Analytics Medium

NTLM Hash Harvesting

An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting.

Module:
Identity Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Attacker's goals:

The attacker may attempt to extract NTLM hashes for credential access.

Investigative actions:

Check that the destination is not a server. Verify that the destination is not external to the organization.

Test period:
1 Hour
Deduplication:
1 Day