Name:Windows Unusual NTLM Authentication Users By Source id:80fcc4d4-fd90-488e-b55a-4e7190ae6ce2 version:10 date:None author:Steven Dick status:production type:Anomaly Description:The following analytic detects when an unusual number of NTLM authentications is attempted by the same source. This activity generally results when an attacker attempts to brute force, password spray, or otherwise authenticate to a domain joined Windows device using an NTLM based process/attack. This same activity may also generate a large number of EventID 4776 events in as well. Data_source:
```CIM alignment, remove leading \\ from some auth attempts``` | eval src = replace(WorkstationName,"\\\\","") | eval dest = SChannelName, user = UserName
``` Remove NTLM auths to self, improves accuracy for certain applications``` | where SChannelName!=src
| stats count min(_time) as firstTime max(_time) as lastTime dc(eval(upper(user))) as unique_count by src | eventstats avg(unique_count) as unique_avg stdev(unique_count) as unique_std
``` adjust formula for sensitivity``` | eval upperBound_unique=(1+unique_avg+unique_std*3)