Skip to content

Latest commit

 

History

History
7 lines (7 loc) · 375 Bytes

A user authenticated with weak NTLM to multiple hosts.md

File metadata and controls

7 lines (7 loc) · 375 Bytes

Description

A user account authenticated to multiple hosts via NTLMv1 or LM authentication for the first time in the past 30 days.

Attacker's Goals

The attacker attempts to gain access to the accounts.

Investigative Actions

Audit all login events with a weaker protocol and review any anomalous usage. Investigate the mentioned user for additional suspicious activity.