NTLM-Analyzer
Status report · 7 days

NTLM status report

Period 18 Sep 2026 – 25 Sep 20268 agents · data since 11 Aug 2026Generated 25 Sep 2026, 22:38

28.1 % of all logons still go through NTLM.

↑1.8 percentage points more than in the 7 days before.
NTLM share
28.1 %
of all logons
+1.8 pp vs. before
NTLM logons
373
in the period
+9 % vs. before
of which NTLMv1
25
insecure, switch off first
+39 % vs. before
Accounts using NTLM
19
3 of them with NTLMv1
01

Trend

NTLM share per week - the goal is the zero line.

0 %10 %20 %30 %goal 0 %28.1 %last 7 daysWk 34Wk 35Wk 36Wk 37Wk 38
NTLMv1 logons per week
02

Progress

The dashboard's work list, and machines that can switch NTLM off.

4done4in progress56open
4 done in this period
Not done yet, by area
Programs (outgoing)11
Services (incoming)11
Connections (DC view)36
NTLMv1 SSO2
Each row of the dashboard's work lists is one item; whoever removes it marks it "done".

Ready to switch off

2outgoing · of 8 machines
2incoming · of 6 machines
SRV-PRINT, WKS-0107
Auditing on, watched for 30 days, no NTLM in that time: "Restrict NTLM: Deny" can be set here.
03

Risks and visibility

What needs attention first - and where the picture is incomplete.

NTLMv1act

25 NTLMv1 logons from 6 accounts, mostly svc_scan, mfp_service, d.fischer and 3 more. NTLMv1 can be cracked and should be switched off first.

October 2026act

4 logons use NTLMv1-derived credentials. They will break by themselves with the October 2026 change.

Failed logonsact

Possible password spraying: UNKNOWN-PC failed with 8 accounts. Find the machine and the cause.

Visibilitywatch

The picture is incomplete: 2 machines with auditing off, 36 machines use NTLM without an agent.

Relay attackswatch

26 sessions without MIC protection or channel binding - open to NTLM relay.

04

Next steps

Derived from the data, most important first.

  1. Switch off NTLMv1 for svc_scan, mfp_service, d.fischer and 3 more. Set LmCompatibilityLevel 5 on the machines behind it and replace or isolate devices that can only do NTLMv1.
  2. Before October 2026 move the 2 accounts with NTLMv1-derived credentials - otherwise they fail with the change.
  3. Check for password spraying: UNKNOWN-PC failed with 8 accounts.
  4. Fix service names (SPN): 4 are missing or registered wrongly, first cifs/nas01, http/intranet, cifs/archive01 and 1 more - 79 NTLM connections behind them. The setspn commands are in the dashboard.
  5. Tackle the most common cause: Target name could not be resolved by Kerberos (14×). Check the SPN: missing, wrong or duplicated (setspn -X finds duplicates).
  6. Set "Restrict NTLM: Deny" on 2 machines that have not used NTLM for 30 days: SRV-PRINT, WKS-0107.
05

What is left

The largest items by number of logons in the period.

Programs sending NTLM
Program → targetLogons
msedge.exeopen→ HTTP/intranet23
explorer.exein progress→ cifs/fs01.demo.nopcap.net17
svchost.exeopen→ ldap/dc01.demo.nopcap.net16
Systemin progress→ cifs/fs01.demo.nopcap.net12
Veeam.Backup.Service.exein progress→ cifs/nas0112
EXCEL.EXEopen→ cifs/fs01.demo.nopcap.net9
WINWORD.EXEopen→ cifs/fs01.demo.nopcap.net6
wsmprovhost.exein progress→ HOST/app036
explorer.exeopen→ nas014
java.exeopen→ HTTP/erp-test3
robocopy.exeopen→ cifs/archive013
Accounts using NTLM
AccountLogons
svc_backupfrom 8 machines to 8 servers27
k.lorenzfrom 11 machines to 7 servers26
m.beckerfrom 15 machines to 10 servers26
svc_sqlfrom 11 machines to 9 servers24
j.schulzfrom 22 machines to 9 servers23
p.neumannfrom 14 machines to 8 servers21
t.hoffmannNTLMv1from 11 machines to 9 servers20
a.kleinfrom 10 machines to 7 servers18
administratorfrom 9 machines to 7 servers16
svc_monitorfrom 9 machines to 9 servers17
svc_webfrom 8 machines to 8 servers17
d.fischerfrom 12 machines to 9 servers16
s.wagnerfrom 8 machines to 7 servers14
svc_scanNTLMv1from 4 machines to 2 servers12
mfp_serviceNTLMv1from 2 machines to 2 servers8
How it is counted. Based on the NTLM and logon events of the agents and domain controllers. The same logon is often seen several times - by the client, the server and the DC; it counts once. 8001 entries not confirmed by a DC do not count. The NTLM share is NTLM divided by NTLM plus Kerberos tickets. Failed logons do not count towards the share.
NTLM-Analyzer · 25 Sep 2026, 22:387 days