// REFERENCE

4776 — NTLM credential validation

Log: Security Medium risk

The domain controller validated credentials via NTLM. Heavy NTLM use (versus Kerberos) or validations from unexpected hosts can indicate pass-the-hash or misconfigured legacy apps.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.