Event ID 8001 — NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blocked.
Description
NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blocked.
Message #
Fields #
| Name | Description |
|---|---|
TargetName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
CallerPID UInt32 | — |
ProcessName UnicodeString | — |
ClientLUID HexInt64 | — |
ClientUserName UnicodeString | — |
ClientDomainName UnicodeString | — |
MechanismOID UnicodeString | — |
Detection Rules #
View all rules referencing this event →
Sigma # view in reference
- Potential Remote Desktop Connection to Non-Domain Host source medium: Detects logons using NTLM to hosts that are potentially not part of the domain.