What MITRE CAPEC-644: Use of Captured Hashes (Pass The Hash) (Detailed Attack Pattern - High Severity) requires
MITRE CAPEC-644 (Use of Captured Hashes (Pass The Hash)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary obtains (i.e. steals or purchases) legitimate Windows domain credential hash values to access systems within the domain that leverage the Lan Man (LM) and/or NT Lan Man (NTLM) authentication protocols. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-522, CWE-836, CWE-308, CWE-294, and others. Relates to MITRE ATT&CK T1550.002.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/644.html
SHA-256 integrity: ab602d886a301a7091a7d37b5d41d1c7c3bcd5f13e543578e555103a2e5b558c
Primary Citations — 12 traced to source
- MITRE CAPEC-644: Use of Captured Hashes (Pass The Hash) (https://capec.mitre.org/data/definitions/644.html)
- CWE-522: underlying weakness (http://cwe.mitre.org/data/definitions/522.html)
+ 10 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-capec-capec-644-use-of-captured-hashes-pass-the-hash.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-capec-capec-644-use-of-captured-hashes-pass-the-hash.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-capec-capec-644-use-of-captured-hashes-pass-the-hash
- Back to registry: Browse all 10,085 compliance nodes