NTLMv1 Logon Between Client and Server

 Original Source: [Sigma source]
Title: NTLMv1 Logon Between Client and Server
Status: test
Description:Detects the reporting of NTLMv1 being used between a client and server. NTLMv1 is insecure as the underlying encryption algorithms can be brute-forced by modern hardware.
References:
  -https://github.com/nasbench/EVTX-ETW-Resources/blob/f1b010ce0ee1b71e3024180de1a3e67f99701fe4/ETWProvidersManifests/Windows10/22H2/W10_22H2_Pro_20230321_19045.2728/WEPExplorer/LsaSrv.xml
Author: Tim Shelton, Nasreddine Bencherchali (Nextron Systems)
Date: 2022-04-26
modified:2023-06-06
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1550.002'
Logsource:
  • product: windows
  • service: system
Detection:
  selection:
    Provider_Name: 'LsaSrv'
    EventID:
      -'6038'
      -'6039'

  condition:selection
Falsepositives:
  -Environments that use NTLMv1
Level: medium