|
|
|
|
|
by aja12
148 days ago
|
|
Actually, the real countermeasure to PTH is to disable NTLM auth and rely only on Kerberos (and then monitor NTLM as a very strong indicator that someone or something is attempting PTH) Of course kerberos tickets can be abused too in a lot of fun ways, but on a modern network PTH is pretty much dead and a surefire way to raise a lot of alerts (You are absolutely right that privileged accounts must never login on less privileged assets, however!) |
|