NTLM Security Protocol

3 events across 1 channel

Event IDTitleChannel
0NTLM Server AcceptETW Trace
1NTLM Client InitializeETW Trace
2NTLM Validate CredentialsETW Trace

Event ID 0 — NTLM Server Accept

Provider
NTLM Security Protocol
Channel
ETW Trace

Fields

NameDescription
StageHint
InContext
OutContext
Flags
UserName
DomainName
Workstation

Event ID 1 — NTLM Client Initialize

Provider
NTLM Security Protocol
Channel
ETW Trace

Fields

NameDescription
StageHint
InContext

Event ID 2 — NTLM Validate Credentials

Provider
NTLM Security Protocol
Channel
ETW Trace

Fields

NameDescription
Success
LogonServer
LogonDomain
UserName
Workstation