Analytics BIOC
Informational
✕
Rare NTLM Access By User To Host
An unusual NTLM authentication attempt by a user to a host. This may indicate the use of stolen credentials or access tokens to access restricted hosts.
- Module:
- Identity Analytics
- Data source:
- Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Use Alternate Authentication Material (T1550)
Attacker's goals:
The attacker may be attempting lateral movement within a compromised network.
Investigative actions:
Verify any successful authentication for the user account referenced by the alert, as this could indicate the attacker has used stolen credentials.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day