An attack that bypasses authentication using a stolen password hash directly, without needing to know the plaintext password.
Exploiting mechanisms such as Windows NTLM authentication, where the server validates a hash value, an attacker presents a stolen hash as-is to impersonate the user. It's a common technique for lateral movement from a compromised machine to other systems.
© 2026 ITBGM