Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1187 ✕
Download CSV Show ATT&CK heatmapSuspicious NTLM authentication with machine account Informational Identity Analytics 1 variation
A suspicious NTLM authentication attempt was made by a machine account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Forced Authentication (T1187)Required data: Palo Alto Networks Firewall EAL Logs XDR AgentAttacker's goals: An attacker aims to exploit authentication protocols to steal credentials and enable lateral movement within the network.Investigative actions: Identify the source and target users and hosts involved in the NTLM authentication attempt. Monitor the users associated with the authentication for any further suspicious activities or unauthorized actions. Look for earlier connections to the source which may cause it to initiate the session. Investigate the root cause of the behavior and determine if it can be mitigated or blocked in the future.Variations
Rare and sensitive NTLM authentication with machine account
Low overridden
A rare and sensitive NTLM authentication attempt was made by a machine account. overridden