NTLM Brute Force

 Original Source: [Sigma source]
Title: NTLM Brute Force
Status: test
Description:Detects common NTLM brute force device names
References:
  -https://www.varonis.com/blog/investigate-ntlm-brute-force
Author: Jerry Shockley '@jsh0x'
Date: 2022-02-02
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1110'
Logsource:
  • product: windows
  • service: ntlm
  • definition: Requires events from Microsoft-Windows-NTLM/Operational
Detection:
  selection:
    EventID: '8004'
  devicename:
    WorkstationName:
      -'Rdesktop'
      -'Remmina'
      -'Freerdp'
      -'Windows7'
      -'Windows8'
      -'Windows2012'
      -'Windows2016'
      -'Windows2019'

  condition:selection and devicename
Falsepositives:
  -Systems with names equal to the spoofed ones used by the brute force tools
Level: medium