Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash

Flags successful Windows NewCredentials (LogonType 9) logons using seclogo with Negotiate, consistent with Overpass-the-Hash behavior.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Roberto Rodriguez (source), Dominik Schaudel (rule) (SigmaHQ), DRL 1.1
Published
2018-02-12
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies successful Windows logons (EventID 4624) with LogonType 9 (NewCredentials) when the logon process is seclogo and the authentication package is Negotiate. Such sessions can indicate credential abuse consistent with Overpass-the-Hash techniques, where attackers obtain access by using alternate credentials rather than an interactive logon. It relies on Windows Security auditing telemetry for successful logon events and the specific logon/session attributes.

Related detections6 linkedT1550.002 — drag to rearrange
Suspicious Registry Modification Disabling RestrictedAdmin Mode (via process_creation)
Suspicious Lateral Movement via Invoke-WMIExec or Invoke-SMBExec (via ps_script)
Windows LsaSrv Events Indicating NTLMv1 Logon Between Client and Server
Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Windows NTLM authentication events (Event ID 8002)
Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Pivot detection · T1550.002 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.