NTLM Logon

 Original Source: [Sigma source]
Title: NTLM Logon
Status: test
Description:Detects logons using NTLM, which could be caused by a legacy source or attackers
References:
  -https://twitter.com/JohnLaTwC/status/1004895028995477505
Author: Florian Roth (Nextron Systems)
Date: 2018-06-08
modified:2024-07-22
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1550.002'
Logsource:
  • product: windows
  • service: ntlm
  • definition: Requires events from Microsoft-Windows-NTLM/Operational
Detection:
  selection:
    EventID: '8002'
  condition:selection
Falsepositives:
  -Legacy hosts
Level: low