Skip to content

New Query: NTLM authentication where Kerberos is expected (Baseline)#65

Merged
Polaceka merged 1 commit into
mainfrom
submission/95e4bb93-f9ea-4aab-b0b3-9a65f43e6bed
Jun 18, 2026
Merged

New Query: NTLM authentication where Kerberos is expected (Baseline)#65
Polaceka merged 1 commit into
mainfrom
submission/95e4bb93-f9ea-4aab-b0b3-9a65f43e6bed

Conversation

@byteray-cql-hub-bot

Copy link
Copy Markdown
Contributor

New Query Submission

Name: NTLM authentication where Kerberos is expected (Baseline)
Author: YV Nikhil
Submission ID: 95e4bb93-f9ea-4aab-b0b3-9a65f43e6bed

Description

This query identifies NTLM authentications observed by Active Directory in service‑based authentication contexts where Kerberos is the default and normally preferred mechanism. It filters for NTLM (v1/v2) usage during access to domain services (such as SMB, LDAP, or RPC) by leveraging the presence of a service identifier, which indicates that Kerberos should typically be available. The query aggregates events to highlight recurring NTLM fallback patterns across users, machines, and servers, and is intended for baseline exposure tracking and hygiene monitoring, not direct incident alerting.


This PR was automatically created by the CQL Hub submission pipeline.

@Polaceka Polaceka merged commit e4e1a03 into main Jun 18, 2026
2 checks passed
@Polaceka Polaceka deleted the submission/95e4bb93-f9ea-4aab-b0b3-9a65f43e6bed branch June 18, 2026 21:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant