Name:Windows Unusual NTLM Authentication Destinations By Source id:ae9b0df5-5fb0-477f-abc9-47faf42aa91d version:10 date:None author:Steven Dick status:production type:Anomaly Description:The following analytic detects when an unusual number NTLM authentications is attempted by the same source against multiple destinations. This activity generally results when an attacker attempts to brute force, password spray, or otherwise authenticate to a multiple domain joined Windows devices using an NTLM based process/attack. This same activity may also generate a large number of EventID 4776 events as well. Data_source:
-NTLM Operational 8004
-NTLM Operational 8005
-NTLM Operational 8006
search:`ntlm_audit` EventCode = 8004 SChannelName=* WorkstationName=* ```CIM alignment, remove leading \\ from some auth attempts ``` | eval src = replace(WorkstationName,"\\\\","") | eval dest = SChannelName, user = UserName
``` Remove NTLM auths to self, improves accuracy for certain applications ``` | where SChannelName!=src
| stats count min(_time) as firstTime max(_time) as lastTime dc(eval(upper(dest))) as unique_count by src | eventstats avg(unique_count) as unique_avg stdev(unique_count) as unique_std
``` adjust formula for sensitivity``` | eval upperBound_unique=(1+unique_avg+unique_std*3)