Detection rules › Sigma

NTLM Logon

Severity
low
Author
Florian Roth (Nextron Systems)
Source
upstream

Detects logons using NTLM, which could be caused by a legacy source or attackers

MITRE ATT&CK coverage

TacticTechniques
Defense EvasionT1550.002 Use Alternate Authentication Material: Pass the Hash
Lateral MovementT1550.002 Use Alternate Authentication Material: Pass the Hash

Event coverage

ProviderEvent IDTitle
NTLM8002NTLM server blocked audit: Audit Incoming NTLM Traffic that would be blocked.

Stages and Predicates

Stage 1: selection