LoFP LoFP / environments that use ntlmv1

Techniques

Sample rules

NTLMv1 Logon Between Client and Server

Description

Detects the reporting of NTLMv1 being used between a client and server. NTLMv1 is insecure as the underlying encryption algorithms can be brute-forced by modern hardware.

Detection logic

condition: selection
selection:
  EventID:
  - 6038
  - 6039
  Provider_Name: LsaSrv