stolen hash or ticket as an access incident, not a password incident. The first decision is whether the artefact belongs to a privileged, service, or broadly trusted account, because that determines whether the likely blast radius is a single host or the wider domain.

What to verify: Confirm where the same identity can authenticate, whether administrative tiering exists, and whether tickets or hashes could still be valid on other systems. If the account can reach management planes, directory services, or shared infrastructure, containment should be immediate and broader than simple password rotation.

Practitioner takeaway: The real danger is not the stolen artefact alone, but the trust and privilege it already carries across the environment, so containment should be driven by reachable access paths and privilege level, not by the apparent age of the theft.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org