Windows LsaSrv Events Indicating NTLMv1 Logon Between Client and Server

Flags LsaSrv events 6038/6039 showing NTLMv1 authentication between client and server on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Service
system
Author
Tim Shelton, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-04-26
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags Windows System events from the LsaSrv provider that report NTLMv1 being used for authentication between a client and server. NTLMv1 is insecure because its underlying cryptography can be brute-forced with modern hardware, making sessions vulnerable to credential abuse. It relies on Windows event telemetry for LsaSrv provider events with Event IDs 6038 and 6039 indicating NTLMv1 usage.

Related detections6 linkedT1550.002 — drag to rearrange
Suspicious Registry Modification Disabling RestrictedAdmin Mode (via process_creation)
Suspicious Lateral Movement via Invoke-WMIExec or Invoke-SMBExec (via ps_script)
Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Windows NTLM authentication events (Event ID 8002)
Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Windows LsaSrv Events Indicating NTLMv1 Logon Between Client and Server
Pivot detection · T1550.002 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.