mdecrevoisier / Windows-authentication-brutforce-cheatsheet

Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

8004

OxD30bfu5c470R opened this issue · comments

Hi @OxD30bfu5c470R . Thanks for the feedback. ID 8004 (and others below) can be used for deeper NTLM analysis, troubleshooting or migration purposes. However If the intention is to collect them for security purposes (eg: in a SIEM), I would rather suggest to focus on ID 4776 (failures only) and 4625. So far, the mindmap has been updated to reflect your proposal.

8001 | NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blocked.
8002 | NTLM traffic that would be blocked
8003 | NTLM server blocked in the domain audit: Audit NTLM authentication in this domain
8004 | Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.