Blog

The Cached Credentials Saga: Stopping Pass-the-Hash Exploits

Config hardening
the-dangers-of-cached-credentials

When hackers are successful in accessing user credentials, they can access the resources of an organization and cause a lot of damage as they move laterally. This normally goes unnoticed as the platform trusts the user who has successfully been authenticated. Once authenticated, hackers can exploit other common weaknesses caused through misconfiguration and ultimately gain full domain admin access. This is a common attack technique and a challenge for organizations to detect and respond.

The Risk of Cached Credentials

In a Microsoft Windows environment, credentials are cached on the endpoint. This is sometimes known as cached logon data. This cached information is encrypted using a complex hash known as DCC2 (Domain Cached Credentials version 2). Attempts to decrypt the cache would take far too long, instead a hacking technique known as pass the hash is used.

This technique uses the encrypted NTLM hash of the cached credential to authenticate with the remote server in order to gain access. The attacker does not require to know the plain text password to become authenticated. This is a well-known weakness in the implementation of the authentication protocol because the password hash itself is static between sessions until the password is changed.

Where Current Solutions Fall Short

To help overcome this weakness, Microsoft introduced Credential Guard for Windows 10 operating system (Enterprise edition only). The solution uses a virtualization-based isolation technology which prevents attackers from stealing the hashed credentials.

However, there are several ways hackers are able to bypass this mechanism such as: keylogging, the Internal Monologue attack or with admin rights, you can install an alternative Security Support Provider.

An alternative method is to use other mechanisms that will not cache the credentials such as Windows Hello or Smart Card authentication. However both of these are not popular choices within organizations from an operational standpoint.

Text graphic stating: "Once authenticated, hackers can exploit other weaknesses—such as cached credentials—and ultimately gain full domain admin access.

Organizations that perform pen testing activities either themselves or by a cybersecurity specialist company should check for the existence of cached credentials. An open-source application called Mimikatz is commonly used to identify them. While this will “do the job”, there are some disadvantages of taking this approach.

For most organizations, a pen test is only performed once or twice a year often due to the high cost, people resource time and disruption it causes to the platform. Yet, an attack based on pass the hash can happen at any time, therefore it is something which should be monitored constantly.

Pen Tests are normally performed on a small subset of endpoints of an organization, yet the exploitation of cached credentials is a high risk on all endpoints and users in an organization. Operationally, it would be nearly impossible to run Mimikatz on all endpoints. Not only would it be very time consuming, it would impact productivity of the organization.

Eliminating Security Risks from Cached Credentials

A comprehensive solution should provide continuous monitoring of configuration security risks of all endpoints without negatively impacting operations. Remedio delivers on this by providing real-time visibility into these risks, including the detection of cached credentials to prevent exploitation by bad actors.

With Remedio, SecOps and IT Admins gain complete oversight of configuration security risks, enabling proactive defense. Additionally, Remedio's auto-remediation feature instantly neutralizes threats without interrupting employees whether they are on the network or working remotely.


Secure the top ten risksAttackers Love to Exploit Get the Guide

FAQ

What is a Pass-the-Hash attack?
A Pass-the-Hash (PtH) attack allows an attacker to authenticate using a stolen NTLM password hash instead of the user's plaintext password. Once a hash is obtained from a compromised Windows endpoint, it can be reused to access other systems, making lateral movement significantly easier without needing to crack the password.
Why are cached credentials a security risk?
Windows caches certain credentials to support offline authentication and improve usability. If an attacker compromises a device, these cached credentials or their associated password hashes can become valuable assets for privilege escalation and lateral movement, especially in Active Directory environments.
Can Microsoft Credential Guard completely prevent Pass-the-Hash attacks?
Credential Guard significantly raises the barrier by isolating credential material using virtualization-based security, but it is not a complete solution. Advanced attackers may still attempt alternative techniques, exploit privileged access, or target systems where Credential Guard is not enabled or supported. Organizations should combine it with broader hardening and continuous configuration management.
Why isn't periodic penetration testing enough to detect cached credential risks?
Penetration tests provide a snapshot in time, while endpoint configurations continuously change. Cached credential exposure can appear between assessments as users log on, systems are reconfigured, or policies drift. Continuous monitoring provides much greater assurance than annual or quarterly testing alone.
How can organizations reduce the risk of Pass-the-Hash attacks?
Reducing PtH risk requires multiple controls, including minimizing credential caching where appropriate, enforcing least privilege, enabling security features such as Credential Guard, hardening Windows configurations, monitoring authentication activity, and continuously validating that security settings remain enforced across every endpoint.
What role does continuous configuration management play in protecting cached credentials?
Continuous configuration management helps identify insecure settings, configuration drift, and policy gaps before attackers can exploit them. Automated assessment and remediation ensure that protections against credential theft remain consistently applied instead of relying on manual audits or one-time hardening projects.
How do attackers use cached credentials after compromising an endpoint?
After compromising a device, attackers typically extract password hashes or cached credential data, authenticate to additional systems using those credentials, escalate privileges, and move laterally throughout the environment. This often enables them to reach high-value assets or ultimately obtain domain administrator privileges.
Why is automated remediation important for credential security?
Manual remediation is often too slow to keep pace with changing endpoint configurations. Automated remediation enables organizations to quickly correct insecure settings, maintain consistent hardening across thousands of devices, reduce the exposure window, and prevent configuration drift from reintroducing credential-related risks.

About Author

Bar Bikovsky

Bar Bikovsky

Global cybersecurity sales leader

With a strong background in technology and sales, Bar helps businesses identify and prioritize key challenges — translating technical complexity into clear, actionable solutions. By combining big-picture thinking with hands-on engagement, he plays a pivotal role in expanding Remedio reach & impact.

Fix Misconfigurations Without Fear

Automate configuration security while keeping full control.

Book a Demo