Analytics
Medium
✕
NTLM Hash Harvesting
An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting.
- Module:
- Identity Analytics
- Data source:
- Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Attacker's goals:
The attacker may attempt to extract NTLM hashes for credential access.
Investigative actions:
Check that the destination is not a server. Verify that the destination is not external to the organization.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day