the admin café

Grab a cup.Let's take Windows apart, and put it back together, safer.

A quiet corner for IT security in Windows environments: how attacks work, and what actually stops them. Slow-brewed by Lukas.

35 articles, 13 Hack The Box write-ups, writing since 2023.

The Daily FeedNTLM-Analyzer: Find Out Who Still Uses NTLM
today's roast:
Find Out Who Still Uses NTLM, extra shot
winter special:
hot chocolate, Find Out Who Still Uses NTLM on the side
spring special:
matcha, with Find Out Who Still Uses NTLM
too hot for coffee:
iced, with Find Out Who Still Uses NTLM
pumpkin spice season:
Find Out Who Still Uses NTLM, extra cinnamon
O'zapft is!
Find Out Who Still Uses NTLM und a Brezn
Frohe Weihnachten!
Find Out Who Still Uses NTLM mit Lebkuchen
boo.
Find Out Who Still Uses NTLM, if you dare
Prosit Neujahr!
stir the cup for confetti
Samichlaus isch da!
Find Out Who Still Uses NTLM und en Grittibänz
happy 1st of August!
Find Out Who Still Uses NTLM and a Weggli
Ändlich Fasnacht!
Find Out Who Still Uses NTLM und Chüechli
Frohe Ostern!
Find Out Who Still Uses NTLM mit Osterfladen
the café turns today!
Find Out Who Still Uses NTLM on the house

TODO: patch the DC ✓

SALTfor your hashes

Today's special

fresh off the press
Today's brewCappuccino6 min read

The Daily Feed

“Freshly brewed IT security, since 2023”

Morning editionPrice: freewith every cup
Vol. IV · No. 35Saturday, 3 October 2026theadmincafe.ch · A1

Tools

NTLM-Analyzer: Find Out Who Still Uses NTLM

Windows logs a lot of NTLM activity, but you have to piece it together yourself. I built a tool that shows which users and programs still use NTLMv1 or NTLMv2, and what already runs over Kerberos.

Fig. 1: from today's lead story. Full colour inside.The Admin Café

I've worked for IT security service providers, and every now and then the job was to turn off NTLM in an Active Directory domain. Windows logs a lot of NTLM activity, so in theory you have everything you need. In practice you have to piece it all together yourself. There was never a quick and easy way to see which user or process still uses NTLMv1 or NTLMv2, or which programs already use Kerberos.

The information is spread over every machine in the domain. Event 8001 on the client tells you which process sent NTLM. Event 8003 on the server tells you which service accepted it.

Continued on A2 →

Read the full story →

The cork board

pinned up by the barista

Project #01

NTLM-Analyzer

Shows which users, machines and programs still use NTLMv1 or NTLMv2, and why Kerberos was not used. Agent on Windows, collector on Linux.

who still speaks NTLM?

Rust · Python · GPLv3ArticleGitHub ↗

Project #02

Doppio

Your own second factor for the Windows logon: a credential provider plus an LSA authentication package, in C++.

a double shot for your logon

The pastry case

Hack The Box write-ups, 13 baked so far. Only retired boxes make it into the case: day-old, still delicious.

All 13 boxes →

Stammgast

Become a regular

No newsletter, no tracking, no cookie banner. Just a feed that tells you when a fresh pot is ready.

Subscribe via RSS

Hausordnung

House rules

Found a crack in the cup? Tell the barista, not the whole café. Responsible disclosure details live in security.txt.

Read security.txt

Behind the counter

Meet the barista

Lukas. Wannabe ethical hacker, Hack The Box regular, nine stamps on the cert loyalty card.

servus! →

the admin café

Open whenever the shell is. Right now, apparently.

Tip jar. Costs nothing, cheers me up anyway.

© 2023–2026 Lukas. Servus.

Esc

Fresh today

Type to search all articles. ↑ ↓ and Enter to open a result.