[{"data":1,"prerenderedAt":703},["ShallowReactive",2],{"post-ntlm-analyzer":3,"post-list":470},{"id":4,"title":5,"body":6,"category":446,"date":447,"description":448,"draft":449,"extension":450,"image":451,"links":452,"meta":457,"navigation":458,"path":459,"readingTime":460,"seo":461,"stem":462,"tags":463,"__hash__":469},"posts\u002Fposts\u002Fntlm-analyzer.md","NTLM-Analyzer: Find Out Who Still Uses NTLM",{"type":7,"value":8,"toc":437},"minimark",[9,13,16,19,24,27,39,45,56,63,66,70,76,82,101,107,117,123,130,136,142,148,154,160,166,172,175,179,194,200,274,284,290,312,323,329,340,343,349,353,356,398,405,409,416,419,422,430,433],[10,11,12],"p",{},"I've worked for IT security service providers, and every now and then the job was to turn off NTLM in an Active Directory domain. Windows logs a lot of NTLM activity, so in theory you have everything you need. In practice you have to piece it all together yourself. There was never a quick and easy way to see which user or process still uses NTLMv1 or NTLMv2, or which programs already use Kerberos.",[10,14,15],{},"The information is spread over every machine in the domain. Event 8001 on the client tells you which process sent NTLM. Event 8003 on the server tells you which service accepted it. Event 8004 on the domain controller tells you who authenticated against what. And on anything older than Server 2025, the NTLM version is only in the 4624 logon event on the server. Some of these events don't even have named fields, Microsoft ships them as a plain list of values.",[10,17,18],{},"So I built a tool for it, for myself and for anyone else who has to do the same job. It's called NTLM-Analyzer.",[20,21,23],"h2",{"id":22},"what-it-is","What it is",[10,25,26],{},"It has two parts, and I wanted both of them to be as simple as possible.",[10,28,29,33,34,38],{},[30,31,32],"strong",{},"The collector"," runs on Linux and is based on Python. It's one single file without any additional dependencies, so no ",[35,36,37],"code",{},"pip install"," and no database server, everything goes into SQLite. You just start it and you're done. If you want it to run as a service, there is an installer script that does everything automatically. It even creates its own service account and runs the collector under it. The collector also serves the web dashboard.",[10,40,41,44],{},[30,42,43],{},"On Windows"," you only need a small agent written in Rust, on every machine you want to see, domain controllers included. It runs as a Windows service, reads the NTLM and logon events and sends them to the collector. It's a single EXE, or an MSI if you want to install it unattended. The agent doesn't listen on any port, it only sends.",[10,46,47,48,55],{},"If you want to see it before you install anything, there is a ",[49,50,54],"a",{"href":51,"rel":52},"https:\u002F\u002Fnobrac.github.io\u002FNTLM-Analyzer\u002Fdemo\u002F",[53],"nofollow","live demo"," with the real dashboard on made-up lab data. Everything works there, including the search, the filters and the detail views.",[10,57,58],{},[59,60],"img",{"alt":61,"src":62},"The overview: NTLM share, the handover bar from NTLMv1 to Kerberos, the countdown to October 2026 and the trend","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Foverview.webp",[10,64,65],{},"The first thing you see is the share of logons that still go through NTLM, and whether it's going down. The bar below it is the handover: red is NTLMv1, yellow NTLMv2, green Kerberos. The goal is a bar that's completely green.",[20,67,69],{"id":68},"what-it-shows-you","What it shows you",[10,71,72,75],{},[30,73,74],{},"Who still uses NTLMv1."," That's the first thing I always wanted to know, because NTLMv1 is the urgent part. The dashboard lists every account with how often it used NTLMv1. It also tells you where it can't see NTLMv1, for example on a machine without logon auditing. An empty list there doesn't automatically mean \"no NTLMv1\".",[10,77,78],{},[59,79],{"alt":80,"src":81},"Insecure logons by user, with a hint on which machines NTLMv1 