Forum Discussion
Tali Ash
Sep 24, 2019Iron Contributor
Enriched NTLM authentication data using Windows Event 8004
Have you previously experienced NTLM authentications activities that came from unknown devices, such as Workstation or MSTSC? Would you like to discover the actual server being accessed inside the ne...
Christopher Campos
Jun 08, 2021Copper Contributor
Hi, where i configure this "NTLM authentication using Windows Event 8004" in domain controller or in the defender for identity standalone?. I have a implementation where i use defender for identity standalone with port mirroring. Thanks!