Name:Windows Unusual NTLM Authentication Destinations By User id:a4d86702-402b-4a4f-8d06-9d61e6c39cad version:10 date:None author:Steven Dick status:production type:Anomaly Description:The following analytic detects when an unusual number of NTLM authentications is attempted by the same user account against multiple destinations. This activity generally results when an attacker attempts to brute force, password spray, or otherwise authenticate to numerous domain joined Windows devices using an NTLM based process/attack. This same activity may also generate a large number of EventID 4776 events as well. Data_source:
```CIM alignment, remove leading \\ from some auth attempts ``` | eval src = replace(WorkstationName,"\\\\","")
``` CIM alignment``` | eval dest = SChannelName, user = UserName
``` Remove NTLM auths to self, improves accuracy for certain applications ``` | where SChannelName!=src
| stats count min(_time) as firstTime max(_time) as lastTime dc(eval(upper(dest))) as unique_count by user | eventstats avg(unique_count) as unique_avg stdev(unique_count) as unique_std
``` adjust formula for sensitivity``` | eval upperBound_unique=(1+unique_avg+unique_std*3)