is invisible","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Fntlmv1.webp",[10,83,84,87,88,92,93,96,97,100],{},[30,85,86],{},"Which program uses NTLM, and against which server."," This is the work list. Every program with its target, how often, the trend and the users behind it. You can set each row to ",[89,90,91],"em",{},"open",", ",[89,94,95],{},"in progress"," or ",[89,98,99],{},"done",". If something you marked as done shows up again, it gets an \"active again\" badge.",[10,102,103],{},[59,104],{"alt":105,"src":106},"Programs still using NTLM, with target server, count, trend, users and status","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Fprograms.webp",[10,108,109,112,113,116],{},[30,110,111],{},"Why it wasn't Kerberos."," This panel turns the findings into fixes. On Windows 11 24H2 and Server 2025 the new NTLM events contain the reason why Kerberos wasn't used. On older systems the tool takes the failed Kerberos requests instead (event 4769, for example ",[35,114,115],{},"0x7"," for \"SPN not found\"). Every reason comes with what usually fixes it. The classic is still a script or a drive mapping that uses an IP address instead of a host name.",[10,118,119],{},[59,120],{"alt":121,"src":122},"Why NTLM was used: each reason with what helps","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Fwhy-ntlm.webp",[10,124,125,126,129],{},"Since version 2.4 there is also an SPN check. A domain controller with the agent looks up in AD every service name that clients fell back to NTLM for. It tells you if the SPN is missing, registered twice, or only registered for the real server name while the clients use an alias. You get the ",[35,127,128],{},"setspn"," command to fix it. The lookup is read-only, the tool itself never changes anything in AD.",[10,131,132],{},[59,133],{"alt":134,"src":135},"The SPN check with the setspn command for each finding","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Fspn-check.webp",[10,137,138,141],{},[30,139,140],{},"What already runs over Kerberos."," The good side, for contrast. Here you also see which services still get RC4 tickets.",[10,143,144],{},[59,145],{"alt":146,"src":147},"Services that already use Kerberos, with the encryption types","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Fkerberos.webp",[10,149,150,153],{},[30,151,152],{},"When NTLM happens."," A heatmap with weekdays against hours. A batch job that runs once a week at night disappears in the daily numbers. Here it stands out right away, and that's exactly the kind of thing that breaks after you switch NTLM off.",[10,155,156],{},[59,157],{"alt":158,"src":159},"Heatmap of NTLM activity per weekday and hour","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Ftiming.webp",[10,161,162,165],{},[30,163,164],{},"Which machines are ready."," A machine counts as ready when auditing is on, it was watched for 30 days and there was no NTLM in that time. Then you can set \"Restrict NTLM\" to deny there. For the ones that aren't ready, you see what is still using NTLM.",[10,167,168],{},[59,169],{"alt":170,"src":171},"Ready to switch off, per machine, outgoing and incoming","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Fready-to-switch-off.webp",[10,173,174],{},"There is a lot more in it: failed NTLM logons with the reason in plain words, password spraying, machines that use NTLM but run no agent, and a CSV export. And there is a status report that you can print or save as PDF, in German or English, for everyone who will never open a dashboard.",[20,176,178],{"id":177},"getting-started","Getting started",[10,180,181,182,187,188,193],{},"The short version. The ",[49,183,186],{"href":184,"rel":185},"https:\u002F\u002Fgithub.com\u002FNobrac\u002FNTLM-Analyzer",[53],"README"," has the details, and the ",[49,189,192],{"href":190,"rel":191},"https:\u002F\u002Fgithub.com\u002FNobrac\u002FNTLM-Analyzer\u002Fblob\u002Fmain\u002Fdocs\u002FOPERATIONS.md",[53],"operations guide"," has everything else.",[10,195,196,199],{},[30,197,198],{},"1. Turn on