Do you remember the first time you passed the hash?  It probably went a little something like this:

If you are unfamiliar, that is the Metasploit PSexec module being used. Well, nowadays we don’t really do that anymore.  You probably pass the hash something like this:

That is CrackMapExec being used to pass…