LoFP LoFP / legacy hosts

Techniques

Sample rules

NTLM Logon

Description

Detects logons using NTLM, which could be caused by a legacy source or attackers

Detection logic

condition: selection
selection:
  EventID: 8002
  ProcessName|contains: '*'