NTLM Hash Harvesting
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall traffic Logs OR XDR Agent
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
OS Credential Dumping (T1003)
Severity
Medium
Description
An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting.
Attacker's Goals
The attacker may attempt to extract NTLM hashes for credential access.
Investigative actions
Check that the destination is not a server.
Verify that the destination is not external to the organization.
Was this helpful?
