Security expert: “Our department considers pass-the-hash attacks our No. 1 threat, above all other computer threats” Hashes can be used to access any protected resource within the same forest. If a domain admin has logged on to a computer, a local attacker can harvest the domain admin authentication hashes right out of memory. The trustworthiness of your domain admin credentials are now an exponential factor of every computer they have ever been used on. Most companies are increasingly worried that determined adversaries will get access to data.”]
Source: https://www.csoonline.com/article/2617564/the-two-most-feared-attacks-and-how-to-avoid-them.html