Pass-the-Hash: Remote Exec via WMI/SMB with Explicit Credential Use
Detects common lateral movement patterns associated with Pass-the-Hash (PtH) attacks, specifically identifying remote execution via WMI/services, the use of explicit credentials in management utilities (wmic/net), and suspicious network connections from known administration tools over lateral movement ports.
SentinelOne

