Analytics BIOC
Informational
✕
Rare NTLM Usage by User
Rare authentication by user account to host via NTLM. The user has not authenticated with NTLM in the past 30 days. This may be indicative of downgrade attacks from Kerberos to NTLM.
- Module:
- Identity Analytics
- Data source:
- Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Use Alternate Authentication Material (T1550)
Attacker's goals:
The attacker is attempting to move laterally within a compromised network.
Investigative actions:
Verify any successful authentication for the user account referenced by the alert, as these can indicate the attacker managed to use the stolen credentials.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day