Analytics BIOC
Informational
✕
Suspicious NTLM authentication with machine account
A suspicious NTLM authentication attempt was made by a machine account.
- Module:
- Identity Analytics
- Data source:
- Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Forced Authentication (T1187)
Attacker's goals:
An attacker aims to exploit authentication protocols to steal credentials and enable lateral movement within the network.
Investigative actions:
Identify the source and target users and hosts involved in the NTLM authentication attempt. Monitor the users associated with the authentication for any further suspicious activities or unauthorized actions. Look for earlier connections to the source which may cause it to initiate the session. Investigate the root cause of the behavior and determine if it can be mitigated or blocked in the future.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Rare and sensitive NTLM authentication with machine account Low (parent: Informational)