UnPAC-the-Hash NTLM Authentication Following Potential Certificate Abuse
Detects NTLM network logons (NtLmSsp) for accounts that may have been targets of certificate-based identity abuse (e.g., ESC1). Attackers often leverage this technique to extract NTLM hashes from PKINIT TGT PACs and subsequently utilize Pass-the-Hash for lateral movement within the network.
Cortex XDR

