
A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.
A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.
The tool was published as part of the "Pass-The-Hash detection" research - more details on "Pass-The-Hash detection" are in the blog post:
https://www.cyberark.com/threat-research-blog/detecting-pass-the-hash-with-windows-event-viewer
Full research can be found in the white paper:
https://www.cyberark.com/resource/pass-hash-detection-using-windows-events/
(direct link: http://lp.cyberark.com/rs/cyberarksoftware/images/wp-Labs-Pass-the-hash-research-01312018.pdf)
Account with the following privileges:
Ketshash is a tool for detecting suspicious privileged NTLM connections, based on the following information:
There are two options:
Import-Module .\Ketshash.ps1 or copy & paste Ketshash.ps1 content to PowerShell sessionInvoke-DetectPTH <arguments>alt text
Invoke-DetectPTH -TargetComputers "MARS-7" -LogFile "C:\tmp\log.txt"
alt text
Invoke-DetectPTH -TargetComputers "ComputerName" -StartTime ([datetime]"2017-12-14 12:50:00 PM") -LogFile "C:\tmp\log.txt" -UseKerberosCheck -UseNewCredentialsCheck
alt text
Because it uses threads, it is not possible to debug the script block of the main function.
A workaround can be by using Invoke-Command before the Detect-PTHMultithreaded:
Invoke-Command -ScriptBlock $detectPTHScriptBlock -ArgumentList $TargetComputers, $startTime, $LogFile, $UseKerberosCheck, $UseNewCredentialsCheck, $MaxHoursOfLegitLogonPriorToNTLMEvent`
Detect only one target computer:
Invoke-DetectPTH -TargetComputers "<computer_name>" ...
Change the $TargetComputer to be [string] instead of [array].
This way it is possible to use breakpoints inside the script block of the main function.
For more comments and questions, you can contact Eviatar Gerzi (@g3rzi) and CyberArk Labs.