CTD-000077

AD domain allowing NTLM authentication

Medium
Active Directory
Credential Access Defense Evasion Lateral Movement Privilege Escalation
v36

Signature Identity

CTD-000077
Threat ID
36
Version
IOE
Indicator Type

Threat Description

NTLM and NTLMv2 authentication is vulnerable to various malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards.

Malicious attacks on NTLM authentication traffic resulting in a compromised server or domain controller can occur only if the server or domain controller handles NTLM requests. If those requests are denied, this attack vector is eliminated.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Before completely disabling NTLM in a domain and switching to Kerberos, ensure that there are no applications in the domain that require and use NTLM authentication. To track the usage of NTLM authentication:

  1. Open the Default Domain Controller Policy.
  2. Navigate to the Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options section.
  3. Find and enable the Network Security: Restrict NTLM: Audit NTLM authentication in this domain policy.
  4. Set its value to Enable all.
  5. Also, enable the following policies in the Default Domain Policy:
    1. Network Security: Restrict NTLM: Audit Incoming NTLM Traffic – set its value to Enable auditing for domain accounts.
    2. Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers: set Audit all.
  6. Check the events with Event ID 4624 from the source Microsoft-Windows-Security-Auditing: “An Account was successfully logged on“. See the information in the “Detailed Authentication Information” section. If there is NTLM in the Authentication Package value, then the NTLM protocol was used to authenticate this user. Identify servers and applications that are using the legacy protocol.
To disable NTLM on the Active Directory domain use the Network Security: Restrict NTLM: NTLM authentication in this domain policy. Learn more.

Frequently Asked Questions

What does AD domain allowing NTLM authentication mean?

An Active Directory environment domain configured for NTLM (NT LAN Manager) authentication allows Windows systems to authenticate using a less secure method. This can lead to exposure of sensitive information, including user and group details.

The use of NTLM protocol exposes sensitive data, enabling attackers to gather domain details for potential exploitation, but does not grant administrative control.

Attackers can exploit the vulnerability by using the NTLM protocol to enumerate users, groups, and other domain details, which can aid in planning a more serious intrusion. This unauthorized access also enables attackers to gather information about domain permissions and credentials.

Cayosoft Guardian continuously monitors Active Directory environment configurations, detecting when the NTLM protocol is enabled. When this condition is identified, Guardian flags the issue to alert administrators of potential exposure.

Cayosoft Guardian alerts administrators to disable the NTLM protocol in their Active Directory environment, limiting sensitive data exposure and reducing reconnaissance capabilities. This action supports investigation by providing visibility into changes made to the environment.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Domain-wide GPO
Attack Tactics
Credential Access Defense Evasion Lateral Movement Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical