IP Library Granted Patent US 11,916,953
Granted Patent B2
US 11,916,953 · App. 16/579,215 · Granted Feb 27, 2024

Method and mechanism for detection of pass-the-hash attacks

Inventor: Phillip Tsukerman (Tel Aviv, IL)
Assignee: Cybereason, Inc.
H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,953
App. No.
16/579,215
Granted
Feb 27, 2024
Kind
B2
Abstract

A method of generating a baseline of expected behavior on a single machine or endpoint to accurately fingerprint the native behavior of the NTLM protocol on that particular endpoint in a network. By limiting the scope of a baseline to a single endpoint, the scope of the baseline can consist of expected behavior (including supported hash functions, version strings and various feature flags). Deviations from these behaviors are considered evidence of a redundant implementation of NTLM utilized by an attacker and thus as evidence of an attempted PTH attack. Using this method it is possible to accurately detect PTH attacks originating from all publicly known non-standard implementations of NTLM existing in tools such as Impacket, Metasploit, and Invoke-TheHash.

Claims (22)

1. A computer-implemented method of preventing a malicious attack on a networked system comprising an endpoint machine, the computer-implemented method comprising:

generating, by an agent executing on the endpoint machine, a plurality of baseline fingerprints of system activity of the networked system, the plurality of baseline fingerprints comprising baseline representations of the system activity;

monitoring, by the agent, real-time system activity on the endpoint machine after said plurality of baseline fingerprints is generated;

generating, by the agent, a plurality of real-time fingerprints based on the real-time system activity on the endpoint machine;

determining, by the agent, that a Pass-the-Hash (PTH) attack is occurring by:

comparing the plurality of real-time fingerprints to the plurality of baseline fingerprints based on the endpoint machine, and

detecting a deviation between the plurality of real-time fingerprints and the plurality of baselines fingerprints; and

flagging the real-time system activity associated with the detected deviation.

2. The computer-implemented method of claim 1 wherein the agent collects information on operating system (OS) implemented libraries as a portion of the fingerprint.

3. The computer-implemented method of claim 2 wherein the agent flags a loading of additional libraries.

4. The computer-implemented method of claim 2 wherein the agent examines at least one OS cryptographic library and includes at least one implemented cryptographic technique as part of the fingerprint.

5. The computer-implemented method of claim 4 wherein the agent flags a communication that attempts to force a cryptographic technique that is weaker than an available stronger alternative or standard protocol.

6. The computer-implemented method of claim 1 wherein the agent collects identities of processes using a Hypertext Transfer Protocol (HTTP) user-agent strings as part of the fingerprint.

7. The computer-implemented method of claim 6 wherein the agent detects inconsistencies based on the fingerprint between identities of a single process and user-agent strings being used in communication.

8. The computer-implemented method of claim 6 wherein the agent detect a single process using multiple user-agent strings.

9. The computer-implemented method of claim 8 wherein the agent white-lists known processes allowed to use multiple user-agent strings.

10. The computer-implemented method of claim 9 wherein the known processes are known spiders.

11. The computer-implemented method of claim 1 wherein the agent detects an existence of non-standard implementations of New Technology LAN Manager (NTLM).

12. The computer-implemented method of claim 1 , wherein at least one of the plurality of baseline fingerprints comprises at least one of implemented communication sockets or user agent strings associated with authorized processes running on the endpoint machine.

13. The computer-implemented method of claim 1 , further comprising:

receiving, by the agent, an indication that the detected deviation is a false positive; and

based on the indicating, modifying, by the agent, the plurality of baseline fingerprints to include activity that triggered the flagging.

Assignments (7)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 054517/0199) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0912 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2023
From: SOFTBANK CORP.
To: CYBEREASON INC.
Reel/Frame 064108/0725 →
SECURITY INTEREST Recorded May 5, 2023
From: CYBEREASON INC.
To: SOFTBANK CORP.
Reel/Frame 063550/0415 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2021
From: TSUKERMAN, PHILLIP
To: CYBEREASON, INC.
Reel/Frame 055049/0438 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 25, 2020
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054517/0199 →
Continuity (2)
Provisional Application 62735745 · Sep 24, 2018
Related Publication 20200099715A1 · Mar 26, 2020