Digital Forensic Survival Podcast

DFSP # 411 - NTLM Credential Validation


Listen Later

This week I'm talking about detecting evidence of lateral movement on Window systems using NTLM credential validation events. Much like the episode I did on Kerberos, NTLM events offer the same advantage of being concentrated on domain controllers, which allows you, as the analyst, leverage a great resource for user account analysis. I will have the background, artifact breakdown, and triage strategy coming up right after this…..

...more
View all episodesView all episodes
Download on the App Store

Digital Forensic Survival PodcastBy Digital Forensic Survival Podcast

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

60 ratings


More shows like Digital Forensic Survival Podcast

View all
Adversary Universe Podcast by CrowdStrike

Adversary Universe Podcast

78 Listeners