Analytics BIOC Informational

Rare NTLM Access By User To Host

An unusual NTLM authentication attempt by a user to a host. This may indicate the use of stolen credentials or access tokens to access restricted hosts.

Module:
Identity Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Use Alternate Authentication Material (T1550)
Attacker's goals:

The attacker may be attempting lateral movement within a compromised network.

Investigative actions:

Verify any successful authentication for the user account referenced by the alert, as this could indicate the attacker has used stolen credentials.

Test period:
N/A (single event)
Deduplication:
1 Day