The Daily Feed
“Freshly brewed IT security, since 2023”
Tools
NTLM-Analyzer: Find Out Who Still Uses NTLM
Windows logs a lot of NTLM activity, but you have to piece it together yourself. I built a tool that shows which users and programs still use NTLMv1 or NTLMv2, and what already runs over Kerberos.
I've worked for IT security service providers, and every now and then the job was to turn off NTLM in an Active Directory domain. Windows logs a lot of NTLM activity, so in theory you have everything you need. In practice you have to piece it all together yourself. There was never a quick and easy way to see which user or process still uses NTLMv1 or NTLMv2, or which programs already use Kerberos.
The information is spread over every machine in the domain. Event 8001 on the client tells you which process sent NTLM. Event 8003 on the server tells you which service accepted it.
