Loading...
Windows Events

NTLM server blocked in the domain audit: Audit NTLM authentication in this domain

Event ID 8003 Microsoft-Windows-NTLM/Operational Network security: Restrict NTLM: Audit NTLM authentication in this domain

Main fields

IP address
IP
Windows IP
ELK -
Microsoft Sentinel -
QRadar -
Splunk -
Computer name
Computer
Windows Computer
ELK winlog.computer_name
Microsoft Sentinel -
QRadar -
Splunk -
User name
UserName
Windows User
ELK winlog.event_data.UserName
Microsoft Sentinel -
QRadar -
Splunk -
Important field
ProcessName
Windows Process
ELK winlog.event_data.ProcessName
Microsoft Sentinel -
QRadar -
Splunk -

Fields

Windows Raw Windows ELK Microsoft Sentinel QRadar Splunk
UserName User winlog.event_data.UserName - - -
DomainName Domain winlog.event_data.DomainName - - -
Workstation Workstation winlog.event_data.Workstation - - -
CallerPID PID winlog.event_data.CallerPID - - -
ProcessName Process winlog.event_data.ProcessName - - -
LogonType Logon type winlog.event_data.LogonType - - -
MechanismOID Mechanism winlog.event_data.MechanismOID - - -
IP System field IP System field - - - -
Computer System field Computer System field winlog.computer_name - - -
ProcessID System field ProcessID System field winlog.process.pid - - -
ThreadID System field ThreadID System field winlog.process.thread.id - - -

Sample Event

No Sample Event Provided.

SOCpedia - knowledge platform

This section contains materials on SOC and Blue Team practices: articles, news, books, and translations.