auditing by GPO."," Without it nothing gets logged, and the events only start from the moment auditing is on, not retroactively.",[201,202,203,219],"table",{},[204,205,206],"thead",{},[207,208,209,213,216],"tr",{},[210,211,212],"th",{},"Where",[210,214,215],{},"Setting",[210,217,218],{},"Value",[220,221,222,236,248,261],"tbody",{},[207,223,224,228,231],{},[225,226,227],"td",{},"All machines",[225,229,230],{},"Restrict NTLM: Outgoing NTLM traffic to remote servers",[225,232,233],{},[35,234,235],{},"Audit all",[207,237,238,240,243],{},[225,239,227],{},[225,241,242],{},"Restrict NTLM: Audit Incoming NTLM Traffic",[225,244,245],{},[35,246,247],{},"Enable auditing for domain accounts",[207,249,250,253,256],{},[225,251,252],{},"Domain controllers",[225,254,255],{},"Restrict NTLM: Audit NTLM authentication in this domain",[225,257,258],{},[35,259,260],{},"Enable all",[207,262,263,266,269],{},[225,264,265],{},"DCs and member servers",[225,267,268],{},"Advanced Audit Policy: Audit Logon",[225,270,271],{},[35,272,273],{},"Success and Failure",[10,275,276,277,279,280,283],{},"Make sure you choose ",[35,278,235],{}," and not ",[35,281,282],{},"Deny all",". Auditing only logs, it doesn't block anything.",[10,285,286,289],{},[30,287,288],{},"2. Install the collector"," on a Linux server, from the cloned repository:",[291,292,297],"pre",{"className":293,"code":294,"language":295,"meta":296,"style":296},"language-bash shiki shiki-themes gruvbox-dark-medium","sudo .\u002Finstall.sh\n","bash","",[35,298,299],{"__ignoreMap":296},[300,301,304,308],"span",{"class":302,"line":303},"line",1,[300,305,307],{"class":306},"s59W0","sudo",[300,309,311],{"class":310},"sTqo2"," .\u002Finstall.sh\n",[10,313,314,315,318,319,322],{},"The script asks a few questions (port, API key for the agents, how long to keep the data, TLS certificate), creates the service account and the systemd service, and opens the port in the firewall if you want. At the end it prints the exact command for the agent install. If you only want to try it quickly, you can also just run ",[35,316,317],{},"python3 ntlm-collector.py",", and ",[35,320,321],{},"--help"," shows all options.",[10,324,325,328],{},[30,326,327],{},"3. Install the agent"," on every Windows machine. That's the small Rust agent from above, you find the MSI in the releases:",[291,330,334],{"className":331,"code":332,"language":333,"meta":296,"style":296},"language-cmd shiki shiki-themes gruvbox-dark-medium","msiexec \u002Fi ntlm-agent.msi \u002Fqn COLLECTORURL=https:\u002F\u002Fcollector.example.local:8443\n","cmd",[35,335,336],{"__ignoreMap":296},[300,337,338],{"class":302,"line":303},[300,339,332],{},[10,341,342],{},"By default the agent runs as LocalSystem. If you prefer least privilege, it also runs as a gMSA.",[10,344,345,348],{},[30,346,347],{},"4. Open the dashboard."," In the machine list every agent should show up with a green heartbeat, and the audit badges turn green once the GPO has arrived on the machine.",[20,350,352],{"id":351},"before-you-switch-ntlm-off","Before you switch NTLM off",[10,354,355],{},"The tool tells you what still uses NTLM. It does not switch anything off, and that's on purpose. A few things I would check before you do:",[357,358,359,366,376,386,392],"ul",{},[360,361,362,365],"li",{},[30,363,364],{},"Let it run for at least two weeks."," Weekly tasks and month-end jobs only show up over time. The dashboard warns you as long as there are less than 14 days of data.",[360,367,368,371,372,375],{},[30,369,370],{},"Make the NTLM log bigger."," The default size of the NTLM\u002FOperational log is only about 1 MB. Once incoming auditing is on, it can roll over between two collection runs, and those events are gone. ",[35,373,374],{},"wevtutil sl Microsoft-Windows-NTLM\u002FOperational \u002Fms:20971520"," sets it to 20 MB.",[360,377,378,385],{},[30,379,380,381,384],{},"Set ",[35,382,383],{},"LmCompatibilityLevel"," to 5 first."," A machine can go months without a single NTLMv1 logon and still allow it. The machine list shows the level for every machine.",[360,387,388,391],{},[30,389,390],{},"Clients and member servers first, domain controllers last."," And make sure you have console access to at least one DC (iLO, iDRAC, vSphere) before you enforce anything there.",[360,393,394,397],{},[30,395,396],{},"Look at October 2026."," Microsoft switches NTLMv1-derived SSO credentials to blocking by default this month. Whatever still uses them breaks on its own. Machines with Credential Guard aren't affected, because Credential Guard already prevents NTLMv1. The machine list shows which ones are.",[10,399,400,401,404],{},"And one warning that I want to repeat, because it's the one that hurts the most: ",[30,402,403],{},"MS-CHAPv2 is invisible."," RADIUS, 802.1X and NPS with MS-CHAPv2 don't show up in any NTLM audit event. But they still break as soon as your domain controllers block NTLM. So your Wi-Fi or your network access control can go down while the dashboard looks completely green. If you still use MS-CHAPv2, plan the move to something like EAP-TLS before you restrict NTLM.",[20,406,408],{"id":407},"where-it-stands","Where it stands",[10,410,411,412,415],{},"The current version is 2.4.0. The collector has 67 tests and the agent 34, and they run on every push. I tested everything in a real AD environment. The only exception is the new SPN check, which so far I could only test against a simulated directory. If it reports a name wrongly, ",[35,413,414],{},"ntlm-agent.exe spn-check \u003Cspn>"," on a DC shows exactly what AD answered. Please open an issue with that output.",[10,417,418],{},"To be transparent, like in the README: most of the code was written by Claude in a pair-programming workflow. I defined what it should do, reviewed it and tested it. So please review it before you use it in production, like any code you didn't write yourself.",[10,420,421],{},"It's GPLv3 licensed and on GitHub:",[10,423,424],{},[30,425,426],{},[49,427,429],{"href":184,"rel":428},[53],"github.com\u002FNobrac\u002FNTLM-Analyzer",[10,431,432],{},"If you run it in your domain, I'd like to hear what it found.",[434,435,436],"style",{},"html pre.shiki code .s59W0, html code.shiki .s59W0{--shiki-default:#FABD2F}html pre.shiki code .sTqo2, html code.shiki .sTqo2{--shiki-default:#B8BB26}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":296,"searchDepth":438,"depth":438,"links":439},3,[440,442,443,444,445],{"id":22,"depth":441,"text":23},2,{"id":68,"depth":441,"text":69},{"id":177,"depth":441,"text":178},{"id":351,"depth":441,"text":352},{"id":407,"depth":441,"text":408},"tools","2026-10-03","Windows logs a lot of NTLM activity, but you have to piece it together yourself. I built a tool that shows which users and programs still use NTLMv1 or NTLMv2, and what already runs over Kerberos.",false,"md","\u002Fimages\u002Fposts\u002Fntlm-analyzer\u002Fcover.webp",[453],{"title":454,"description":455,"website":184,"image":456},"NTLM-Analyzer on GitHub","Windows agent in Rust, collector in Python. GPLv3 licensed.","https:\u002F\u002Fgithub.githubassets.com\u002Fimages\u002Fmodules\u002Flogos_page\u002FGitHub-Mark.png",{},true,"\u002Fposts\u002Fntlm-analyzer",6,{"title":5,"description":448},"posts\u002Fntlm-analyzer",[464,465,466,467,468],"active-directory","ntlm","kerberos","auditing","windows-server","ZAoF_nj5MFxwYOOg0VZ-YDC57aFko-XBvtegcEJ-kHk",[471,473,485,493,502,507,514,519,526,531,539,546,551,557,562,567,575,586,592,600,606,613,620,626,633,639,645,651,657,665,671,677,684,691,697],{"path":459,"title":5,"description":448,"date":447,"category":446,"tags":472,"readingTime":460},[464,465,466,467,468],{"path":474,"title":475,"description":476,"date":477,"category":478,"tags":479,"readingTime":484},"\u002Fposts\u002Fwindows-2fa-inside-lsa","Build Your Own 2FA for the Windows Logon, Part 2: Inside LSA","The credential provider from Part 1 only sees the logon screen. Part 2 goes into LSA to close the paths it can't reach, with an authentication package and an MSV1_0 sub-authentication filter in C++.","2026-10-01","windows",[478,480,481,482,483],"credential-provider","lsa","2fa","security",32,{"path":486,"title":487,"description":488,"date":489,"category":478,"tags":490,"readingTime":492},"\u002Fposts\u002Fwindows-2fa-credential-provider","Build Your Own 2FA for the Windows Logon","How a Credential Provider works and how to build a working TOTP 2FA for local Windows accounts in C++. With rate limiting, replay protection and logging.","2026-09-30",[478,480,482,491,483],"totp",60,{"path":494,"title":495,"description":496,"date":497,"category":446,"tags":498,"readingTime":438},"\u002Fposts\u002Fadtierkit-active-directory-tiering","ADTierKit: Automatic AD-Tiering","I got tired of building tier models by hand, so I wrote a tool for it. One PowerShell script, one JSON file.","2026-08-06",[464,468,499,500,501],"powershell","tiering","laps",{"path":503,"title":504,"description":504,"date":497,"category":464,"tags":505,"readingTime":506},"\u002Fposts\u002Fldap-ldaps-and-active-directory","The thing with LDAP, LDAPS and Active Directory",[],11,{"path":508,"title":509,"description":509,"date":510,"category":511,"tags":512,"readingTime":438},"\u002Fposts\u002Finstall-tor-exit-node","Install Tor Exit Node","2025-09-30","linux",[513],"tor",{"path":515,"title":516,"description":516,"date":517,"category":464,"tags":518,"readingTime":303},"\u002Fposts\u002Fconfigure-kerberos-armoring","Configure Kerberos Armoring","2025-07-28",[466],{"path":520,"title":521,"description":521,"date":522,"category":523,"tags":524,"readingTime":525},"\u002Fposts\u002Fexchange-2019-install","Installation guide for Exchange 2019","2025-06-26","exchange",[],47,{"path":527,"title":528,"description":528,"date":529,"category":464,"tags":530,"readingTime":441},"\u002Fposts\u002Fhow-ntlm-works-active-directory","How NTLM works in Active Directory","2025-05-07",[465],{"path":532,"title":533,"description":534,"date":535,"category":464,"tags":536,"readingTime":538},"\u002Fposts\u002Fadfs-installation","ADFS Installation","Basic installation guide for Active Directory Federation Services","2025-01-27",[537],"adfs",4,{"path":540,"title":541,"description":542,"date":543,"category":464,"tags":544,"readingTime":438},"\u002Fposts\u002Fexample-pass-the-hash-attack","Pass the Hash Attack Example","Example of a pass the hash attack","2025-01-22",[545],"pass-the-hash",{"path":547,"title":548,"description":548,"date":549,"category":464,"tags":550,"readingTime":460},"\u002Fposts\u002Fhow-kerberos-works-active-directory","How Kerberos works in Active Directory","2025-01-16",[466],{"path":552,"title":553,"description":553,"date":554,"category":478,"tags":555,"readingTime":438},"\u002Fposts\u002Fconfigure-credential-guard-computer-accounts","Configure Credential Guard for Computer Accounts","2025-01-15",[556],"credential-guard",{"path":558,"title":559,"description":559,"date":560,"category":478,"tags":561,"readingTime":538},"\u002Fposts\u002Fconfigure-credential-guard-windows","Configure Credential Guard","2025-01-13",[556],{"path":563,"title":564,"description":564,"date":560,"category":478,"tags":565,"readingTime":438},"\u002Fposts\u002Fosconfig-windows-server-2025-security","OSConfig - Security Settings for Windows Server 2025",[566],"osconfig",{"path":568,"title":569,"description":570,"date":571,"category":478,"tags":572,"readingTime":438},"\u002Fposts\u002Fsecure-iis-modsecurity","Secure IIS with Modsecurity","Installation guide to secure IIS with Modsecurity","2025-01-12",[573,574],"iis","modsecurity",{"path":576,"title":577,"description":577,"date":578,"category":464,"tags":579,"readingTime":585},"\u002Fposts\u002Fvcsa-certificate-windows-pki","Issue VCSA Certificate with Windows PKI","2025-01-09",[580,581,582,583,584],"ad-cs","pki","vmware","vcsa","vcenter",10,{"path":587,"title":588,"description":588,"date":589,"category":464,"tags":590,"readingTime":591},"\u002Fposts\u002Fwindows-pki-installation","Installation guide for a Windows PKI","2024-12-20",[580,581],36,{"path":593,"title":594,"description":595,"date":596,"category":597,"tags":598,"readingTime":585},"\u002Fposts\u002Fhack-the-box-administrator","Hack