Pass-the-hash techniques
As you learned in Chapter 9, Performing Network Penetration Testing, the Microsoft Windows operating system does not store the passwords of local users in plaintext. Rather, it converts the passwords into a New Technology LAN Manager (NTLM) hash on newer versions of Windows and stores that within the Security Accounts Manager (SAM) file. Penetration testers usually experience time constraints while conducting a penetration test on an organization. For instance, while cyber-criminals have a lot of time to perform reconnaissance, identify security vulnerabilities, and exploit their targets, penetration testers do not typically have unlimited time. In many cases just a few weeks is allocated to complete a security assessment on specific company assets. This means they must work quickly and efficiently to ensure the goals of the pentesting engagement are met.
Performing password cracking can be a very time-consuming task. While some penetration testers may...