{
  "node_id": "mitre-capec-capec-644-use-of-captured-hashes-pass-the-hash",
  "title": "MITRE CAPEC-644: Use of Captured Hashes (Pass The Hash) (Detailed Attack Pattern - High Severity)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE CAPEC-644 (Use of Captured Hashes (Pass The Hash)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-522, CWE-836, CWE-308, CWE-294, and others. Relates to MITRE ATT&CK T1550.002.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_attack"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "iso-27001-2022",
    "cis-controls-v8",
    "owasp-asvs-l2",
    "mitre-attack-t1550-use-alternate-authentication-material"
  ],
  "primary_citations_count": 12
}