The Box: Administrator","Walkthrough for the \"Administrator\" Hack the Box Challenge","2024-11-19","hack-the-box",[599,478,464],"writeup",{"path":601,"title":602,"description":603,"date":604,"category":464,"tags":605,"readingTime":441},"\u002Fposts\u002Fsecure-active-directory-part-1","Secure Active Directory - Part 1","Part 1 of the guide to a secure Active Directory","2024-09-09",[],{"path":607,"title":608,"description":609,"date":610,"category":597,"tags":611,"readingTime":612},"\u002Fposts\u002Fhack-the-box-greenhorn","Hack The Box: Greenhorn","Walkthrough for the \"Greenhorn\" Hack the Box Challenge","2024-07-24",[599,511],12,{"path":614,"title":615,"description":616,"date":617,"category":597,"tags":618,"readingTime":619},"\u002Fposts\u002Fhack-the-box-runner","Hack The Box: Runner","Walkthrough for the \"Runner\" Hack the Box Challenge","2024-07-20",[599,511],9,{"path":621,"title":622,"description":623,"date":624,"category":597,"tags":625,"readingTime":303},"\u002Fposts\u002Fhack-the-box-ghost","Hack The Box: Ghost","Walkthrough for the \"Ghost\" Hack the Box Challenge","2024-07-18",[599,478,464],{"path":627,"title":628,"description":629,"date":630,"category":597,"tags":631,"readingTime":632},"\u002Fposts\u002Fhack-the-box-knife","Hack The Box: Knife","Walkthrough for the \"Knife\" Hack the Box Challenge","2024-07-15",[599,511],7,{"path":634,"title":635,"description":636,"date":637,"category":597,"tags":638,"readingTime":438},"\u002Fposts\u002Fhack-the-box-broker","Hack The Box: Broker","Walkthrough for the \"Broker\" Hack the Box Challenge","2024-07-10",[599,511],{"path":640,"title":641,"description":642,"date":643,"category":597,"tags":644,"readingTime":303},"\u002Fposts\u002Fhack-the-box-permx","Hack The Box: PermX","Walkthrough zur \"PermX\" Hack the Box Challenge","2024-07-08",[599,511],{"path":646,"title":647,"description":648,"date":649,"category":597,"tags":650,"readingTime":438},"\u002Fposts\u002Fhack-the-box-lame","Hack The Box: Lame","Walkthrough zur \"Lame\" Hack the Box Challenge","2024-07-06",[599,511],{"path":652,"title":653,"description":654,"date":655,"category":597,"tags":656,"readingTime":538},"\u002Fposts\u002Fhack-the-box-analytics","Hack The Box: Analytics","Walkthrough zur \"Analytics\" Hack the Box Challenge","2024-06-30",[599,511],{"path":658,"title":659,"description":660,"date":661,"category":597,"tags":662,"readingTime":664},"\u002Fposts\u002Fhack-the-box-sense","Hack The Box: Sense","Walkthrough zur \"Sense\" Hack the Box Challenge","2024-06-28",[599,663],"freebsd",5,{"path":666,"title":667,"description":668,"date":669,"category":597,"tags":670,"readingTime":506},"\u002Fposts\u002Fhack-the-box-mailing","Hack The Box: Mailing","Walkthrough zur \"Mailing\" Hack the Box Challenge","2024-06-26",[599,478],{"path":672,"title":673,"description":674,"date":675,"category":597,"tags":676,"readingTime":438},"\u002Fposts\u002Fhack-the-box-jerry","Hack The Box: Jerry","Walkthrough zur \"Jerry\" Hack the Box Challenge","2024-06-20",[599,478],{"path":678,"title":679,"description":679,"date":680,"category":511,"tags":681,"readingTime":303},"\u002Fposts\u002Flinux-ssh-telegram-notifications","Setting up notifications via Telegram for SSH login\u002Flogoff","2024-06-01",[682,683],"ssh","monitoring",{"path":685,"title":686,"description":687,"date":688,"category":597,"tags":689,"readingTime":690},"\u002Fposts\u002Fhack-the-box-forest","Hack The Box: Forest","Walkthrough zur \"Forest\" Hack the Box Challenge","2024-05-20",[599,478,464],16,{"path":692,"title":693,"description":693,"date":694,"category":523,"tags":695,"readingTime":303},"\u002Fposts\u002Fpowershell-connect-to-exchange-online","Verbindung zu Exchange Online mit Powershell","2023-10-23",[696,499],"m365",{"path":698,"title":699,"description":700,"date":701,"category":523,"tags":702,"readingTime":303},"\u002Fposts\u002Fexchange-october-2023-updates","Exchange Server","Neue Sicherheitsupdates (Oktober 2023)","2023-10-18",[],1791074674585]