For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual weak authentication by user

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detection Modules

Identity Analytics

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Use Alternate Authentication Material (T1550)

Severity

Informational

Description

A user account authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be indicative of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2.

Attacker's Goals

The attacker attempts to gain access to the accounts.

Investigative actions

  • Audit all login events with a weaker protocol and review any anomalous usage.

Was this helpful?