Suspicious NTLM authentication with machine account
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Forced Authentication (T1187)
Severity
Informational
Description
A suspicious NTLM authentication attempt was made by a machine account.
Attacker's Goals
An attacker aims to exploit authentication protocols to steal credentials and enable lateral movement within the network.
Investigative actions
Identify the source and target users and hosts involved in the NTLM authentication attempt.
Monitor the users associated with the authentication for any further suspicious activities or unauthorized actions.
Look for earlier connections to the source which may cause it to initiate the session.
Investigate the root cause of the behavior and determine if it can be mitigated or blocked in the future.
Variations
Was this helpful?
